Zoom has patched a major vulnerability that security researchers say could have let an attacker compromise participants’ devices during a meeting, according to The Verge. The report attributes the finding to researchers at A Security, who said in a Tuesday blog post that they uncovered the flaw using “fewer than 20 prompts on publicly available AI models,” with Wired having reported the finding earlier. The vulnerability centered on Zoom’s annotation feature, The Verge reports. That feature lets users draw on a shared screen during a meeting; A Security said the exploit path could allow an attacker who joined or hosted a meeting to run malicious code on victims’ devices. According to the researchers’ account summarized by The Verge, the potential impact was broad: data theft, turning on a camera or microphone, or installing malware. A Security also said the attack required no action from victims and showed no visual cue that a device had been compromised. Zoom issued a fix for the vulnerability on Tuesday, The Verge reports. The issue affected Zoom’s apps across Windows, macOS, Linux, Android, and iOS, according to the same report. The most important claim for security teams is the researchers’ account of how quickly they produced a working exploit. Idan Levcovich, a vulnerability researcher at A Security, framed the work as something previously associated with elite teams, long timelines, and government-scale budgets, but said A Security did it in a single day with an AI agent and publicly accessible models. That claim should be treated as a reported finding from A Security rather than a general rule about all vulnerability research. The provided material does not include independent technical validation, version numbers, a Common Vulnerabilities and Exposures identifier, or evidence that the flaw was exploited in the wild. Still, the disclosure is a useful marker for operators: collaboration software remains high-value attack surface, and AI-assisted exploit development is increasingly part of the security workflow described by researchers. For now, the concrete action is narrower and immediate—ensure Zoom clients across supported platforms are updated with Tuesday’s fix. Who benefits: Organizations that update Zoom quickly reduce exposure to the specific flaw described by A Security and The Verge. Security teams also gain another real-world example to use when reassessing patch urgency for collaboration tools. Who's exposed: Users and organizations running affected Zoom apps on Windows, macOS, Linux, Android, or iOS are the exposed population identified in the report. The provided material does not specify affected versions or whether any attacks occurred before the patch.