Connect with us

Tech

Zoom Zero-Click RCE: AI Helped Build an Exploit in Under 24 Hours

Published

on

A critical Zoom vulnerability chain could have allowed an attacker to take control of another participant’s device simply by joining the same meeting. 

The attack required no clicks, downloads, or other interaction from the victim. 

Researchers at A Security dubbed the vulnerability chain “ZOOMSDAY” and said they developed a working exploit in less than 24 hours using fewer than 20 prompts with publicly available AI models. The findings highlight both the potential severity of vulnerabilities in widely used collaboration platforms and the growing role of AI in accelerating offensive security research.

“The barrier to producing this class of weapon has collapsed, and it won’t come back,” researchers said in their disclosure.

Key takeaways of the Zoom RCE exploit chain

  • ZOOMSDAY enabled zero-click RCE, allowing an attacker to potentially compromise another Zoom participant’s device without any user interaction.
  • The exploit affected major operating systems, with A Security confirming the attack against Zoom Client on Windows, macOS, iOS, and Android.
  • AI accelerated exploit development, with A Security developing a working exploit in less than 24 hours using fewer than 20 prompts with publicly available AI models.
  • Organizations should update Zoom immediately and reinforce patching with meeting access controls, endpoint monitoring, and other defense-in-depth measures.

Inside the Zoom zero-click RCE exploit chain

A Security’s research found that the ZOOMSDAY vulnerability chain affected Zoom’s native clients across major operating systems.

Researchers confirmed the zero-click remote code execution (RCE) exploit against Zoom Client v7.0.5 on Windows, macOS, iOS, and Android.

How the ZOOMSDAY exploit chain works 

The vulnerability chain centered on memory corruption associated with Zoom’s annotation feature, which allows meeting participants to draw, highlight, or add information to shared content. 

According to A Security, Zoom clients automatically processed data transmitted through the platform’s proprietary annotation protocol. 

Researchers discovered they could manipulate this process with specially crafted messages that corrupted the receiving client’s memory and ultimately enabled remote code execution.

What attackers could do with ZOOMSDAY 

What made ZOOMSDAY especially concerning was that exploitation did not require the victim to click a malicious link, open an attachment, or download a file. 

An attacker could join or host a Zoom meeting and target another participant without requiring any action from that person or displaying an obvious indication that the device had been compromised. The communication between Zoom clients also created multiple potential attack paths. 

A Security found that a malicious meeting participant could target a presenter, while a compromised presenter could potentially target other participants. 

Successful exploitation could allow malicious code to run on a victim’s device, creating opportunities to steal sensitive information, install additional malware, or access the device’s microphone or camera.

The ZOOMSDAY exploit chain involved three vulnerabilities, tracked as CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415.  

CVE-2026-53413

CVE-2026-53413 is one of the vulnerabilities associated with the Zoom annotation functionality exploited as part of the ZOOMSDAY chain. 

The flaw enabled manipulation of how a Zoom client handled specially crafted annotation data sent during a meeting. For an attacker, exploiting this weakness could help trigger unintended memory behavior on a targeted Zoom client. 

When combined with the other vulnerabilities in the chain, it helped researchers progress toward executing attacker-controlled code without requiring interaction from the targeted participant.

CVE-2026-53414

CVE-2026-53414 is a memory over-read vulnerability in how Zoom processes character data received through its annotation protocol. 

The issue occurs because Zoom allocates a memory buffer based on the character count specified in an incoming packet, even when the packet contains less data than that count indicates. The unused portion of the allocated buffer is not cleared before it is processed, potentially exposing information already stored in the victim device’s memory.

A Security confirmed that the exposed memory could contain sensitive technical information, including live code and virtual function table (vtable) pointers from loaded software libraries.

An attacker could use these leaked memory addresses to determine where code is located in memory and help bypass address space layout randomization (ASLR), a security protection designed to make memory-based attacks more difficult. Although the vulnerability does not provide complete device takeover on its own, the leaked memory information can make other memory-corruption vulnerabilities easier to exploit

In the ZOOMSDAY chain, CVE-2026-53414 provided information an attacker could use to overcome memory protections and move closer to reliable RCE on the targeted Zoom client.

CVE-2026-53415

CVE-2026-53415 is a separate vulnerability discovered in Zoom’s annotation engine that could provide an attacker with another path to remote code execution. 

The flaw affects how Zoom processes an annotation message used for auto-shape metadata.

According to A Security, Zoom’s parser could read attacker-controlled data directly into an internal linked-list structure without first validating the supplied pointers. This created what researchers describe as a “write-what-where” condition, meaning an attacker could potentially control both the data written to memory and the location where it was written. 

The capability can be dangerous because it can provide a path toward executing attacker-controlled code on the affected device.

Zoom had deployed a server-side mitigation designed to filter malicious messages before they reached vulnerable clients. However, that protection could not be applied to end-to-end encrypted (E2EE) meetings because Zoom’s servers are unable to inspect the encrypted meeting content. As a result, specially crafted messages could still reach vulnerable clients during E2EE meetings.

Zoom has already released fixes for the vulnerabilities.

How to mitigate the Zoom vulnerabilities 

Updating vulnerable Zoom clients should be the priority, but organizations should also apply defense-in-depth controls to reduce exposure and contain the blast radius of a potential compromise. 

This includes tightening meeting-level permissions, strengthening endpoint protections, and limiting the privileges available to compromised accounts and applications. 

  • Maintain accurate software inventories and SBOMs to identify affected software, and promptly update Zoom Workplace and other business-critical applications to remediate vulnerable versions. 
  • Restrict sensitive meetings to authenticated or approved participants and use waiting rooms to control access.
  • Limit annotation, screen sharing, and other participant capabilities to trusted users when they are not required.
  • Use endpoint detection and response tools to monitor Zoom endpoints for suspicious processes, persistence, or unusual device activity.
  • Apply least-privilege and application-control policies to limit what attackers can access or execute after compromising an endpoint.
  • Test incident response plans and use attack simulation tools with scenarios around endpoint compromise.

For security teams, ZOOMSDAY underscores a broader shift in the threat landscape. AI is reducing the time and resources required to identify vulnerabilities and develop functional exploits.

Editor’s note: This article originally appeared on our sister publication, eSecurityPlanet.

>

Continue Reading

Tech

Apple’s 2027 iPhone: New Report Sheds Light on Glass Redesign

Published

on

Apple’s most ambitious iPhone redesign in years may not be dead. It may simply have collided with the realities of building hundreds of millions of phones.

Apple is still developing a glass-centric overhaul of the iPhone for 2027, according to new reporting from Bloomberg, contradicting an analyst report that suggested the project had been canceled. The planned Pro models reportedly feature glass that curves from the front and back toward the sides, separated by a metal band.

That distinction matters. According to Bloomberg, Apple scrapped an earlier, more radical glass-heavy concept, but its broader anniversary redesign remains in development. The gap between those two concepts offers a revealing look at the challenge facing Apple as it tries to make the iPhone feel genuinely new again.

Apple’s ‘all-glass’ iPhone may have been too ambitious to manufacture

The confusion stems from two different versions of Apple’s reported plans.

Jefferies analyst Edison Lee recently downgraded Apple and argued that the company had canceled an anticipated all-glass anniversary iPhone because of poor manufacturing yields. Barron’s reported that Lee viewed the cancellation as a setback for Apple’s efforts to introduce more expensive iPhones as component costs rise.

Bloomberg’s reporting paints a more nuanced picture.

Apple reportedly explored a more extreme design that would have replaced even more of the phone’s metal structure with glass. But that version ran into problems connecting the glass panels and reportedly could not meet the requirements of large-scale production.

The 2027 iPhones still in development, reportedly known internally as V73 and V74, are less radical. Glass is expected to cover the front and back and curve toward the sides, while a metal band remains in the middle.

In other words, Apple reportedly abandoned the more futuristic prototype. The broader design direction appears to have survived.

Why Apple’s 2027 iPhone could feel different

For Apple, 2027 carries symbolism that an ordinary iPhone cycle does not.

The original iPhone debuted in 2007. Ten years later, Apple introduced the iPhone X, eliminating the Home button, introducing Face ID and pushing the screen much closer to the edges of the device.

Apple explicitly positioned that redesign as the start of something bigger. In Apple’s original iPhone X announcement, then-design chief Jony Ive described the device as the realization of Apple’s decade-long ambition to create an iPhone that was “all display.” Phil Schiller separately called the iPhone X the beginning of the next 10 years for the iPhone.

Twenty years after the original iPhone, Apple faces a similar challenge: finding a visual and functional idea big enough to define another era.

Incremental improvements to cameras, chips and battery life can give existing customers reasons to upgrade, but they do less to change how consumers perceive the device itself. A dramatically different physical design could give Apple something increasingly difficult to create in a mature smartphone market: obvious novelty.

There is also a financial dimension. Apple reported a March-quarter record for iPhone revenue earlier this year. Apple’s fiscal second-quarter results show that the franchise remains enormously valuable even without a radical redesign. But that scale makes successful experimentation more difficult, not less.

A design that works beautifully in a prototype has to survive drops, heat, repairs, cases, wireless charging and years of everyday use. More importantly, Apple must be able to manufacture it reliably at extraordinary volume.

That may explain why the surviving design is more interesting than the reportedly scrapped one. Apple appears to be searching for a balance between the visual simplicity of an almost uninterrupted glass device and a design its supply chain can reliably produce at iPhone scale.

What the glass redesign could mean for users

Previous reports have suggested Apple wants the 2027 model to appear almost borderless, with a display that curves around all four edges. Reports have also pointed to thinner OLED technology and techniques intended to minimize the visibility of the bezels.

If those reports prove accurate, Apple could achieve the visual effect of an uninterrupted slab of glass without literally constructing the phone that way. It would be a familiar Apple maneuver: make complicated engineering disappear behind a simpler physical experience.

And that may ultimately matter more than whether analysts can accurately describe the device as “all glass.”

The iPhone X was transformative not because its chassis contained a particular percentage of glass, but because its display, Face ID and gesture-based interface worked together to make the old Home-button design suddenly look dated.

Apple will need a similarly convincing trick in 2027.

The smartphone market is far more mature than it was a decade ago, and annual upgrades increasingly revolve around refinement rather than reinvention. Better cameras, faster chips and longer battery life remain valuable, but they rarely change how people think about what a smartphone can be.

That is why the fate of Apple’s more ambitious glass prototype matters beyond one reportedly abandoned design. If Apple scaled back the concept because it could not manufacture it reliably, the decision highlights the tension at the center of modern consumer technology: breakthrough designs still have to survive the unforgiving economics of mass production.

Apple does not need to ship the most futuristic iPhone its designers can imagine. It needs to build one that looks futuristic while remaining durable and manufacturable at iPhone scale.

For a company preparing to mark 20 years of its most important product, that distinction could determine whether the anniversary iPhone feels like another upgrade or the beginning of Apple’s next smartphone era.

Related reading: Thinking about upgrading before 2027? See how much your current iPhone, Mac, or iPad could be worth with Apple’s latest trade-in values.

>

Continue Reading

Tech

Lovable Raises $400M at $13.3B Valuation as Enterprise Use Grows

Published

on

Lovable has raised $400 million at a $13.3 billion valuation, more than doubling its value in eight months as investors place another large bet on software built through natural-language prompts.

The Stockholm-based company is nearing a $600 million annual revenue run rate and plans to expand its workforce by 50% to about 450 employees this year. Its customer list now includes Nvidia, Adidas, Hearst, and Zendesk, giving Lovable a larger foothold inside companies where AI-built applications can move quickly from experiments to everyday business tools.

Lovable’s $13.3B valuation backs a broader software bet

The new $400 million funding round was co-led by Menlo Ventures and Scaleup Europe Fund, an EU-backed investment vehicle overseen by EQT. Balderton Capital, World Innovation Lab, and Tencent also participated.

It follows Lovable’s $330 million Series B in December, when the company was valued at $6.6 billion. Lovable’s valuation has therefore more than doubled while its revenue run rate has nearly tripled from the level reported at the end of last year.

Lovable is part of the broader vibe-coding market, which lets people create applications by describing what they want rather than writing the code themselves. Its platform can generate front ends, back ends, databases, authentication, and integrations, with generated code available for review or export to GitHub.

That model is increasingly moving into established companies. Nvidia, for example, uses Lovable to create customized software that helps team leaders track projects and delivery. Lovable also markets the platform for internal tools and production applications built by product managers, designers, marketers, and other employees alongside engineering teams.

Investor interest extends beyond Lovable. Replit was valued at $9 billion in March, while SpaceX agreed to acquire Cursor parent Anysphere for $60 billion in June.

More builders mean more software for IT to govern

Giving employees outside engineering the ability to create working applications can remove development bottlenecks, but it also expands the amount of software an organization has to track.

Lovable’s enterprise offering reflects that shift. The company provides SSO and SAML authentication, role-based access controls, SCIM provisioning, audit logs, GitHub integration, and controls for managing applications across shared workspaces.

Its Workspace Insights tool gives enterprise administrators an inventory of projects and externally published apps, along with information about owners, personally identifiable information, security findings, publishing status, authentication providers, database tables, and row-level security settings.

Lovable says enterprise workspaces can grow to thousands of projects. At that scale, an AI app builder becomes another part of the organization’s software estate rather than an isolated productivity tool.

IT teams adopting platforms such as Lovable therefore need policies for who can build and publish applications, which company data those apps can access, how generated code enters existing development workflows, and who remains responsible for maintaining an application after it is deployed.

Lovable’s $13.3 billion valuation is ultimately a bet that far more employees will build software themselves. If that bet pays off, IT departments will be managing not only AI coding tools, but a rapidly growing inventory of software those tools create.

Also read: A high-severity Cursor Git vulnerability demonstrated how flaws in AI coding environments can reach the development systems around them.

>

Continue Reading

Tech

Grubhub’s $24M FTC settlement is finally reaching diners and drivers

Published

on

Well over half a million Grubhub drivers and customers are set to receive a share of $23.8 million following allegations that the food delivery company misled workers about their potential earnings and engaged in other deceptive practices.

The Federal Trade Commission (FTC) announced on Wednesday that it’s distributing the money to 640,038 consumers, with most recipients receiving a check in the mail. Some will receive their payments through PayPal.

The payouts stem from a lawsuit the FTC and Illinois Attorney General filed against Grubhub in December 2024. The complaint accused the company of a range of unlawful practices, including making misleading claims about how much drivers could earn, restricting customers’ access to their accounts and money, and listing restaurants on its platform without their permission.

Another allegation involved Grubhub’s restaurant listings. According to the complaint, the company had as many as 325,000 restaurants on its platform that were not affiliated with Grubhub. The FTC alleged that Grubhub used those listings to make its platform appear larger.

The complaint also alleged that Grubhub sometimes refused to remove restaurants after they asked to be taken off the platform. Instead, the company allegedly tried to convince some of those businesses to enter into paid partnerships.

The settlement required Grubhub to change how it operates in several areas. For instance, the company must be more accurate when advertising potential driver earnings, give customers a way to challenge account restrictions that leave them unable to access their accounts or funds, and obtain a restaurant’s consent before listing it on the platform.

Today’s announcement puts renewed attention on Grubhub’s treatment of its drivers and diners and the company’s broader business practices. Notably, it comes just one month after a federal judge granted final approval of another settlement worth nearly $25 million and involving approximately 60,000 Grubhub delivery drivers in California.

Grubhub also isn’t the only delivery company to face scrutiny. In the past, DoorDash has faced criticism and legal challenges over driver compensation, while Uber Eats has dealt with allegations involving customer charges and its relationships with restaurants.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

>

Continue Reading

Trending

Copyright © 2017 Zox News Theme. Theme by MVP Themes, powered by WordPress.