In early August 2026, cybersecurity faced a new challenge: artificial intelligence demonstrated the ability to find critical vulnerabilities in popular platforms within hours. Experts from A Security discovered that AI managed to develop a working exploit for Zoom, allowing silent takeover of participants' devices during video calls. The vulnerability affected all major operating systems — Windows, macOS, Linux, iOS, and Android.
How AI found the vulnerability in Zoom
Specialists used fewer than 20 text prompts to have the AI identify gaps in the screen-sharing protocol and create an attack scenario. Previously, a similar task required a team of five highly qualified specialists and about six months of work. Now, AI handled it in less than 24 hours, demonstrating a radical lowering of the barrier to entry into cybercrime.
Attack mechanism: silent device takeover
The vulnerability was located in the protocol responsible for real-time drawing and annotations during screen sharing. An attacker could use it to execute arbitrary code on the victim's device without their knowledge — without notifications and without any user action. This opened the path to full control over the gadget, including access to credentials and the ability to move laterally within a corporate network.
Why this is dangerous for businesses and ordinary users
Users perceive Zoom as a trusted environment — especially in the corporate sector, where the platform is the standard for online meetings. However, it is precisely this confidence that makes them vulnerable. A hacker who joined a call with a company employee could gain access not only to their PC but also to the organization's internal network, potentially leading to data leaks or financial losses.
Conflicting data
While most sources confirm the fact of the vulnerability and its fix, there are discrepancies in the details. For example, TechRepublic states that the exploit was created in "less than 24 hours," whereas Wired emphasizes that the AI required "less than 20 prompts" — which could mean several hours or even minutes depending on the generation speed. There is also no consensus on whether the vulnerability was already used in real attacks before its discovery — some sources suggest it might have been exploited "in the wild," while others believe it was found solely during research.
Zoom's response and recommendations for users
Zoom developers reacted quickly to the threat: updates were released on both the server side and in client applications for all platforms. The company urged users to immediately update the app to the latest version. Experts also recommend enabling two-factor authentication, limiting screen-sharing access, and regularly checking security settings in Zoom.
This incident served as another reminder that in the age of AI, cyber threats are becoming faster, more accessible, and more dangerous. The democratization of hacking capabilities means that even inexperienced attackers can cause serious damage — and protection must be one step ahead.