cd /news/artificial-intelligence/zoomsday-ai-used-to-build-critical-z… · home topics artificial-intelligence article
[ARTICLE · art-94101] src=decrypt.co ↗ pub= topic=artificial-intelligence verified=true sentiment=↓ negative

Zoomsday: AI Used to Build Critical Zoom Exploit in One Day

Israeli cybersecurity firm A Security reported that a researcher used fewer than 20 AI prompts to find and exploit vulnerabilities in Zoom's annotation tool, building a working attack in under 24 hours that could let an attacker take control of another participant's device. The flaws, tracked as CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415, affected Zoom apps for Windows, macOS, Linux, Android, and iOS, and were fixed by Zoom between June 22 and July 20. A Security called the exploit 'nation-state-grade,' noting that such attacks previously required specialists, months of work, and a large budget.

read2 min views1 publishedAug 12, 2026
Zoomsday: AI Used to Build Critical Zoom Exploit in One Day
Image: Decrypt (auto-discovered)

In brief

  • A security researcher found and exploited Zoom flaws using fewer than 20 AI prompts.
  • The bugs affected Zoom’s annotation tool and could let an attacker run code on another participant’s device.
  • Zoom fixed the vulnerabilities before they were publicly disclosed.

AI is making it faster and easier to find serious security flaws. Now, a researcher says he used publicly available models to find vulnerabilities in the video chat platform Zoom and build a working attack in less than 24 hours.

Calling it ‘Zoomsday’ in a report published Tuesday, Israeli cybersecurity firm A Security said a researcher used fewer than 20 AI prompts to uncover flaws in Zoom’s annotation tool that could let someone in a meeting take control of another participant’s device without any action from the victim.

“Once the nefarious code is running on the victim's device, the threat actor can quietly steal personal data, switch on the microphone or camera to spy on the target, or install other malicious software,” A Security wrote. “In a large call, that's a room full of targets from a single message, with no safe seat in it.”

According to A Security, the attack was tested on Zoom’s apps for Windows, macOS, Linux, Android, and iOS. The firm called it “nation-state-grade,” arguing that building such an exploit once required specialists, months of work, and a large budget.

The flaws are tracked as CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415. CVEs are public identifiers for security vulnerabilities.

“Exploits like this one are weapons. Governments regulate their export. Criminal organizations pay millions for them,” they wrote. “Acquiring one has always required nation-state infrastructure, elite teams, and months of work.”

A Security said the exploit also enables attackers to either join or host a meeting, target any participant, and take over their machine with “no required action from the victim and no visual cue indicating the compromise.”

“It worked in both directions: a compromised presenter could reach every participant, and any participant could reach the presenter,” they wrote.

A Security said it reported the first flaw to Zoom on June 10, two days after discovering it. Zoom released fixes between June 22 and July 20, but users still needed to update because its server-side safeguard could not filter malicious messages in end-to-end encrypted meetings.

“As shared on our Zoom Security Bulletin page, we’ve already resolved this issue," a Zoom spokesperson told Decrypt. "We always recommend users keep up to date with the latest version of Zoom so that they’re taking advantage of our latest features and updates."

The report comes as AI tools are being used across the tech industry to uncover bugs, including 271 vulnerabilities in Mozilla Firefox in April and flaws in the Zcash network in May. At the same time, AI models from OpenAI, Anthropic, and Meta have escaped containment and hacked other companies’ systems.

── more in #artificial-intelligence 4 stories · sorted by recency
── more on @a security 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/zoomsday-ai-used-to-…] indexed:0 read:2min 2026-08-12 ·