Zoomsday: AI Used to Build Critical Zoom Exploit in One Day
The flaws could let someone in a meeting take control of another participant’s device without the victim clicking anything.
Jason Nelson
Publisher Decrypt
Aug 12, 2026 at 5:46 PM UTC · 2 Min. Lesezeit

- A security researcher found and exploited Zoom flaws using fewer than 20 AI prompts.
- The bugs affected Zoom’s annotation tool and could let an attacker run code on another participant’s device.
- Zoom fixed the vulnerabilities before they were publicly disclosed.
AI is making it faster and easier to find serious security flaws. Now, a researcher says he used publicly available models to find vulnerabilities in the video chat platform Zoom and build a working attack in less than 24 hours.
Calling it ‘Zoomsday’ in a report published Tuesday, Israeli cybersecurity firm A Security said a researcher used fewer than 20 AI prompts to uncover flaws in Zoom’s annotation tool that could let someone in a meeting take control of another participant’s device without any action from the victim.

“Once the nefarious code is running on the victim's device, the threat actor can quietly steal personal data, switch on the microphone or camera to spy on the target, or install other malicious software,” A Security wrote. “In a large call, that's a room full of targets from a single message, with no safe seat in it.”
According to A Security, the attack was tested on Zoom’s apps for Windows, macOS, Linux, Android, and iOS. The firm called it “nation-state-grade,” arguing that building such an exploit once required specialists, months of work, and a large budget.
Article Intelligence
Topics
Related Coverage
Sponsored
AdNewsLayer Premium
Unlock deeper intelligence.
Ad-free reading, exclusive research, and real-time onchain insights.
Go Premium
