Tom's Hardware reports that researchers at A.Security developed a Zoom Workplace exploit that could let one meeting participant gain remote code execution on another participant's device. The report says the exploit, dubbed Zoomsday, targeted Zoom's annotation functionality and could work without the victim using the whiteboard feature. The vulnerability has been patched, according to the report. Tom's Hardware says the affected software was Zoom Workplace before version 7.0.6, and before version 7.1.5 for users on the fast-track branch. The outlet reports that users who have updated Zoom Workplace to the current version should be safe. The technical path, as described by Tom's Hardware, involved two remote code execution vulnerabilities in a library used by Zoom's annotations. The report says annotation objects were handled in serialized form, with count fields telling the recipient how much data to read. The vulnerable code allegedly lacked a maximum-size boundary check, creating a buffer overrun condition. That matters because the feature did not need to be actively used by participants, according to the report. Tom's Hardware says the code path was active during a meeting, so an attacker only needed to join the meeting to reach the vulnerable surface. The outlet characterizes the resulting access as full remote code execution at the user level, not administrator or kernel-level access. A.Security's most striking claim is about speed. The firm says a small team developed the exploit with only 20 prompts to an AI agent, according to Tom's Hardware. The researchers initially decompiled the Android package and asked an AI agent to rank possible attack surfaces, then shifted attention to the communications protocol, where they found the annotation-handling weakness. Tom's Hardware frames the case as another sign that AI-assisted vulnerability research is compressing exploit-development timelines. The report quotes A.Security as arguing that the old model requiring elite teams, months of work, and large budgets has broken down. That is the researchers' claim, not yet corroborated by another item in this cluster. The potential exposure is large because of Zoom's reach. Tom's Hardware cites recent estimates of about 220 million monthly active Zoom users and roughly 56% share of the global conferencing market. Those figures do not mean all users were exploited, but they show why a remotely reachable meeting bug in a widely deployed conferencing app is high-stakes. For operators, the immediate action is straightforward: verify that Zoom Workplace is updated to the current version. For security teams, the larger issue is process: proprietary, closed communications software can still present attack surfaces that AI-assisted research may help explore faster than legacy disclosure calendars assume. Who benefits: Users and organizations that have updated Zoom Workplace to the current version benefit from the reported fix. Security teams also gain a concrete case study for reassessing patch urgency around collaboration tools. Who's exposed: Organizations running affected Zoom Workplace versions are the clearest exposed group based on the report. The risk is especially relevant where external participants can join meetings.