Share
Researchers at A Security uncovered a major flaw in Zoom's annotation feature, allowing attackers to hijack devices with just 20 AI prompts. Here’s what it means for cybersecurity.
Zoom has patched a critical security vulnerability that could allow an attacker to take over any device on a call, according to a blog post from researchers at A Security. The exploit, which involved Zoom's annotation feature, was discovered using fewer than 20 prompts on publicly available AI models. This discovery highlights the growing role of AI in both launching and defending against cyber attacks.
The vulnerability, dubbed "Zoomsday," allowed an attacker to join or host a meeting and run malicious code on victims' devices, effectively giving them full control over the target's machine. The exploit leveraged Zoom’s annotation feature, which lets users draw on their screen while sharing it with other participants. By manipulating this feature, attackers could execute arbitrary code on the victim’s device.
The implications of this vulnerability are significant for both individual users and organizations that rely heavily on Zoom for communication. The ability to hijack devices during a meeting could lead to data theft, ransomware attacks, or even more sophisticated multi-stage attacks where the compromised device serves as a foothold in a larger network.
The speed at which researchers were able to exploit this vulnerability using AI highlights the evolving nature of cybersecurity threats. Traditional methods of attack detection and prevention are being challenged by the rapid advancements in AI, which can generate sophisticated exploits with minimal human intervention.
As AI continues to evolve, the balance between attack and defense will remain a critical area of focus for cybersecurity professionals. The "Zoomsday" vulnerability serves as a stark reminder that even the most widely used tools can have hidden flaws, and staying one step ahead requires constant vigilance and innovation.
Tags
Original Sources
‘Zoomsday’ hack uncovered using fewer than 20 AI prompts
↗ https://www.theverge.com/ai-artificial-intelligence/977909/zoom-vulnerability-ai-attack
About the author
Kai built ML infrastructure at a Bay Area startup before developing an obsession with transformer architectures and inference optimisation that eventually pulled him out of product work entirely. A stint at a compute research lab sharpened his instinct for what actually matters in a model release versus what is marketing. He writes from the inside — from the perspective of someone who has debugged the systems he is describing at three in the morning. He is allergic to hype and instinctively drawn to the unglamorous plumbing questions that everyone else skips over.
More from The Engineer →This Week's Edition
17 August 2026
113 articles
Related Articles

A Fundamental Flaw in LLMs Makes Them Vulnerable to Adversarial Attacks
Security & Risk · 3 min

OpenAI's AI Models Breach Hugging Face Security, Highlighting Critical Risks in AI Development
Security & Risk · 2 min

Anthropic Discloses AI Models Breached Three Companies During Security Tests
Security & Risk · 3 min
Related Articles

A Fundamental Flaw in LLMs Makes Them Vulnerable to Adversarial Attacks
Security & Risk · 3 min

OpenAI's AI Models Breach Hugging Face Security, Highlighting Critical Risks in AI Development
Security & Risk · 2 min

Anthropic Discloses AI Models Breached Three Companies During Security Tests
Security & Risk · 3 min
More Stories
© 2026 Cedar & Bloom. All rights reserved.