AI Found a Zoom Security Hole in One Day That Used to Take Nation-States Months

A research team used widely available AI tools to discover and exploit a flaw in Zoom's screen-sharing feature. Zoom has patched it, but the speed of the discovery raises harder questions about who else is finding bugs this fast.

AI2Day Newsdesk3 min read
A digital lock symbolizing data breach in a corporate setting, with abstract code overlay
Share

Key points

  • Security firm A Security discovered a critical vulnerability in Zoom's annotation feature in a single day using AI tools anyone can access.
  • The flaw affected Zoom across all five major platforms: Windows, macOS, Linux, Android, and iOS.
  • An attacker could steal data, activate a victim's camera or microphone, or install malware, all with no warning visible on screen.
  • Zoom issued a patch on Tuesday, so users who keep auto-update on are already protected.
  • A Security's researcher said this class of attack previously required elite government-funded teams and months of work.

Zoom has fixed a serious security flaw in its app after researchers at a firm called A Security discovered they could take over another person's device during a meeting, silently and without any warning.

The vulnerability, first reported by The Verge AI, lived inside Zoom's annotation feature. That is the tool that lets meeting participants draw or highlight things on a shared screen. By exploiting a weakness in how that feature handled certain data, an attacker only needed to join or host a meeting. From there, they could run malicious software, meaning code designed to cause harm, on the victim's device without the victim doing anything at all.

What could an attacker actually do?

Quite a lot. The exploit gave an attacker the ability to steal files, switch on a camera or microphone without the owner's knowledge, or install malware, software that hides on a device and causes ongoing damage. Nothing on screen would warn the victim it was happening.

Zoom patched the flaw on Tuesday. If you have automatic updates switched on, you are already running the fixed version. If you update manually, open Zoom, go to your profile, and check for updates now.

Why does it matter how fast the researchers found it?

Speed is the story here. Traditionally, finding this kind of deep software vulnerability required what researchers call nation-state resources: a skilled, well-funded team, often working for a government, spending months searching for a single exploitable weakness. That is why governments treat certain hacking tools as controlled weapons.

A Security says it found and built a working exploit in a single day, using an AI agent (software that can carry out multi-step tasks on its own) and AI models that anyone can download or access online. The firm used fewer than 20 prompts, meaning fewer than 20 typed instructions, to guide the AI through the process.

"Producing a working exploit against it has always been nation-state work: elite teams, months of effort, budgets that governments regulate as weapons," wrote Idan Levcovich, a vulnerability researcher at A Security. "We did it in a single day, with an AI agent and models anyone can access today."

What does this mean for ordinary Zoom users?

For now, update Zoom and carry on. The patch closes this specific door.

The wider concern is what the speed of discovery signals. If a legitimate security team can find a critical flaw in hours using off-the-shelf AI tools, less scrupulous actors have the same toolkit. The gap between what expert hackers can do and what a determined amateur can do is narrowing.

Security researchers have warned for some time that AI would accelerate both sides of cybersecurity, the defenders and the attackers. This episode is a concrete data point, not a hypothetical one.

© 2026 AI2Day