Israeli Cybersecurity Researchers Use AI to Quickly Uncover Critical Zoom Vulnerability
Researchers at Israeli cybersecurity firm A Security discovered a critical vulnerability in Zoom by sending fewer than 20 prompts to a publicly accessible AI model within 24 hours. Without AI, identifying this flaw would have required months of work by a skilled team of five to six experts. Idan Lavkovitz, a vulnerability researcher at A Security, explained that their mission is to protect against AI-based attacks by investigating critical modern infrastructures. He emphasized that Zoom is widely used by major corporations, governments, and families, and the vulnerability they found allows remote takeover of any device during a video call.
The researchers focused on Zoom's Android app, whose code libraries are publicly available. Their AI prompts were complex instructions guiding the AI agent to analyze the software code, identify bugs, and detect potential entry points, rather than simple commands like "find a security flaw." The vulnerability relates to Zoom's feature that lets users draw and write on the screen while sharing it during calls. Exploiting this flaw enables attackers to execute malicious code on the victim’s device, steal data, remotely activate the camera and microphone, or install malware without any user action or visible signs.
Zoom has since patched the vulnerability in updated app versions, but it previously affected all versions across Windows, Mac, iPhone, Android, and Linux devices. While AI-assisted vulnerability detection still requires cybersecurity expertise, it significantly lowers the barrier to discovering critical flaws, enabling even less experienced actors to operate like advanced threat groups. Lavkovitz highlighted the broader implications, noting Zoom’s role as a core platform for 70% of Fortune 100 companies, most Fortune 500 firms, and federal agencies, as well as millions of users connecting with doctors, lawyers, and families.
He stressed that the real issue is the speed at which such weaponized tools can now be created, dismantling previous barriers. Security defenses designed for a world where such tools were rare are no longer effective. Lavkovitz urged security managers to proactively apply these AI capabilities internally to continuously assess their environments before adversaries exploit them.