Updated
Updated · Gizmodo · Aug 12
A Security Finds Zoom Zero-Click RCE in Under 24 Hours With Fewer Than 20 AI Prompts
Updated
Updated · Gizmodo · Aug 12

A Security Finds Zoom Zero-Click RCE in Under 24 Hours With Fewer Than 20 AI Prompts

3 articles · Updated · Gizmodo · Aug 12

Summary

  • A Security said Zoom’s annotation feature contained a zero-click remote code execution flaw that could let an attacker hijack any participant’s device during a screen-sharing call.
  • The bug stemmed from Zoom clients automatically parsing annotation data; a specially crafted message could corrupt memory and execute code, with each viewer or sharer targetable through a direct channel.
  • Every Zoom version on every operating system was reportedly affected, and the exploit worked even with end-to-end encryption enabled; the issue has now been patched, but users must update.
  • Fewer than 20 prompts and under 24 hours were enough for researchers using publicly available AI models to identify and exploit the flaw, though human experts guided the process.
  • The disclosure adds to warnings from U.S. and U.K. officials at Black Hat last week that vulnerability discovery is accelerating faster than defenders can patch systems.

Insights

Could your device have been silently compromised through a Zoom screen share before you even clicked update?
If AI can weaponize a Zoom flaw in under 24 hours, how can human defenders possibly keep up with future zero-day attacks?
Does end-to-end encryption actually put users at greater risk by preventing server-side blocks of malicious zero-click exploits?