A cybersecurity team built a working exploit for a critical Zoom vulnerability in under a day using fewer than 20 prompts on publicly available AI models, a demonstration that researchers say is shrinking the gap between elite offensive hacking and widely accessible AI tools.
- A cybersecurity team built a working exploit for a critical Zoom vulnerability in under a day using fewer than 20 prompts on publicly available AI models, a demonstration that researchers say is shrinking the gap between elite offensive hacking and widely accessible AI tools.
- Black Hat's 2026 programme included more than 100 peer-reviewed briefings and highlighted AI and autonomous threats as a central topic.
- A vulnerability can exist for years without being weaponized, but the time needed to turn its discovery into an operational exploit may now be measured in hours.
The vulnerability allowed a malicious participant in a Zoom meeting to execute code on another participant’s device through the platform’s annotation feature, according to researchers at A Security. The attack required no action from the victim and could expose data, activate the device’s camera or microphone, or install malware. Zoom has since patched the flaw.
The demonstration was presented against the backdrop of Black Hat USA, where AI-powered vulnerability discovery, exploit generation and autonomous threats were among the conference’s major research themes. Black Hat’s 2026 programme included more than 100 peer-reviewed briefings and highlighted AI and autonomous threats as a central topic.
Researchers Compressed Months Of Work Into A Day
A Security said it found the Zoom flaw in early June and developed a working exploit with an AI agent using publicly available models.
The team said the process took fewer than 20 prompts and less than 24 hours, according to the researcher’s disclosure and reporting on it.
Have a development worth tracking?
Share product launches, funding announcements, partnerships, research findings and market developments with The Grey Terminal's readership.
→ Submit a Press Release“Producing a working exploit against it has always been nation-state work: elite teams, months of effort, budgets that governments regulate as weapons,” A Security vulnerability researcher Idan Levcovich wrote.
“A [Security] did it in a single day, with an AI agent and models anyone can access today,” he wrote.
The “nation-state-grade” characterization belongs to the researchers, not an independent government classification.
What changed in the demonstration was not the underlying Zoom vulnerability, but the time and expertise needed to turn it into a working attack.
Zoom Meeting Participants Could Be Targeted
The flaw sat in Zoom’s real-time annotation system, which lets participants draw on a shared screen during a meeting.
An attacker could exploit the feature to run malicious code on another participant’s device without requiring the victim to click a link, approve a request or otherwise interact with the attack.
A Security said the compromise produced no obvious visual indication to the victim.
The researchers said the exploit could allow attackers to steal information, turn on the camera or microphone and install malware.
The vulnerability affected Zoom applications across Windows, macOS, Linux, Android and iOS, according to reporting on the disclosure. Zoom issued fixes for the affected software.
The research did not show that criminals were using this specific Zoom exploit against victims.
It showed that publicly available AI tools could materially accelerate the process of finding and weaponizing the vulnerability.
AI Is Moving Deeper Into Offensive Cyber Work
The Zoom demonstration came as researchers at Black Hat examined a wider shift in how AI is being used in offensive security.
Black Hat’s conference programme included work on AI-powered vulnerability discovery, exploit generation and autonomous threats, alongside sessions focused on how defenders can respond to increasingly automated attacks.
The conference framing is broader than AI-assisted coding.
The issue is whether models can take on enough of the work involved in reconnaissance, vulnerability analysis and exploit development to compress the time between discovering a weakness and producing something attackers can use.
A Security’s Zoom demonstration provides one measurable example of that compression: fewer than 20 prompts, less than a day and a working exploit.
The Barrier Is Falling, Not Disappearing
The experiment does not mean that anyone with access to a chatbot can immediately reproduce every advanced cyberattack.
Researchers still had to identify the target, validate the vulnerability, direct the model and test the resulting attack. The work also depended on an existing flaw in Zoom’s software and the researchers’ ability to work with its underlying protocol.
But the researchers’ warning is about the economics of offensive work.
Tasks that once demanded large teams, specialist knowledge and long development cycles can increasingly be broken into smaller pieces that AI systems can perform or accelerate.
That can widen the pool of people capable of attempting sophisticated vulnerability research, even when the underlying technical challenge has not become simpler.
Zoom Fixed The Vulnerability
Zoom has patched the vulnerability disclosed by A Security.
The company says its security bulletins contain the latest fixes and recommends users keep Zoom software updated.
The immediate Zoom risk has therefore been addressed through software updates.
The wider issue raised at Black Hat is harder to patch: the same publicly available AI systems that can help developers and security researchers can also lower the time and expertise required to turn software weaknesses into working attacks.
That leaves defenders facing a faster development cycle on the offensive side.
A vulnerability can exist for years without being weaponized, but the time needed to turn its discovery into an operational exploit may now be measured in hours.
Activate Terminal Layer
Structural analysis of the systems, pressures, and stakeholders behind this story.





