Search TorNews

Find cybersecurity news, guides, and research articles

Popular searches:

Home » News » Cyber Threats » AI Helps Researcher Find Critical Zoom Zero-Click Flaw in Under 24 Hours

AI Helps Researcher Find Critical Zoom Zero-Click Flaw in Under 24 Hours

Last updated:August 12, 2026
Human Written
  • A researcher used simple AI prompts to find a dangerous Zoom bug called “Zoomsday.”

  • The flaw lets attackers take over a device just by joining a meeting. No clicks needed.

  • Zoom has since fixed the bug, but the case raises new fears about AI-powered hacking.

AI Helps Researcher Find Critical Zoom Zero-Click Flaw in Under 24 Hours

Hackers usually need weeks to find flaws in closed software like Zoom. A researcher at A Security just did it in under a day. The team used fewer than 20 prompts on public AI tools to find and build a working exploit.

They named the bug “Zoomsday.” According to the report, the whole process, from discovery to a working exploit, took less than 24 hours. That speed has security experts worried.

How the Zoomsday Bug Worked

The bug lived inside Zoom’s annotation tool. This feature lets people draw, type, or add shapes on a shared screen. Zoom built its own private system to run this feature. That system reads and processes messages sent by other people in the call.

The security found a flaw in how that system checks incoming messages. An attacker could craft a message that breaks the memory checks. Once sent, that message could let the attacker run code on someone else’s device.

And the target never had to click or download a thing. According to CyberInsider, the flawed code trusted certain values from the sender. It did not check them properly against the size of the data storage.

AI tools played a big role in this discovery. According to A Security, the AI models helped sort through Zoom’s code. They pointed researchers toward the annotation tool as a likely weak spot. The models also helped rebuild Zoom’s private protocol from scratch, since it isn’t public. This let the team spot the unsafe memory issue much faster than usual.

The bug hit every major platform. Security confirmed the exploit worked on Zoom’s apps for Windows, macOS, iOS, Android, and Linux. Simply being present in a call was enough to put a device at risk.

Why this Flaw was so Dangerous

Once an attacker gained control of a device, the risks grew fast. They could steal files, turn on a camera or microphone, or plant more harmful software. Nobody in the meeting would see a warning sign.

The flaw actually covers three separate bugs. They’re tracked as CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415. A Security rated all three as critical, giving them a severity score of 9.0. Other outlets, like SOFX, report that Zoom itself scored the bugs somewhat lower, between 6.5 and 8.3. Zoom also said user interaction was needed for some of the flaws, which differs slightly from A Security’s zero-click claim.

Mozilla addressed a different type of privacy risk in Firefox 150 and Tor Browser 15.0.10, patching CVE-2026-6770 which could allow websites to link user activity across private sessions.

A security researcher reported the issue to Zoom on June 10, 2026. Zoom responded the next day and started work on a fix. The company released a client-side patch in version 7.1.0 on June 22. It followed up with a server-side shield in July, then closed the remaining gaps by July 20. Security waited until August 11 to share the full details publicly. This gave Zoom time to protect its users first.

This story goes beyond just one app. Normally, finding bugs like this takes large teams, months of work, and big budgets. Security says AI tools are changing that. A single researcher can now do work that once needed a whole specialist group. Outlets such as CSO Online and Security Affairs also covered the discovery this week, echoing those concerns.

What Zoom Users Should Do Now

First, update your Zoom app right away. Older versions still carry the risk. Go to your app settings and check for the newest update today.

Second, limit who can join your meetings. Use waiting rooms or approval settings where you can. Fewer strangers in your call means fewer chances for attacks.

Third, turn off features you don’t need. If you rarely use the annotation tool, disable it in your settings. That closes one more door for attackers.

Fourth, keep an eye out for Zoom’s own safety notices. The company may release more guidance or patches soon. Following their instructions quickly matters most.

This case tells two stories at once. One is about a serious flaw in an app millions of people use daily. The other is about how fast AI is changing the hacking world. The same tools that help companies defend their software can also help attackers break in faster. As AI keeps improving, both sides of this race will keep moving quicker than before.

Share this article

About the Author

Memchick E

Memchick E

Digital Privacy Journalist

Memchick is a digital privacy journalist who investigates how technology and policy impact personal freedom. Her work explores surveillance capitalism, encryption laws, and the real-world consequences of data leaks. She is driven by a mission to demystify digital rights and empower readers with the knowledge to protect their anonymity online.

View all posts by Memchick E >
Comments (0)

No comments.