Technology newsroom
Critical Alert! Zoomsday Vulnerability in Zoom Allows Hackers to Seize Devices During Calls, Discovered Using AI with Only 20 Prompts!
Researchers have discovered a critical 'Zoomsday' vulnerability in Zoom, allowing meeting participants to completely seize control of others' devices. This flaw was easily found with AI assistance using only 20 command prompts. All users are urged to update immediately.
π Key Highlights:
- A critical vulnerability named Zoomsday has been found in Zoom, allowing any meeting participant to instantly seize control of another person's computer in the same call without the victim's knowledge.
- Researchers used AI to discover this high-severity vulnerability with only 20 command prompts, demonstrating that cyberattacks can be much easier and faster in the age of AI.
- Zoom has released a patch. All users should update the Zoom Workplace application to the latest version immediately to mitigate the risk.
A team of researchers from A.Security has disclosed a critical security vulnerability in the popular online meeting application Zoom, naming it Zoomsday. This flaw is severe enough that a malicious actor participating in the same meeting can completely penetrate and control other participants' devices. What's alarming is that these attacks can occur without the victim noticing any abnormalities.
What makes this discovery even more startling is the method researchers used to find the vulnerability. They admitted to using an AI Agent to assist in analyzing and creating the exploit by feeding it just 20 prompts. This is clear proof that AI has broken down barriers and reduced the resources previously required to find high-level vulnerabilities. What once demanded teams of top experts, months of time, and massive budgets has now become much simpler, increasing cyber risks like never before.
π» In-Depth Technical Vulnerability
The Zoomsday vulnerability comprises two Remote Code Execution (RCE) flaws (CVE-2026-53413 and CVE-2026-53415), stemming from defects in the library that manages the Annotation (or screen drawing) function. Even if no one uses this feature, this code segment runs constantly whenever a meeting is in progress.
The primary vulnerability is a classic Buffer Overrun error, where the program does not correctly validate the size of incoming data. This allows attackers to send data larger than the program expects, overwriting other memory regions with malicious code and ultimately executing remote commands to seize control of the device.
π‘οΈ Prevention and Urgent Update
The good news is that Zoom has acknowledged and released a patch to fix this critical vulnerability. All Zoom Workplace users should update their application to the latest version as quickly as possible. The secure version is 7.0.6 or higher, and for those using the "fast track" update channel, it must be version 7.1.5 or higher. Keeping software up-to-date is the most crucial defense against this type of threat.
π¬ Does your organization enforce a policy of always keeping software updated to the latest version? Let's share best practices.