# 不到20条AI提示词即可利用的"Zoom末日"漏洞已被修复

- 来源：The Verge：AI（RSS）
- 作者：Emma Roth
- 发布时间：2026-08-11 22:45
- AIHOT 分数：51
- AIHOT 链接：https://aihot.virxact.com/items/cmsou0fa206morohd8712v4ng
- 原文链接：https://www.theverge.com/ai-artificial-intelligence/977909/zoom-vulnerability-ai-attack

## AI 摘要

安全公司A Security发现Zoom存在一个严重漏洞，攻击者可利用其注释功能在会议中劫持任意参会者设备，远程窃取数据、开启摄像头或麦克风、安装恶意软件，且无需受害者任何操作、无任何视觉提示。研究人员称仅用“不到20条提示词”的公开AI模型即发现该漏洞，并称此前此类利用需国家级团队数月努力。Zoom已于周二发布修复，影响覆盖Windows、macOS、Linux、Android和iOS平台。

## 正文

The Zoom vulnerability allowed hackers to take over everyone’s device on a call, security researchers say.

The Zoom vulnerability allowed hackers to take over everyone’s device on a call, security researchers say.

Zoom has patched a major security vulnerability that could allow an attacker to hijack anyone’s device during a meeting. In a blog post on Tuesday, researchers at A Security say they uncovered the flaw using “fewer than 20 prompts on publicly available AI models,” as reported earlier by Wired.

The exploit involved Zoom’s annotation feature, which allows users to draw on their screen while sharing it with other meeting participants. With the exploit, an attacker could join or host a meeting and run malicious code on victims’ devices, allowing them to steal data, turn on the camera or microphone, or install malware. The attack required no action from victims and showed “no visual cue indicating the compromise,” according to A Security.

“Producing a working exploit against it has always been nation-state work: elite teams, months of effort, budgets that governments regulate as weapons,” Idan Levcovich, a vulnerability researcher at A Security, writes in the blog post. “A [Security] did it in a single day, with an AI agent and models anyone can access today.” Zoom issued a fix for the vulnerability on Tuesday, which impacted the app across Windows, macOS, Linux, Android, and iOS.
