Researchers at the firm A Security disclosed a chain of memory-corruption bugs in Zoom's annotation feature — the tool that lets meeting participants draw on shared content — that allowed code execution on another participant's machine with no clicks, no downloads and no interaction of any kind from the victim. They confirmed the exploit against Zoom client version 7.0.5 on Windows, macOS, iOS and Android. What has drawn attention is not the bug but its price: the team says a single researcher produced a working exploit in under 24 hours using fewer than 20 prompts to publicly available AI models, work they estimate would previously have taken a team of five around six months. Zoom has issued fixes; users on old clients are still exposed.