ZOOMSDAY AI-discovered zero-click Zoom RCE exploit chain CVE-2026-53413 53414 53415
A researcher used fewer than 20 AI prompts to build a working zero-click exploit chain for Zoom in under 24 hours, a task that used to take five people about six months. The flaws let any meeting participant silently run code on another attendee's device, no click needed. Zoom ha
Security researchers at A Security have disclosed ZOOMSDAY, a critical zero-click remote code execution exploit chain in Zoom's screen-sharing annotation feature. The three vulnerabilities, tracked as CVE-2026-53413, CVE-2026-53414 and CVE-2026-53415, could have allowed any participant in a Zoom meeting to silently execute arbitrary code on another attendee's device across Windows, macOS, Linux, iOS and Android, with no click, download or other interaction required from the victim. What stands out is how the flaws were found: a single researcher used fewer than 20 prompts on publicly available AI models to uncover the vulnerabilities and develop a working exploit chain in under 24 hours, a process the researchers say previously required a team of about five people roughly six months of work. Zoom has since patched the issue. The case illustrates how AI tools are compressing the time needed to find nation-state-grade bugs from months down to hours, narrowing the gap between what state-backed hacking teams and independent researchers can accomplish and raising the bar for how fast software vendors need to respond once a flaw class becomes findable at scale. Sources: CSO Online, eSecurity Planet, Privacy Guides.