Researchers say a public artificial intelligence tool needed fewer than 20 prompts to identify a Zoom flaw that could let a caller hijack another participant’s device. The vulnerability has since been fixed, but the finding shows how quickly widely available AI systems may assist security research and potential attacks.
The reported test involved a public AI tool rather than a private system built for cybersecurity work. That detail raises concern because such tools are easy to access and can rapidly review code, suggest tests, and refine possible attack methods.
A Short Path to a Serious Discovery
The researchers reported that the AI system found the flaw after a brief exchange with its users.
It took “fewer than 20 prompts” for the public AI tool to find the vulnerability, according to the researchers.
The flaw could have allowed anyone on a Zoom call to take control of another participant’s device. That type of access can pose serious risks, including data theft, surveillance, or unauthorized changes to a computer.
Key technical details were not disclosed in the available account. It did not identify the AI tool, the affected Zoom product, or the operating systems at risk. The account also did not state whether attackers had exploited the flaw outside the research setting.
Zoom fixed the vulnerability, removing the reported path to device hijacking. Users should still install current Zoom updates because security fixes offer limited protection until they reach individual devices.
AI Changes the Speed of Security Testing
Security researchers have long used automated tools to inspect software and find weak points. Public AI adds a conversational layer. A user can ask the system to assess code, explain unusual behavior, or suggest another test within seconds.
The number of prompts does not reveal the full amount of work involved. Researchers may have selected the target, prepared relevant material, checked the model’s output, and confirmed the flaw through separate tests. AI responses can also be inaccurate and require expert review.
Even with those limits, the short exchange matters. It suggests that AI can reduce the time needed to develop a useful theory about a software weakness. That may help defenders find defects before criminals do. It may also lower the skill or time needed for malicious users to search for similar problems.
Disclosure and Access Shape the Risk
The case highlights several issues for software companies and security teams:
- Vendors may need faster systems for receiving and verifying AI-assisted reports.
- Researchers must avoid exposing users while confirming serious flaws.
- AI providers face pressure to restrict requests that directly support device compromise.
- Organizations need rapid patching plans for widely used meeting software.
There is also a balance to maintain. Broad restrictions could block legitimate security work, while weak controls could make harmful guidance easier to obtain. Clear disclosure rules and careful testing can help separate defensive research from abuse.
What Users and Companies Should Watch
The fixed Zoom flaw is one example of a larger shift in software security. AI can support code review and vulnerability discovery, but it can also accelerate attempts to exploit defects.
For users, the immediate step is simple: keep Zoom and device software updated. Companies should also limit meeting privileges, monitor unusual activity, and train staff to report unexpected device behavior.
The next test will be whether vendors can match the speed of AI-assisted discovery with faster fixes and distribution. The Zoom case ended with a patch. Its wider warning is that future flaws may be found with fewer steps, by a larger group of people, and with less time for defenders to respond.