
Fewer than 20 AI prompts uncovered a dangerous Zoom vulnerability, researchers say
Cyber researchers at A Security say work that could previously have taken months was completed in less than 24 hours with a publicly available AI model.
Researchers at Israeli cybersecurity firm A Security say they discovered a dangerous vulnerability in Zoom by sending fewer than 20 prompts to a publicly available AI model over less than 24 hours. They estimate that without AI, finding the same vulnerability would have required months of work by a skilled team of five or six people.
“As part of A Security’s mission to protect against AI-based attacks, we investigate the critical infrastructure of the modern world,” Idan Levkovich, a vulnerability researcher at A Security, told Calcalist. “Zoom is used by large corporations, governments, and families, and the vulnerability we found allows remote control of any device over a video call. Such research previously required a team of experts and the capabilities of cyber superpowers, while today such a vulnerability can be found and exploited in just one day with models accessible to everyone. This incident illustrates that organizations must use this technology to proactively find and fix vulnerabilities, long before they are discovered by attackers.”
To find the vulnerability, the researchers began with the Zoom Android app, whose code libraries are publicly available. The prompts they used drew on their knowledge of coding and cybersecurity defenses. Rather than simply instructing the AI to “find a security breach,” they used a series of prompts to guide the AI agent through the software code, helping it understand the application, identify bugs and potential entry points, and uncover the vulnerability.
The vulnerability is linked to a Zoom feature that allows users to draw and write on the screen while sharing their device's display during a call. According to the researchers, an attacker could use the vulnerability to execute malicious code on a victim's computer and potentially steal information, remotely activate the camera and microphone, or install malware. The attack would not require any action from the victim or provide a visible indication that an attack was taking place.
Zoom has already patched the vulnerability in recent versions of its applications. Before the fix, however, the vulnerability was present across Zoom's various platforms, including Windows, Mac, iPhone, Android and Linux, according to A Security.
Using AI to identify vulnerabilities still requires knowledge of cybersecurity and software. But the researchers say it can dramatically lower the barrier to discovering critical flaws, allowing actors with relatively limited expertise to conduct research that once required highly specialized teams.
Levkovich argues that the implications extend well beyond Zoom.
“Zoom is core infrastructure at 70 percent of Fortune 100 companies, most Fortune 500 companies, and federal agencies,” he wrote in a report summarizing the findings. “In addition, it is the platform where millions meet with their doctors, lawyers, and families.”
But, he wrote, “the real finding is not the bug. It is the speed.”
“The barrier to creating such weapons has collapsed, and it will not return,” Levkovich wrote. “The message to security managers: Defenses built for a world where these weapons were rare are no longer valid.”
The researchers argue that organizations will increasingly need to use AI not only to develop products and automate work, but also to continuously search their own systems for vulnerabilities before attackers find them.














