Zoom patched, on Tuesday (August 11), a set of severe vulnerabilities that would have let an attacker take complete control of any participant's device during a meeting. The case was dubbed "Zoomsday" and drew the industry's attention less because of the bug itself — already fixed — and more because of how it was found: with "fewer than 20 prompts" on public AI models, according to the digital defense firm A Security, which ran the investigation.
The flaw sat in Zoom's annotation feature, the one that lets users draw over a shared screen during a call. By exploiting it, an attacker could join or host a meeting and run malicious code on victims' devices — stealing data, switching on cameras and microphones, or installing malware. The worst part: the attack required no interaction from the target and unfolded silently, with no sign that anything was wrong.
The reach was almost universal. The flaws affected every operating system Zoom supports — Windows, macOS, Linux, iOS, and Android — and were discovered back in June, when the researchers decided to target a specific component of the protocol used for real-time annotation. "Convoluted and obscure functions often concentrate overlooked vulnerabilities," the team said, pointing to a pattern human bug hunters know well: in proprietary, closed-source software, complex and rarely used features rarely get the same public scrutiny as open code.
What worries the researchers most, however, is the thesis behind the discovery. "What is interesting for us and what we believe is dangerous is the democratization of these capabilities — the barrier to entry is dropping rapidly," said Omer Gull, cofounder of A Security. "Before it would have taken a team of five people maybe six months to find this. Now people can reach the same results with under 20 prompts." Zoom issued a security advisory on Tuesday and has begun rolling out fixes both server-side and in its client applications.
The episode is the latest example of a trend that has been consolidating: AI models increasingly capable of finding vulnerabilities, developing exploits, and even carrying out autonomous attacks. In Zoom's case, what used to be an expensive, time-consuming exercise became a task of minutes for anyone who knows how to ask the right questions. That doesn't mean everyone is now a hacker — but it does mean the marginal cost of a serious discovery has collapsed. For teams running critical infrastructure, it is an uncomfortable reminder that the attack surface is expanding faster than the capacity to audit every line of code — and that the next person to ask the right twenty questions may not be a security firm publishing a responsible disclosure.
The video-conferencing industry, in particular, lives a delicate relationship with trust. Zoom is a platform where people "assume trust," in Gull's words — nobody imagines that joining a meeting could be an attack vector. After "Zoomsday," that assumption feels a little more fragile. What nobody can yet answer is how many other everyday software products hide equivalent flaws that have never been the target of twenty well-chosen prompts — and what the cost will be when someone finds them first.
Sources: The Verge, Wired, 9to5Mac, A Security
✓ Independent sources cross-checked and verified before publishing