Zoom Patches 'Zoomsday' Flaw That Allowed Silent Device Takeovers
A critical zero-click vulnerability in Zoom's screen-sharing feature enabled remote code execution across all supported platforms.
Zoom has patched a critical security vulnerability, dubbed "Zoomsday," that allowed attackers to remotely execute code and gain full control of participants' devices during active calls. The flaw resided within the platform's screen-sharing feature and posed a severe risk to users across the entire Zoom ecosystem.
The vulnerability was universal in scope, affecting every operating system supported by the service, including Windows, macOS, Linux, iOS, and Android. The attack was "zero-click," meaning it could be carried out silently with no indication to the victim and required no interaction from the target to succeed. Zoom has since issued a security advisory and rolled out patches across all platforms to neutralize the threat.
The AI-Driven Discovery
The flaw was uncovered by the cybersecurity firm A Security, which utilized public AI models to identify the vulnerability. This discovery underscores a shift in how software bugs are found; the firm reported that AI significantly accelerated the process, reducing a task that previously required extensive human labor to a matter of prompts.
Omer Gull, cofounder of A Security, highlighted the efficiency of this new approach, stating that while finding such a flaw would have previously taken a team of five people roughly six months of refining and iteration, researchers can now achieve the same results with fewer than 20 prompts to an AI tool.
Industry Implications
This incident demonstrates the dual-use nature of artificial intelligence in the cybersecurity landscape. While AI provides defenders with powerful tools to find and fix bugs faster, it simultaneously lowers the barrier for malicious actors to discover "zero-day" style vulnerabilities in enterprise-grade software.
The ability to execute a silent takeover on mobile devices—specifically iOS and Android—alongside traditional desktops increases the potential impact of such flaws. Because mobile operating systems are generally more locked down than desktops, a zero-click remote code execution (RCE) vulnerability is particularly dangerous, as it bypasses the standard security assumptions users have about their handheld devices.
Moving Forward
As AI tools become more integrated into the security research workflow, the window between the creation of a vulnerability and its discovery is likely to shrink. Organizations are now facing a landscape where complex flaws can be surfaced in hours rather than months.
Users are urged to ensure their Zoom clients are updated to the latest version to protect against the Zoomsday exploit. While Zoom has addressed this specific flaw, the incident serves as a reminder for the industry to harden screen-sharing and media-streaming protocols against AI-assisted discovery techniques.