Ⓐ Security discovered a critical zero-click remote code execution vulnerability in Zoom's annotation feature, exploitable by any meeting participant without requiring victim interaction. The flaw affects all versions up to 7.0.5 across all platforms (Windows, Mac, iPhone, Android, Linux) and was found and weaponized using public AI models in under 24 hours with fewer than 20 prompts.
Background
Zoom serves as a primary communications platform for enterprises, with 70% of Fortune 100 companies using it. This research highlights the growing concern that weaponized AI could democratize nation-state-level exploit development, previously requiring elite teams and significant budgets.
- Source
- Lobsters
- Published
- Aug 13, 2026 at 11:27 PM
- Score
- 9.0 / 10