Zoom has shipped a fix for a vulnerability that let an attacker take control of any device in a meeting. What has drawn attention is not the flaw so much as how cheaply it was found: researchers at A Security say they got there with fewer than twenty prompts against AI models anybody can use, in an account Wired carried first.
The weakness sat in the annotation tool — the feature that lets participants draw over a screen somebody is sharing. From there, a person joining or hosting a call could execute code on other people's machines, which was enough to pull data off them, switch on a camera or microphone, or leave malware behind.
Nobody had to click anything. A Security says the attack ran without any action from the people it targeted, and without anything appearing on screen to suggest it was happening.
Idan Levcovich, a vulnerability researcher at the firm, put the significance in terms of who has historically been capable of this. Building a working exploit against a target of that size, he wrote, has been the preserve of state programmes — specialist teams, months of effort, budgets governments regulate the way they regulate weapons. His team did it inside a day, with an AI agent and models on general release.
That is the part worth sitting with. The vulnerability is patched; the economics that produced it are not. If a day's work with commodity tools now reaches where months of state-funded effort used to, the number of people able to do this has changed by orders of magnitude, and so has the number of flaws likely to be found in everything else.
Zoom's patch went out on Tuesday. The bug affected the client on Windows, macOS, Linux, Android and iOS.
