A meeting participant could take over the devices of everyone else on the call — with no one needing to click, download or approve anything. That is the threat behind 'Zoomsday', a zero-click vulnerability disclosed this week by Israeli security firm A Security and now patched by Zoom.
The flaw lives in Zoom's real-time annotation engine, where memory-corruption bugs allowed a malicious participant to execute code on other attendees' systems across Windows, macOS, Linux, Android and iOS. An attacker could steal information, install malware or switch on cameras and microphones without the victim taking any action. Zoom, which says the platform is used by 70% of the Fortune 100, rolled out fixes for the affected versions.
What makes the finding remarkable is how quickly it was produced. A Security said a researcher used fewer than 20 prompts to publicly available AI models to develop the exploit in roughly a day — a process that historically could take experienced vulnerability researchers weeks of studying an unfamiliar protocol.
The result does not mean anyone can become a top hacker by opening a chatbot; skilled researchers still need to recognize promising attack surfaces and judge when a model's output is wrong. But it compresses the economics of vulnerability discovery, accelerating the race between those finding flaws and those weaponizing them. AI, the researchers argue, is now a genuine force multiplier in security research — on both sides.
For enterprises, the episode is a reminder that patching cadence now matters more than ever: the same AI tools that defenders use to harden software are increasingly the tools attackers use to break it.
Sources
- a.securityZOOMSDAY — A Security blog
- theverge.com'Zoomsday' hack uncovered using fewer than 20 AI prompts — The Verge
- decrypt.coZoomsday: AI Used to Build Critical Zoom Exploit in One Day — Decrypt
- privacyguides.orgSevere Zoom vulnerabilities allow malicious meeting participants to take over your device — Privacy Guides
- securityweek.comZoom Patches Zero-Click Code Execution Vulnerability — SecurityWeek




