‘Zoomsday’ hack uncovered using fewer than 20 AI prompts

‘Zoomsday’ hack uncovered using fewer than 20 AI prompts

“Zoomsday” 漏洞被发现:仅需不到 20 条 AI 提示词即可触发

The Zoom vulnerability allowed hackers to take over everyone’s device on a call, security researchers say. 安全研究人员表示,Zoom 存在一个漏洞,允许黑客接管通话中所有人的设备。

Zoom has patched a major security vulnerability that could allow an attacker to hijack anyone’s device during a meeting. In a blog post on Tuesday, researchers at A Security say they uncovered the flaw using “fewer than 20 prompts on publicly available AI models,” as reported earlier by Wired. Zoom 已经修复了一个重大的安全漏洞,该漏洞可能允许攻击者在会议期间劫持任何人的设备。据《连线》(Wired)早先报道,A Security 的研究人员在周二的一篇博客文章中表示,他们仅通过“在公开可用的 AI 模型上输入不到 20 条提示词”就发现了这一缺陷。

The exploit involved Zoom’s annotation feature, which allows users to draw on their screen while sharing it with other meeting participants. With the exploit, an attacker could join or host a meeting and run malicious code on victims’ devices, allowing them to steal data, turn on the camera or microphone, or install malware. The attack required no action from victims and showed “no visual cue indicating the compromise,” according to A Security. 该漏洞利用了 Zoom 的标注功能,该功能允许用户在屏幕共享时在屏幕上进行绘制。通过利用此漏洞,攻击者可以加入或主持会议,并在受害者的设备上运行恶意代码,从而窃取数据、开启摄像头或麦克风,甚至安装恶意软件。据 A Security 称,该攻击无需受害者进行任何操作,且“没有任何视觉迹象表明设备已被入侵”。

“Producing a working exploit against it has always been nation-state work: elite teams, months of effort, budgets that governments regulate as weapons,” Idan Levcovich, a vulnerability researcher at A Security, writes in the blog post. “A [Security] did it in a single day, with an AI agent and models anyone can access today.” Zoom issued a fix for the vulnerability on Tuesday, which impacted the app across Windows, macOS, Linux, Android, and iOS. “针对此类漏洞开发出可用的攻击程序,向来是国家级黑客的工作:需要精英团队、数月的努力,以及政府将其作为武器进行监管的预算,” A Security 的漏洞研究员 Idan Levcovich 在博客文章中写道。“而 A [Security] 仅用了一天时间,借助一个 AI 智能体和任何人都能访问的模型就做到了这一点。” Zoom 已于周二发布了针对该漏洞的修复程序,该漏洞此前影响了 Windows、macOS、Linux、Android 和 iOS 平台上的应用程序。