Skip to main content
Live
Main content

Researchers build Zoom 'Zoomsday' exploit with fewer than 20 AI prompts

A Security used publicly available AI models to develop a device-hijacking Zoom exploit in a single day; Zoom patched it Tuesday.

Jaeden Schafer
Editor in Chief · · 4 min read
Researchers build Zoom 'Zoomsday' exploit with fewer than 20 AI prompts

Security researchers at A Security built a working Zoom exploit capable of hijacking every device on a call using fewer than 20 prompts on publicly available AI models, according to a blog post the firm published Tuesday. Zoom patched the flaw the same day, on August 11, 2026, and the fix covers Windows, macOS, Linux, Android, and iOS. The researchers, who nicknamed the bug 'Zoomsday,' say the entire exploit chain came together in a single day.

The attack targeted Zoom's annotation feature, the tool that lets meeting participants draw on a shared screen. By abusing it, an attacker who joined or hosted a meeting could run arbitrary code on other participants' devices, exfiltrate data, switch on cameras and microphones, or install malware. Victims had to do nothing for the attack to land, and A Security says there was 'no visual cue indicating the compromise' on screen while it happened.

What makes the disclosure notable is not the vulnerability itself but how it was found. A Security did not deploy a large in-house reverse-engineering team. It used off-the-shelf large language models, the same ones anyone with an account can access, and steered them through fewer than 20 prompts to identify the flaw and build a working proof of concept. That collapses a workflow that has historically required specialist security researchers into something closer to guided prompting.

Key facts

  • 01Researchers at A Security built a working Zoom exploit using fewer than 20 prompts on publicly available AI models.
  • 02The exploit abused Zoom's annotation feature to run malicious code on any device in a meeting, with no visual cue to the victim.
  • 03The vulnerability affected Zoom on Windows, macOS, Linux, Android, and iOS; Zoom patched it Tuesday, August 11, 2026.
  • 04A Security says the work took a single day, versus the months typically required by nation-state teams for comparable exploits.

Idan Levcovich, the A Security vulnerability researcher who authored the writeup, framed the shift in stark terms.

The economics that quote points at are the real story. Zoom is used by hundreds of millions of people for work meetings, medical appointments, court hearings, and government business. A pre-authentication, no-click remote code execution bug that touches every major operating system is exactly the class of vulnerability that intelligence agencies stockpile and that brokers pay seven-figure sums for. If a small commercial security shop can now produce one in a day with consumer AI tools, the supply curve for that kind of capability has changed shape.

Zoom's response was fast: the company shipped a patch on the same day the disclosure went live, and users on all five supported platforms should install the update. Auto-updates will catch most consumer installs, but enterprise deployments where IT controls the rollout are the ones worth watching, because those are also the environments where a hijacked meeting is most damaging.

The finding lands in the middle of a broader industry argument about whether AI tools help defenders or attackers more. A Security's case is that both sides get the same lift, but the offensive side benefits first because building one working exploit is a bounded problem, while defending an entire codebase is not. Zoom's engineers had to secure every code path in the annotation feature; the researchers only had to find one that broke.

There are reasons to be cautious about extrapolating from a single disclosure. A Security is a firm with an interest in publicizing dramatic results, 'fewer than 20 prompts' is a slippery metric that does not capture the human judgment guiding those prompts, and the researchers had a specific hypothesis about the annotation feature before they started. AI did not autonomously discover the bug from scratch; it accelerated researchers who knew where to look. The company also has not published the prompts themselves, which makes independent replication difficult.

Related · from this week
Anthropic details eight months of Claude abuse, from state hacking to bioweapon attempts
Jaeden Schafer · 5 min read →

Even with those caveats, the trend line is uncomfortable for every large software vendor. Vulnerability research budgets at big platform companies were sized against an era when bug discovery scaled roughly with headcount. If AI-assisted research keeps compressing the time from 'idea' to 'working exploit,' the mismatch between offense and defense widens, and patch-cycle timelines that assumed weeks of window may need to assume days. Zoom's same-day fix here is the benchmark other vendors will now be measured against, and few of them are currently set up to hit it.

ShareXLinkedInEmail
AI Box

Every AI model. One chat.

The latest models from ChatGPT, Claude, Gemini, Sora, ElevenLabs — 80+ models in a single chat. Compare answers side by side. Pick the best one every time.

  • ChatGPT, Claude, Gemini, Grok, DeepSeek — in one chat
  • Generate images & video with Sora, Veo, Ideogram
  • Compare any two models side by side
  • From $8.99/mo · 80+ models, all included
Try AI Boxaibox.ai
Trusted by 3,000+ teams
Got a tip?

Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.

Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.

AI Box Daily briefingFree · Daily · No fluff

Stay ahead of everyone in AI.

The tightly edited AI news email engineers, founders, and investors actually open. One email. Every weekday. Five minutes to finish.

Loved by 10,000+ AI professionals
Free forever. Unsubscribe with one click.

The briefing read inside teams at

Keep reading

More from Security

Anthropic logo
Security

Anthropic details eight months of Claude abuse, from state hacking to bioweapon attempts

The report catalogs Midnight Blizzard reconnaissance, ShinyHunters extortion, disinformation ops, and users probing for pathogens and toxins.

Jaeden Schafer5 min read
OpenAI logo
Security

New Mexico Supreme Court fines lawyer $5,000 for ChatGPT-fabricated witnesses

Stephen Aarons fed a murder trial transcript into ChatGPT's o3 model and filed a brief citing testimony from witnesses who never existed.

Jaeden Schafer5 min read
Meta logo
Security

Meta reworks AI prompt suggestions after chatbot probes user's children

A viral video showed Meta AI asking a mother to identify her child, then surfacing a photo she says she deleted years ago.

Jaeden Schafer4 min read