AI Found a Zoom Security Hole in One Day That Used to Take Nation-States Months

A research team used widely available AI tools to discover and exploit a flaw in Zoom's screen-sharing feature. Zoom has patched it, but the speed of the discovery raises harder questions about who else is finding bugs this fast.

AI2Day NewsdeskUpdated Editor: Lee Brown3 min read
A digital lock symbolizing data breach in a corporate setting, with abstract code overlay
Share

Key points

  • Security firm A Security discovered a critical vulnerability in Zoom's annotation feature in a single day using AI tools anyone can access.
  • The flaw affected Zoom across Windows, macOS, Linux, Android and iOS.
  • An attacker could steal data, activate a victim's camera or microphone, or install malware, with no warning visible on screen.
  • Zoom issued a patch on Tuesday, so users with auto-update on are already protected.
  • A Security's researcher said this class of attack previously required elite government-funded teams and months of work.

Zoom has fixed a serious security flaw after researchers at A Security discovered they could silently take over another person's device during a meeting, no action from the victim required.

The vulnerability lived inside Zoom's annotation feature, the tool that lets participants draw or highlight things on a shared screen. By exploiting a weakness in how that feature handled certain data, an attacker only needed to join or host a meeting, then run malicious code on the victim's device.

What could an attacker actually do?

Quite a lot. The exploit let an attacker steal files, switch on a camera or microphone without the owner's knowledge, or install malware that hides and causes ongoing damage. Nothing on screen would warn the victim.

Zoom patched the flaw on Tuesday. If you've got automatic updates switched on, you're already running the fixed version. Open Zoom, go to your profile, and check for updates manually if you don't.

Why does it matter how fast the researchers found it?

Speed is the story. Finding this kind of deep software vulnerability traditionally required what researchers call nation-state resources: a skilled, well-funded team spending months on a single exploitable weakness. Governments treat certain hacking tools as controlled weapons for exactly that reason.

A Security says it found and built a working exploit in one day, using an AI agent (software that carries out multi-step tasks on its own) and publicly available AI models. The firm used fewer than 20 prompts, meaning fewer than 20 typed instructions, to guide the AI through the process.

"Producing a working exploit against it has always been nation-state work: elite teams, months of effort, budgets that governments regulate as weapons," wrote Idan Levcovich, a vulnerability researcher at A Security. "We did it in a single day, with an AI agent and models anyone can access today."

It's not an isolated data point. Our 30 July report on Chrome showed Google's AI security tools spotting more flaws in two releases than in the previous 23 combined, a sign that both defenders and attackers are accelerating.

What does this mean for ordinary Zoom users?

Update Zoom. The patch closes this specific hole.

The bigger concern is what the discovery speed signals. If a legitimate security team can find a critical flaw in hours with off-the-shelf AI tools, less scrupulous actors have the same toolkit. The gap between expert hackers and a determined amateur is narrowing faster than most patch cycles can keep up with. That's the part nobody should gloss over.

© 2026 AI2Day