‘Zoomsday’ hack uncovered using fewer than 20 AI prompts
AI Summary
A security vulnerability in Zoom was discovered that could allow attackers to hijack user devices during meetings using AI-generated prompts. The exploit targeted Zoom's annotation feature, risking data theft and unauthorized access, but the flaw has since been patched.
Zoom has patched a major security vulnerability that could allow an attacker to hijack anyone's device during a meeting. In a blog post on Tuesday, researchers at A Security say they uncovered the flaw using "fewer than 20 prompts on publicly available AI models," as reported earlier by Wired. The exploit involved Zoom's annotation feature, which allows users to draw on their screen while sharing it with other meeting participants. With the exploit, an attacker could join or host a meeting and run malicious code on victims' devices, allowing them to steal data, turn on the camera or microphone, or install malware. The attack required no act … Read the full story at The Verge.