● EN VIVO

EL DIARIODICE

Independent digital journalism, economy and analysis

← Back to homepage
Technology⏱️ 2 min read

Zoom issues critical patch for 'Zoomsday': the flaw that lets hackers in with zero clicks

Zoom issues critical patch for 'Zoomsday': the flaw that lets hackers in with zero clicksImage: Gizmodo

A critical “zero-click” vulnerability in Zoom, dubbed “Zoomsday,” allows an attacker to take control of your device during a video call without you doing absolutely anything. The discovery has an unsettling twist: it was found and exploited with the help of AI models.

How the attack works

The flaw resides in the processing of the annotation feature during screen sharing: a malicious packet can corrupt the memory of Zoom’s player and execute arbitrary code on the victim’s machine, with no click required. Being in the same call is enough.

AI as a double-edged sword

Researchers managed to find and exploit the vulnerability with public AI models guided by fewer than 20 prompts in under 24 hours. The case raises alarms about how AI democratizes exploit development: you no longer need to be a security expert to build a devastating attack.

Why it matters

Zoom is installed on millions of corporate and office machines worldwide. Although the company has already shipped a patch, the incident shows that the security of everyday work tools depends on updates many users take weeks to apply.

The key figure

0 clicks. What the attacker needs to compromise your machine. And 20 prompts of AI were enough to figure out how.

Sources

  1. gizmodo.com
  2. securityaffairs.com
  3. thehackernews.com
  4. bleepingcomputer.com