The flaws live in libannotate.so, the component that handles the drawings, shapes and text people share on screen during a call. A malicious annotation object triggers an unbounded copy in CAnnoFormatBlock::Deserialize, corrupting memory. A second flaw leaks heap memory back, and a third gives a write-what-where primitive. Together they hand the attacker control of the process, on every platform, with no user interaction. Server-side filtering that Zoom deployed does not help end-to-end encrypted meetings, where the server cannot see the payload.
The researcher reported finding and weaponising the chain with fewer than twenty prompts to publicly available AI models, in under a day. Read that twice. The capability to build a zero-click exploit for a mainstream product, until recently the preserve of well-funded teams, was reproduced with consumer tools over an afternoon. The vulnerability will be patched. The economics will not go back.
The practical consequence is speed. The window between a product flaw existing and a working exploit existing is collapsing. Defence that assumed weeks of attacker effort now has days, and planning that leaned on “nobody would bother” has lost its main assumption.
If exploits arrive faster, the value of a maintained risk picture goes up, not down. When a zero-click hits a tool that touches your whole organisation, the useful questions are immediate: which business processes depend on this tool, who owns the response, what is our patch status across managed and unmanaged fleets. Those are register questions. The collaboration client is not a low-criticality asset because it is familiar; a single message compromising every participant is a maximum-impact scenario, and it should have been scored that way before the news broke. Cheaper exploits do not change what you should track. They shorten the time you have to already know it.
Technical breakdown and the AI-assisted discovery from the aSecurity research write-up.
In a 45-minute session we run your own scope through SynapseRM: requirements, findings, scored risks, register entry. You keep the output either way.
A Belgium-based provider of cybersecurity solutions, and the team behind SynapseRM / TPRM.