TECH Signal 387
AI-discovered Zoom zero-click RCE via annotation affects all clients; fix in 7.1.5 and 7.0.6
A critical zero-click remote code execution vulnerability in Zoom's annotation feature, discovered by an AI agent, affects all clients before 7.1.5 and 7.0.6, with fixes now available.
This vulnerability demonstrates that AI can now produce nation-state-level exploits in under a day, collapsing the barrier to weaponized attacks. For engineers, it means any closed-source software with automatic parsing of untrusted input is at risk, and defensive testing must be continuous and automated. The fix requires updating all Zoom clients to 7.1.5 or 7.0.6, but the broader lesson is that security assumptions based on obscurity are no longer valid.
Written by elseif from the cluster below · every claim links back to a sourceThe three things worth knowing
Zoom's annotation feature contains a memory-corruption bug allowing zero-click remote code execution on all platforms.
The exploit was developed by an AI agent using fewer than 20 prompts in under 24 hours, previously a nation-state capability.
Zoom has released fixes in versions 7.1.5 and 7.0.6; all clients before these are vulnerable, especially those using end-to-end encryption.
THE CLUSTER
↗