Zoom issues critical patch for 'Zoomsday': the flaw that lets hackers in with zero clicks
Image: GizmodoA critical “zero-click” vulnerability in Zoom, dubbed “Zoomsday,” allows an attacker to take control of your device during a video call without you doing absolutely anything. The discovery has an unsettling twist: it was found and exploited with the help of AI models.
How the attack works
The flaw resides in the processing of the annotation feature during screen sharing: a malicious packet can corrupt the memory of Zoom’s player and execute arbitrary code on the victim’s machine, with no click required. Being in the same call is enough.
AI as a double-edged sword
Researchers managed to find and exploit the vulnerability with public AI models guided by fewer than 20 prompts in under 24 hours. The case raises alarms about how AI democratizes exploit development: you no longer need to be a security expert to build a devastating attack.
Why it matters
Zoom is installed on millions of corporate and office machines worldwide. Although the company has already shipped a patch, the incident shows that the security of everyday work tools depends on updates many users take weeks to apply.
The key figure
0 clicks. What the attacker needs to compromise your machine. And 20 prompts of AI were enough to figure out how.


