安全研究公司A Security在Zoom视频会议平台中发现了一个漏洞,攻击者可以在屏幕共享过程中利用AI模型劫持用户设备[1]。该漏洞影响Zoom支持的所有主要操作系统,包括Windows、macOS、Linux、iOS和Android[1]。研究人员仅用不到20个AI提示就发现了这些漏洞并创建了可行的攻击方式[1]。
A Security联合创始人Omer Gull表示:"Before it would have taken a team of five people maybe six months with a lot of refining and iteration to find this. Now people can reach the same results with under 20 prompts."[1] 这些攻击可在屏幕共享期间无声执行,不需要受害者进行任何交互[1]。Zoom已于周二发布了安全公告并开始向用户推送修复补丁[1]。
Security researchers at A Security have identified vulnerabilities in Zoom's video conferencing platform that allow attackers to commandeer user devices during screen sharing sessions.[1] The flaw affects all operating systems supported by Zoom, including Windows, macOS, Linux, iOS, and Android.[1] Researchers were able to uncover these vulnerabilities and develop functional exploits using fewer than 20 AI prompts in early June.[1]
According to Omer Gull, a co-founder of A Security, the speed of discovery marks a significant shift in security research capabilities: "Before it would have taken a team of five people maybe six months with a lot of refining and iteration to find this. Now people can reach the same results with under 20 prompts."[1] The attacks can be executed silently during screen sharing without requiring any interaction from the victim.[1] Zoom released a security advisory and began rolling out patches on Tuesday.[1]