A security researcher used fewer than 20 prompts to publicly available AI models to discover and chain together three vulnerabilities in Zoom’s screen-sharing annotation feature, producing a working zero-click exploit in under 24 hours — work the researchers said would previously have required a team of specialists roughly six months. The resulting flaw, dubbed “Zoomsday” and tracked as CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415, could have let any meeting participant silently execute code on another attendee’s device across Windows, macOS, Linux, iOS, and Android with no user interaction. Zoom patched the issue ahead of the August 11, 2026 public disclosure, and no real-world exploitation has been reported.