Critical 'Zoomsday' flaw enables total device takeover during Zoom calls — AI-assisted research only used 20 prompts to find an exploit to hack hundreds of millions of people.
Zoomsday vulnerability let anyone in a Zoom meeting take over anybody else. The vulnerability was developed with AI assistance and took research only used 20 prompts to find an exploit to hack hundred of millions of people.
Zoomsday, a critical flaw in Zoom's software, allows attackers to take complete control of a user's device during a Zoom call, according to researchers at A.Security. The exploit, discovered with just 20 prompts to an AI agent, enables any participant in a Zoom meeting to gain unauthorized access to another user's computer and data.
Zoom Workplace before versions 7.0.6 and 7.1.5 contains two remote code execution (RCE) vulnerabilities in its annotation functionality, though users don't need to utilize the whiteboard for the exploit to be effective. The exploit works by taking advantage of a buffer overrun vulnerability within the program, which fails to check the size of an input.
An attacker can send a larger-than-expected input, overwriting part of the following memory with malicious code that will be executed. Zoom swiftly patched the vulnerabilities after the initial reports, and users who have updated to the latest version should be safe. The researchers note that AI-assisted vulnerability research, previously requiring significant resources, can now be accomplished with minimal effort and budget.
Written by urgent.news from Tom's Hardware's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.