A Zoom vulnerability discovered with the help of an AI tool gave an attacker the ability to remotely execute code on whatever device a meeting participant was using, including both iPhone and Mac …
Wired reports:
Researchers [found] vulnerabilities in the video conferencing platform Zoom that could have been exploited to take over targets’ devices. Anyone on a call that involved screen sharing, whether participants or the host, would have been vulnerable to a silent attack that could be carried out with no indication and no interaction from the victim. [It] affected devices running all operating systems that Zoom supports—Windows, macOS, Linux, iOS, and Android.
Cybersecurity firm A Security disclosed the vulnerability to Zoom and it has now been patched. However, it says the truly frightening thing was just how easy it was to use AI to find the flaw.
The bug was discovered in early June using publicly available AI models, and it took fewer than 20 prompts to uncover the vulnerabilities and create a working attack […] A Security cofounder Omer Gull told WIRED ahead of the disclosure: “Before it would have taken a team of five people maybe six months with a lot of refining and iteration to find this. Now people can reach the same results with under 20 prompts. And Zoom is an important type of target because people assume trust when using it. They don’t see it as a threat.”
Wired’s Lily Newman notes that Gull briefed her on the story in a video call taking place on … Microsoft Teams.
Photo: LinkedIn/Unsplash