Zoom Vulnerability Allowed Remote Device Takeover on iPhone and Mac

A recently discovered vulnerability in Zoom’s video conferencing platform enabled attackers to remotely execute code on users’ devices, including iPhones and Macs. This flaw affected all operating systems supported by Zoom, such as Windows, macOS, Linux, iOS, and Android.

The security firm A Security identified the issue and reported it to Zoom, which has since released a patch to address the problem. Notably, the vulnerability was uncovered using publicly available AI models, requiring fewer than 20 prompts to identify and exploit the flaw. This rapid discovery underscores the growing role of artificial intelligence in both cybersecurity research and potential exploitation.

Omer Gull, co-founder of A Security, highlighted the ease with which AI facilitated the discovery, stating that what previously required a team of five people working for six months could now be achieved with minimal AI prompts. He emphasized the trust users place in platforms like Zoom, making such vulnerabilities particularly concerning.

Zoom has faced security challenges in the past. In 2019, a zero-day vulnerability allowed unauthorized access to Mac users’ webcams. The company addressed this issue by removing the hidden web server that facilitated the exploit. Additionally, in 2020, vulnerabilities were found that could expose Windows users’ credentials and grant unprompted access to cameras and microphones. Zoom responded by implementing fixes and enhancing its security measures.

Given the widespread use of Zoom for professional and personal communication, users are strongly advised to update their applications to the latest version to mitigate potential risks. This incident also highlights the dual-edged nature of AI in cybersecurity, serving as a tool for both defense and exploitation. As AI continues to evolve, its impact on security practices will likely grow, necessitating vigilant monitoring and adaptation by both developers and users.