20 prompts in 24 hours: how Israeli cyber researchers used AI to locate a critical vulnerability in Zoom

Researchers from the Israeli cyber company A Security found a dangerous vulnerability in Zoom by sending fewer than 20 prompts to an AI model in less than 24 hours. Previously, such research would have required months of work by a team of experts.

CalcalistAuthor: Omer Kabir
Source
20 prompts in 24 hours: how Israeli cyber researchers used AI to locate a critical vulnerability in Zoom
Photo: Calcalist / גטי

Researchers from the Israeli cyber company A Security found a dangerous vulnerability in Zoom by sending fewer than 20 prompts to a publicly accessible AI model in less than 24 hours. This, at a time when without AI, it would have required months of work by a skilled team of five to six people to locate the vulnerability.

"As part of A Security's mission to protect against AI-based attacks, we are researching the critical infrastructures of the modern world," Idan Levkovich, a vulnerability researcher at A Security, told Calcalist. — "Zoom is used by huge corporations, governments, and families, and the vulnerability we found allows for remote takeover of any device in a video call. Such research previously required a team of experts and the capabilities of cyber powers, while today it is possible to find and exploit such a vulnerability in just one day with models accessible to everyone. This incident illustrates that organizations must use this technology to proactively locate and fix vulnerabilities, long before they are discovered by attackers."

In order to locate the vulnerability, the researchers began working with the Zoom app for Android, whose code libraries are visible. The prompts used by the researchers are based on knowledge of coding and defense mechanisms – these were not simple instructions like "find me a security breach," but a series of instructions that guided the AI agent they were working with to accurately understand the software code, identify bugs and possible entry points, and expose the vulnerability.

The vulnerability they identified is related to a feature in Zoom that allows users to draw and write on the screen while they are sharing their device view during a call. It allows an attacker to run malicious code on the victim's computer, and through it, steal information, remotely activate the camera and microphone, or install malware. This, without the need for any action on the part of the victim or a visual signal that an attack is taking place.

Zoom has already fixed the vulnerability in current versions of the app, however, previously it was active in every version of Zoom and on every device where it is available: Windows, Mac, iPhone, Android, and Linux.

The use of AI to locate the vulnerability still requires familiarity with the cyber world. However, it significantly lowers the barrier to discovering critical vulnerabilities of this type, and allows even players with relatively little knowledge to act like the most sophisticated attack groups in the world.

According to Levkovich, the findings have importance beyond Zoom:

"Zoom is a core infrastructure in 70% of Fortune 100 companies, most Fortune 500 companies, and federal agencies. In addition, it is the platform where millions meet their doctors, lawyers, and families. But the real finding is not the bug. It is the speed. The barrier to creating weapons of this type has collapsed, and it will not return. The message to security managers: defenses built for a world where these weapons were rare are no longer valid. The only robust answer is to turn those same capabilities inward, to examine your environment continuously before the adversaries get there."

Related News