
Researchers have uncovered a security flaw in the online meeting platform Zoom that could reportedly let attackers remotely take over devices. Digital criminals could use the security loophole to run code on devices used by people in a meeting, including iPhones and Macs. The issue reportedly affected calls and meetings where the screen-sharing feature was active. The most concerning aspect is that the flaw could be exploited without the victim clicking anything or seeing a warning.
AI tools speed up vulnerability discovery
The security vulnerability was discovered by the cybersecurity firm A Security back in June. The team found the issue while examining Zoom using publicly available AI models. It took researchers fewer than 20 prompts to identify the vulnerabilities and develop a working attack. The company then shared the issue with Zoom, which has since released a patch to fix the problem.
The speed of discovery is notable. In typical scenarios, finding a vulnerability of this kind could have required months of work by a larger security team. However, thanks to AI, the critical security flaw was discovered in just a few minutes or hours of work.
Related: Acer Laptop Features Dedicated Gemini Key
Attack works across major operating systems
The flaw was dangerous because it could work across all major operating systems, including macOS, Windows, iOS, and Android. Anyone on the call, whether a participant or the organizer, could have been exposed. The attack could be carried out without any interaction, meaning the user would remain unaware of the ongoing attack.
Co-founder of A Security, Omer Gull, told Wired that similar work could previously have taken a team of five people around six months, including repeated testing and refinement. He said the finding shows how publicly available AI tools can reduce the time needed to identify weaknesses. Zoom was an important target because users generally trust the platform and do not expect a normal meeting to pose a security threat.
For many organizations, video conferencing is now a daily necessity. When a platform becomes a critical infrastructure tool, even a single unpatched weakness can create a wide attack surface for bad actors to exploit. The discovery highlights a shift in how security flaws are identified, moving from traditional manual testing to automated processes that can scan for issues much faster than human analysts working in isolation. This new reality forces companies to update their patch management strategies to keep up with the speed of automated threat discovery.
Leave a Reply