There are few things more mortifying than the prospect of sharing something you didn’t intend to on a work Zoom call. Now imagine it’s entirely out of your control. That is the risk of a security flaw discovered and disclosed by a cybersecurity company called A Security, which found a vulnerability that allowed an attacker to hijack the device of any user involved in a call with screen sharing. Notably, the group claims to have found the issue with just a few AI prompts.
According to the firm, the vulnerability was about as bad as it gets: a zero-click remote code execution that takes advantage of the way Zoom’s annotation feature works. The company explained in a blog post that because Zoom’s client “automatically parses whatever it receives” while the annotation feature is in use, an attacker could send a “specially crafted message to corrupt the receiving client’s memory and run code on it.” And because the protocol within the app creates a direct channel between the viewer and sharer, each participant on the call could be targeted individually.
That’s pretty bad, made worse by the fact that the vulnerability was apparently present in every version of Zoom on every operating system, and was even exploitable in calls where end-to-end encryption was active. It has since been patched, but you’ll have to update to make sure you’re not subject to the hijacking technique.
What makes the flaw particularly worth mentioning is how it was discovered in the first place. According to A Security, the company was able to find the vulnerability using publicly available AI models, which were able to identify and exploit the issue in fewer than 20 prompts and in under 24 hours. Of course, the models were guided by security researchers with real know-how providing direction on what to look for, but it does speak to the ways that AI models are impacting the cybersecurity landscape.
All of the frontier AI labs have made hay about just how powerful their top-tier models are—so powerful, in fact, that access to them must be restricted so the power doesn’t fall into the wrong hands. But even the publicly available tools seem to be upending the cyber industry. Just last week, officials from the United States and the United Kingdom warned at the Black Hat cybersecurity conference in Las Vegas that the speed at which people are discovering vulnerabilities is quickly surpassing the ability to patch them.
Safety was never guaranteed, but it seems we’re all increasingly vulnerable without fully realizing it.