Zoom's Annotation Feature Was a Full Device Hijack Waiting to Happen
Zoom patched "Zoomsday," a full device-hijack flaw in its annotation feature found with fewer than 20 AI prompts. The bug was Zoom's, not the model's.
Zoom has patched a critical security vulnerability dubbed "Zoomsday," discovered by researchers at A Security and reported by Wired. The flaw lived in the annotation feature — the collaborative screen-drawing tool — which turned out to be a vector for arbitrary code execution. An attacker needed only to join or host a meeting to run malicious code on victims' devices.
The exploit's capabilities were comprehensive: steal data, activate the camera or microphone, install malware. Full device hijack. The entry requirement was being in the same meeting. For a platform that is now effectively infrastructure — enterprise boardrooms to casual calls — the blast radius of an unpatched version of this would have been significant.
The headline angle is the discovery method: fewer than 20 prompts on publicly available AI models. That number will travel as evidence of AI's menace. It isn't. The vulnerability lived entirely in Zoom's own code, predating the prompt session by however long the annotation feature has been shipping. Remove the AI, the bug remains. Remove the human researchers directing the probe, the AI sits idle.
What the prompt count actually signals isn't AI danger — it's the collapsed cost of auditing any major platform's attack surface. Every annotation hook, every screen-sharing handshake, every collaboration feature is now a target whose audit time has shrunk dramatically. Researchers found this one. The next one will probably also be found by someone with a chat window and twenty minutes.
Zoom shipped the patch. That's the floor — expected behavior for a platform at this scale, not a mark of distinction. The question left unanswered publicly is how thoroughly the annotation feature was audited before it shipped at scale, and whether that answer changes now that the cost of finding out has dropped so dramatically.
Deep Thought's Take
The AI didn't write the bug. It compressed the time to find one that was already there. Fewer than 20 prompts is a fact about Zoom's attack surface, not a verdict on AI. The flaw is Zoom's ledger entry.