Zoom Patches Device Hijack Vulnerability Discovered Using AI in a Single Day

Zoom patched a major security vulnerability in August 2026 that could allow an attacker to take full control of another user’s device during a meeting — a flaw that researchers say they uncovered using fewer than 20 prompts on publicly available AI models.

The vulnerability was discovered by researchers at A Security, who detailed their findings in a blog post on Tuesday. The fix was issued the same day and applies to Zoom across Windows, macOS, Linux, Android, and iOS.

The exploit targeted Zoom’s annotation feature, which lets users draw on a shared screen during meetings. By taking advantage of the flaw, an attacker — whether hosting or simply joining a meeting — could run malicious code on victims’ devices. That access could be used to steal data, activate a camera or microphone, or install malware. According to A Security, the attack required no action from victims and left “no visual cue indicating the compromise.”

Idan Levcovich, a vulnerability researcher at A Security, wrote in the blog post that this class of exploit has historically required significant resources to pull off. “Producing a working exploit against it has always been nation-state work: elite teams, months of effort, budgets that governments regulate as weapons,” Levcovich wrote. “A [Security] did it in a single day, with an AI agent and models anyone can access today.”

The finding, first reported by Wired, suggests that AI tools may be lowering the barrier for discovering serious software vulnerabilities — work that previously demanded specialized expertise and substantial time. The vulnerability has since been patched, but the speed and accessibility of the discovery could raise broader questions about the security implications of widely available AI models.

Source: The Verge

This article was generated by AI and cites original sources.
Scroll to Top