Zoom corrected a serious vulnerability on Tuesday, the 11th, which allowed for the discreet invasion of computers and phones. This flaw was identified by the cybersecurity firm A Security and only required the victim to be participating in a video conference with screen sharing active.
The incident raised concerns about how easily the flaw was discovered, given that researchers used public artificial intelligence models to exploit the vulnerability from the start, using fewer than twenty text commands, known as prompts.
The weak point resided in the protocol responsible for managing real-time annotations, the feature that allows drawing and marking the screen. This flaw created an opening that led to remote code execution.
According to technical reports provided by A Security, an attacker present in the meeting, regardless of whether they were the host or a guest, had the ability to inject malicious code into the devices of all other participants in the room. This attack, nicknamed 'Zoomsday,' presented a significant risk because it operated in a zero-click format, meaning it required no action from the victim.
It was not necessary for the person to click a suspicious link in the chat, download a harmful file, or accept any request on the screen. With control over the system, the cybercriminal gained unrestricted access to steal confidential information, activate the camera and microphone, or install malicious software.
In a business context, the consequences would be extremely detrimental. A hacker could steal a collaborator's credentials to access the company network, compromising servers from a single video call.
What alarmed experts the most was the speed with which AI located and exploited the breach. The cybersecurity firm reported that it took only one day of work; they assigned an AI agent to examine frequently neglected functions in the Zoom code, finding the error and setting up the invasion in record time.
The vulnerability affected the Zoom application across all compatible systems, including Windows, macOS, Linux, Android, and iOS (iPhone). Given that participation in video conferences ranges from professional meetings to virtual classes, millions of users could have had their devices exposed if the details of the flaw had leaked.
Fortunately, the flaw was communicated to developers responsibly. The service owner released a detailed security statement, implemented the necessary corrections on the servers, and made updates available for the applications.
Although there are no records of 'Zoomsday' being maliciously exploited on the internet, the general and unanimous advice is that users update the application immediately.


