Tech & Science
A cybersecurity firm used a general-purpose AI tool to rapidly identify a critical Zoom vulnerability that could enable remote device takeover across Windows, macOS, Linux, iOS, and Android—without user interaction.

A cybersecurity company has disclosed a critical vulnerability in the Zoom application that could have allowed attackers to gain full control over devices used by participants in Zoom video calls. The affected devices include smartphones running iOS and Android, as well as computers operating Windows, macOS, and Linux.
The flaw was tied specifically to Zoom meetings featuring screen sharing. Attackers could exploit it without requiring any action from the victim—no link clicking or manual confirmation was necessary. As a result, users participating in such calls might not have realized their devices were being targeted for compromise.
According to the report, the severity of the issue stemmed from its broad platform coverage. Because the vulnerability affected all operating systems supported by Zoom, it posed a significant concern for both individual users and enterprises relying on Zoom for daily communication and remote work.
Researchers at A Security identified the flaw with assistance from a general-purpose artificial intelligence tool. They reproduced the vulnerability using fewer than 20 inputs to the AI model. The researchers noted that manually discovering a vulnerability of this complexity would previously have taken months and required a specialized team—whereas AI drastically shortened the identification timeline.
The danger lies in the capacity of such vulnerabilities to serve as entry points: once an attacker gains access to a single user’s device, they may attempt to move laterally into other data repositories or internal systems—particularly when the compromised device is connected to a corporate or institutional network.
Following the discovery, the cybersecurity firm reported the vulnerability to Zoom. Zoom addressed the issue by updating its servers and client applications. The company also issued a security advisory detailing the steps taken to resolve the flaw.
This incident highlights an evolving dimension of the cybersecurity arms race: artificial intelligence is no longer merely a support tool for vulnerability detection—it can now significantly accelerate the identification of weaknesses that would otherwise demand extensive time and deep technical expertise to uncover manually.



