A Security Finds Zoom Zero-Click RCE in Under 24 Hours With Fewer Than 20 AI Prompts
Updated
Updated · Gizmodo · Aug 12
A Security Finds Zoom Zero-Click RCE in Under 24 Hours With Fewer Than 20 AI Prompts
3 articles · Updated · Gizmodo · Aug 12
Summary
A Security said Zoom’s annotation feature contained a zero-click remote code execution flaw that could let an attacker hijack any participant’s device during a screen-sharing call.
The bug stemmed from Zoom clients automatically parsing annotation data; a specially crafted message could corrupt memory and execute code, with each viewer or sharer targetable through a direct channel.
Every Zoom version on every operating system was reportedly affected, and the exploit worked even with end-to-end encryption enabled; the issue has now been patched, but users must update.
Fewer than 20 prompts and under 24 hours were enough for researchers using publicly available AI models to identify and exploit the flaw, though human experts guided the process.
The disclosure adds to warnings from U.S. and U.K. officials at Black Hat last week that vulnerability discovery is accelerating faster than defenders can patch systems.