Article
Security & Privacy

Update Zoom first. Then read how an AI found the flaw in under 20 prompts

The 'Zoomsday' bug let one person on a call take over other participants' devices. The fix is out. The way it was discovered is the real story.

by Whatsnew Newsroom
A dystopian scene featuring a ruined cityscape under a stormy sky, with falling meteors and debris. Prominently displayed is the word 'Zoomsday' along with the Zoom logo, implying a humorous take on virtual meetings taking over amidst chaos.

Two facts arrived together this week, and they deserve to be taken in the right order. The first: a vulnerability in Zoom's screen-sharing let a participant on a call take over other participants' devices, and it has now been fixed — so make sure your Zoom is current before doing anything else today, and extend the same courtesy to the forgotten laptop that only exists for Monday meetings. The second fact is the one that will still matter in a year: the flaw was found by a publicly available AI tool, in fewer than twenty prompts.

Consider what a finding like this used to cost. Vulnerabilities of the take-over-the-other-person's-machine class are the trophies of the security world — the product of skilled researchers, specialist tooling and weeks of patient work. The researchers who surfaced this one, and promptly named it "Zoomsday", did not spend weeks. They described a short conversation with an off-the-shelf AI model. Under twenty prompts sits somewhere between an afternoon and a coffee break.

The security industry has been predicting this moment for some time — AI models that can hunt software flaws at scale have been the subject of solemn conference talks and, lately, restricted-release frontier models. What the Zoom episode demonstrates is less grand and more unsettling: the capability is no longer confined to frontier labs and their vetted partners. A public tool found a real, serious hole in software used daily by hundreds of millions of people, when asked nicely.

The same capability points both ways, of course. The people who found Zoomsday were researchers, who disclosed it, which is why there is a fix for you to install. Companies can — and now clearly should — run the same interrogation against their own products before someone else does. The uncomfortable part is arithmetic: there are many more curious people with access to a public AI tool than there are security teams, and the flaws they will find are not all in Zoom.

What should an ordinary person do with this knowledge? Nothing heroic. Let your software update itself, promptly and automatically, because the window between a flaw's discovery and its repair is the only place this ever hurts you — and that window is now being opened by machines working at conversational speed. Assume the next Zoomsday is being prompted somewhere already. The patching side of the race has the same tools. It just has to remember to use them.

by Whatsnew Newsroom
whatsnew. APPS · WEB TOOLS · SECURITY · AI

Know what’s new.

The useful side of the internet. Covered properly.

Set as preferred →

Related Stories