AI Security Firm Discovers Nation-State-Grade Zoom Vulnerability in One Day
Ⓐ used publicly available AI models to find a zero-click remote code execution flaw in Zoom affecting all platforms; company patched before disclosure.
Conversation activity · last 11 hours peak 2/15m
Summary, timeline and people extracted by Claude from 10 items across 4 sources · 4h ago. Quotes are verbatim.
A security firm called Ⓐ discovered a critical zero-click remote code execution vulnerability in Zoom using an AI agent and publicly available frontier models in a single working day. The flaw allowed attackers participating in a meeting to execute malicious code on all participants across Windows, macOS, iOS, and Android without user interaction. Zoom patched the vulnerability before publication, but the discovery underscores how AI has collapsed the barrier to producing nation-state-grade exploits that previously required months and elite teams.
- An AI-powered security firm discovered a zero-click remote code execution vulnerability in Zoom affecting all platforms in a single day—a complexity level that previously required nation-state resources and months of work.
- The vulnerability allowed any meeting participant to compromise all other participants' devices without user interaction; Zoom patched it before public disclosure.
- The discovery demonstrates that AI has fundamentally lowered the barrier to creating nation-state-grade exploits, requiring traditional security defenses built for scarcity to be rethought.
- Zoom is critical infrastructure for 70% of Fortune 100 companies, the Fortune 500, federal agencies, and millions of personal communications with doctors, lawyers, and families.
How it unfolded
-
A security firm using AI agents and publicly available frontier models discovered a critical zero-click remote code execution vulnerability in Zoom's Android client (version 7.0.4) that could be exploited by any meeting participant to compromise all other participants' devices.
“Ⓐ found a critical, nation-state-grade vulnerability in Zoom in a single working day using an AI agent and models anyone can access today.”
Ⓐ (research disclosure) · Hacker News ↗ -
Zoom's security team responded quickly to private disclosure and shipped a fix before the vulnerability was publicly disclosed.
-
Report Security details published
Ⓐ published technical analysis showing the vulnerability worked across all Zoom platforms, required no user interaction, and affected 70% of Fortune 100 companies using Zoom for critical communications.
“The flaw allowed an attacker to take control of a device during any live Zoom call, with no action required from the victim, no click, no download.”
Ⓐ (research disclosure) · Hacker News ↗ -
Researchers emphasized that the discovery represents a fundamental shift in the threat landscape: the barrier to producing nation-state-grade exploits has collapsed with AI access, and traditional security defenses built for scarcity are now inadequate.
“The barrier to producing this class of weapon has collapsed, and it won't come back.”
Ⓐ (research disclosure) · Hacker News ↗
What people are saying verbatim
“Ⓐ found a critical, nation-state-grade vulnerability in Zoom in a single working day using an AI agent and models anyone can access today.”
Ⓐ, Security research firm · Ⓐ research disclosure ↗
“The flaw allowed an attacker to take control of a device during any live Zoom call, with no action required from the victim, no click, no download.”
Ⓐ, Security research firm · Ⓐ research disclosure ↗
“Exploits like this one are weapons. Governments regulate their export. Criminal organizations pay millions for them.”
Ⓐ, Security research firm · Ⓐ research disclosure ↗
“The barrier to producing this class of weapon has collapsed, and it won't come back.”
Ⓐ, Security research firm · Ⓐ research disclosure ↗
“This matters beyond Zoom. Zoom is a core infrastructure for 70% of the Fortune 100, most of the Fortune 500, and federal agencies.”
Ⓐ, Security research firm · Ⓐ research disclosure ↗
“The only durable response is to turn the same capability inward, testing your own environment continuously, before an adversary gets there.”
Ⓐ, Security research firm · Ⓐ research disclosure ↗
Voices from the web unedited
-
Zoom has patched a bug that could have allowed an attacker participating in a meeting to run malicious code across all participants The Zoomsday bug required no interaction from meeting participants and worked across all Zoom OS clients https:// a.security/blog/asecurity-zoom sday
-
# Zoom Patches “#Zoomsday” Zero-Click Flaw Enabling Remote Code Execution https:// securityaffairs.com/197042/hac king/zoom-patches-zoomsday-zero-click-flaw-enabling-remote-code-execution.html # securityaffairs # hacking
-
Zoom Zero-Click RCE Crisis: Four Vulnerabilities Put Millions of Video Meetings Under the Microscope + Video A Dangerous Flaw Hidden Inside Everyday Meetings Zoom has patched four security vulnerabilities, including a serious zero-click remote code execution vulnerability identified as CVE-2026-53413. The flaw affects Zoom's annotator…