415.tech
AI & tech, from the frontlines of Silicon Valley
Zoom zero-click RCE built in under 24 hours with public AI models

Zoom zero-click RCE built in under 24 hours with public AI models

Ⓐ Security chained three memory-corruption bugs in Zoom's proprietary annotation protocol (CVE-2026-53413/53414/53415, CVSS 9.0) into zero-click remote code execution against every participant on Windows, macOS, Linux, iOS and Android — built in under 24 hours with fewer than 20 prompts to publicly available models. Zoom patched in v7.1.0 and v7.1.5, but any Workplace client below 7.1.5 or 7.0.6 running end-to-end encryption is still exposed, and the server cannot filter the payload when E2EE is on. The finding that matters is the cost curve: exploit development against closed-source enterprise software, previously a nation-state capability measured in months and millions, now fits in one working day.

Source: a.security

Post on XEmail

The entire operation, from finding the flaw to building a working exploit, was carried out by Ⓐ using fewer than 20 prompts on publicly available AI models in under 24 hours.

Ⓐ Security

Why this matters

  • → Nation-state-grade exploit now possible in 24 hours with public AI models
  • → Attack hits 70% of Fortune 100 in zero-click, undetectable compromise
  • → Defender assumptions about closed-source obscurity no longer hold
Weapons-grade AI