研究人员用不到 20 条 AI 提示词发现 Zoom 漏洞,24 小时内构建出攻击链

链捕手
Aug 13

ChainCatcher 消息,据 Decrypt 报道,以色列网络安全公司 ASecurity 发布报告称,一名研究人员使用公开可用的 AI 模型,在不到 24 小时内通过不到 20 条提示词发现了 Zoom 注释工具中的多个漏洞,并构建出可利用的攻击链。该漏洞编号为 CVE-2026-53413、CVE-2026-53414 和 CVE-2026-53415,攻击者可借此在会议中无需受害者任何操作即可远程执行代码,控制其设备并窃取数据、开启麦克风或摄像头。

该攻击在 Windows、macOS、Linux、Android 及 iOS 版 Zoom 上均测试有效,ASecurity 称其达到“国家级”水准,以往构建此类利用工具需要专业团队数月工作和巨额预算。ASecurity 于 6 月 10 日向 Zoom 报告首个漏洞,Zoom 于 6 月 22 日至 7 月 20 日间陆续发布修复,但端到端加密会议中的服务器端防护无法过滤恶意消息,用户需手动更新。Zoom 发言人确认问题已解决并建议用户保持最新版本。

Disclaimer: Investing carries risk. This is not financial advice. The above content should not be regarded as an offer, recommendation, or solicitation on acquiring or disposing of any financial products, any associated discussions, comments, or posts by author or other users should not be considered as such either. It is solely for general information purpose only, which does not consider your own investment objectives, financial situations or needs. TTM assumes no responsibility or warranty for the accuracy and completeness of the information, investors should do their own research and may seek professional advice before investing.

Most Discussed

  1. 1
     
     
     
     
  2. 2
     
     
     
     
  3. 3
     
     
     
     
  4. 4
     
     
     
     
  5. 5
     
     
     
     
  6. 6
     
     
     
     
  7. 7
     
     
     
     
  8. 8
     
     
     
     
  9. 9
     
     
     
     
  10. 10