BTC $63,408.97 -0.54%
ETH $1,876.68 -0.34%
BNB $610.73 -1.22%
XRP $1.00 -1.78%
SOL $75.63 -0.97%
TRX $0.3357 +0.41%
DOGE $0.0698 -3.33%
ADA $0.1813 -2.90%
BCH $214.05 +0.16%
LINK $8.63 -1.59%
HYPE $56.28 +3.18%
AAVE $88.00 -1.15%
SUI $0.6828 -2.14%
XLM $0.1598 -1.36%
ZEC $488.00 +1.53%
BTC $63,408.97 -0.54%
ETH $1,876.68 -0.34%
BNB $610.73 -1.22%
XRP $1.00 -1.78%
SOL $75.63 -0.97%
TRX $0.3357 +0.41%
DOGE $0.0698 -3.33%
ADA $0.1813 -2.90%
BCH $214.05 +0.16%
LINK $8.63 -1.59%
HYPE $56.28 +3.18%
AAVE $88.00 -1.15%
SUI $0.6828 -2.14%
XLM $0.1598 -1.36%
ZEC $488.00 +1.53%

Researchers discovered a Zoom vulnerability using fewer than 20 AI prompts and built an attack chain within 24 hours

2026-08-13 09:08:56

According to a report by Decrypt, Israeli cybersecurity company ASecurity released a report stating that a researcher used publicly available AI models to discover multiple vulnerabilities in the Zoom annotation tool in less than 24 hours with fewer than 20 prompts, and constructed an exploitable attack chain. The vulnerabilities are numbered CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415, allowing attackers to remotely execute code in meetings without any action from the victim, control their devices, steal data, and activate the microphone or camera.

The attack was tested successfully on Windows, macOS, Linux, Android, and iOS versions of Zoom. ASecurity claimed it reached a "national-level" standard, whereas previously constructing such exploitation tools required months of work and a substantial budget from professional teams. ASecurity reported the first vulnerability to Zoom on June 10, and Zoom released fixes between June 22 and July 20, but the server-side protections in end-to-end encrypted meetings could not filter malicious messages, requiring users to update manually. A Zoom spokesperson confirmed that the issue has been resolved and advised users to keep their versions up to date.

app_icon
ChainCatcher Building the Web3 world with innovations.