A newly disclosed set of Zoom vulnerabilities has highlighted a security scenario in which one meeting participant could compromise another participant’s device without the target clicking a link, downloading a file, or approving any action. Israeli cybersecurity firm A Security said its researcher found three flaws and assembled a working exploit in less than 24 hours using fewer than 20 prompts with publicly available AI models.

The firm dubbed the attack “Zoomsday” and said the bugs involved Zoom’s annotation feature, which allows users to draw or place notes on shared content. According to the report, successful exploitation could let an attacker run code on the victim’s machine, potentially enabling theft of personal data, malware installation, or access to a device’s microphone and camera.

Three vulnerabilities across multiple platforms

The disclosed issues are tracked as CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415. A Security said it tested the attack path against Zoom applications on Windows, macOS, Linux, Android, and iOS, indicating the risk was not limited to a single operating system.

The researchers said the attack could be launched from either side of a meeting. A compromised presenter could target attendees, and a participant could also attack the presenter. In both cases, the attacker only needed to host or join the meeting and send the malicious data needed to trigger the vulnerabilities.

A Security said the victim would receive no visible warning that the device had been compromised, making the technique a zero-click attack in practical terms once both parties were in the same call.

Why the findings matter for crypto users

The disclosure is especially relevant to the cryptocurrency sector because video calls have already been used repeatedly as a path into wallets, private files, and other sensitive systems. Founders, developers, investors, and executives have been frequent targets in campaigns that begin with a message from a trusted contact and then shift into a Zoom or Teams meeting.

In previously reported cases, attackers typically still needed some cooperation from the victim, often by claiming there were audio problems and pushing a fake update or script during the call. A Security’s report suggests the Zoomsday chain removed that hurdle on vulnerable Zoom clients, because simply sharing the same meeting could be enough to reach the target machine.

That distinction matters in light of recent incidents. In September 2025, THORChain co-founder JP Thor said he lost about $1.3 million after joining what appeared to be a legitimate Zoom meeting through an official link, where a deepfake of a friend was shown before a malicious script began copying files from his computer. Other cases involving Manta Network co-founder Kenny Li and investor Mehdi Farooq followed similar social-engineering patterns tied to compromised contacts and fake meeting updates.

AI-assisted research compressed the timeline

A Security said the researcher used fewer than 20 prompts with public AI models to identify the flaws and build a proof-of-concept exploit in under a day. The finding adds to a growing body of evidence that AI tools can accelerate vulnerability research in large and widely used software systems.

The source article pointed to a separate example from April, when Mozilla said an early version of Anthropic’s Claude Mythos identified 271 vulnerabilities in Firefox during internal testing. Mozilla said those flaws were patched and described the experiment as evidence that AI can help review large codebases at a speed that would otherwise require substantial human effort.

Patches are out, but older clients remain exposed

A Security said it reported the first Zoom vulnerability on June 10, two days after discovery, and then worked through the disclosure process while fixes were prepared. According to the researchers, Zoom released patches between June 22 and July 20.

The researchers also said updating the Zoom app is still required for users on older versions. A server-side defense meant to block malicious messages cannot fully inspect the same content in end-to-end encrypted meetings, which means backend protections alone cannot completely stop the attack path if a vulnerable client remains in use.

Zoom has separately advised users to keep their software current to receive the latest security fixes and improvements. Its July security bulletins also listed CVE-2026-53412, described as a critical improper input validation flaw in Zoom Workplace for Windows that could allow an unauthenticated attacker to carry out an account takeover through network access. The next confirmed step for affected users is straightforward: run the latest Zoom version, because A Security said patched clients are necessary to close the Zoomsday risk.

Source: crypto.news