Key facts
- Researchers discovered critical vulnerabilities in Zoom's annotation tool that could allow for silent device takeover.
- AI models were used to find these flaws with minimal prompts, enabling exploit creation in under 24 hours.
Researchers utilized AI models and fewer than 20 prompts to discover critical vulnerabilities in Zoom's annotation tool, enabling silent device takeover. Zoom has since released fixes for the flaws affecting all major operating systems.

The rapid advancement of AI tools is significantly lowering the barrier to entry for creating sophisticated cyberattacks, posing a growing threat to widely used platforms and user security.
Researchers have disclosed critical vulnerabilities in Zoom's video conferencing platform that could enable attackers to silently hijack users' devices through screen sharing. The flaws were discovered in early June by researchers from the digital defense firm A Security, who utilized publicly available AI models and required fewer than 20 prompts to identify and create a working exploit. Zoom has since issued a security advisory and begun deploying fixes for the vulnerabilities, which impacted all supported operating systems, including Windows, macOS, Linux, iOS, and Android.
Omer Gull, cofounder of A Security, expressed concern over the rapid decrease in the barrier to entry for sophisticated hacking capabilities, noting that what previously required significant time and resources from a team of experts can now be achieved with minimal AI prompts. He highlighted Zoom as a particularly concerning target due to users' inherent trust in the platform. The vulnerabilities specifically resided within the protocol used for real-time annotation during screen sharing. Researchers targeted this area, reasoning that complex and obscure functions in proprietary, closed-source software are often overlooked.
The exploit, dubbed 'Zoomsday,' could allow an attacker to run code on another participant's device without any action from the victim, potentially leading to data theft, surveillance, or the installation of further malicious software. The flaws are tracked as CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415. A Security reported the first flaw to Zoom on June 10, and Zoom released fixes between June 22 and July 20.