Zoom のセキュリティ脆弱性、20 個未満の AI プロンプトで発見される
本文の状態
日本語全文を表示中
詳細モードで約2分の本文を読めます。
同じ出来事の情報源
この情報源を基点に整理
The Verge AI
セキュリティ調査会社 A Security は、公開 AI モデルへの簡易なプロンプト入力で Zoom の画面共有機能の重大脆弱性を発見し、被害者への事前動作なしにデバイス乗っ取りを可能にする exploit を作成したと発表した。
Continue in AI NEW LAB
このニュースを、実務の判断につなげる
AI NEW LABで、試したことや先に確認したい条件を共有できます。まずはログインなしで読めます。
AI NEW LABで論点を見るAI深層分析を開く2026年8月11日 23:58
AI深層分析
キーポイント
AI プロンプトによる脆弱性発見
A Security の研究者は、公開されている AI モデルに対して 20 回未満のプロンプトを入力するだけで、Zoom の画面共有機能における重大なセキュリティ欠陥を発見した。
被害者への影響と攻撃手法
この脆弱性を悪用すると、攻撃者は会議に参加またはホストするだけで、被害者のデバイス上でコードを実行し、データ窃取やカメラ・マイクの無断起動、マルウェアのインストールを可能にする。
検知困難な攻撃の特徴
A Security によると、この攻撃は被害者に何らかのアクションを要求せず、かつ侵害を示す視覚的な手がかりも表示されないため、極めて検知が困難である。
Zoom の対応状況
Zoom は同社のセキュリティバレットにおいて、この重大な脆弱性に対するパッチを適用済みであることを発表している。
脆弱性の修正と影響範囲
Zoom は火曜日にこの脆弱性に対する修正プログラムを発行した。この問題はWindows、macOS、Linux、Android、iOS acrossするアプリ全体に影響を及ぼしていた。
重要な引用
fewer than 20 prompts on publicly available AI models
no visual cue indicating the compromise
Producing a working exploit against it has always been nation-state work: elite teams, months of effort, budgets that governments regulate as weapons
"A [Security] did it in a single day, with an AI agent and models anyone can access today."
編集コメントを表示
編集コメント
AI ツールがセキュリティ研究の効率化に寄与する一方で、悪用される際のリスクも同時に増大していることを示す事例である。企業は AI の活用とセキュリティ対策のバランスを再考し、新たな脅威への対応体制を整える必要がある。
Source Article
元記事を日本語で読む
本文に関係しない購読案内、埋め込み通知、サイト内プロモーションは除いています。
Zoom は、会議中に攻撃者が誰でもデバイスを乗っ取れる可能性のある重大なセキュリティ脆弱性を修正しました。A Security の研究者らは火曜日のブログ記事で、「公開されている AI モデルに対して 20 回未満のプロンプト」を用いてこの欠陥を発見したと発表しています。これは Wired が以前に報じた内容です。
今回の攻撃は、画面共有中に他の参加者に対して画面に描画できる Zoom の注釈機能を利用するものです。攻撃者は会議に参加またはホストすることで被害者のデバイス上で悪意のあるコードを実行でき、データの窃取やカメラ・マイクの起動、マルウェアのインストールが可能になります。A Security によると、この攻撃には被害者の何らかの操作は不要で、「侵害を示す視覚的な手がかりもありません」。
「この種の脆弱性に対する実働型のエクスプロイトを開発するのは、従来は国家レベルの工作でした。エリートチームが数ヶ月かけて取り組み、政府が兵器として規制するほどの予算が必要だったのです」と、A Security の脆弱性情報研究者である Idan Levcovich 氏はブログ記事で述べています。「しかし、[Security] は AI エージェントと、誰でも今日すぐにアクセス可能なモデルを活用して、たった一日でこれを成し遂げました。」Zoom は火曜日にこの脆弱性に対する修正プログラムを公開しました。これにより、Windows、macOS、Linux、Android、iOS 上のすべてのプラットフォームで影響を受けたアプリが保護されます。
この話題や著者についてフォローする
このストーリーの関連トピックや著者をフォローすれば、パーソナライズされたホームフィードで類似記事を見たり、メール更新を受け取ったりできます。
- Emma Roth
原文を表示
Emma Roth
is a news writer who covers the streaming wars, consumer tech, crypto, social media, and much more. Previously, she was a writer and editor at MUO.
Zoom has patched a major security vulnerability that could allow an attacker to hijack anyone’s device during a meeting. In a blog post on Tuesday, researchers at A Security say they uncovered the flaw using “fewer than 20 prompts on publicly available AI models,” as reported earlier by Wired.
The exploit involved Zoom’s annotation feature, which allows users to draw on their screen while sharing it with other meeting participants. With the exploit, an attacker could join or host a meeting and run malicious code on victims’ devices, allowing them to steal data, turn on the camera or microphone, or install malware. The attack required no action from victims and showed “no visual cue indicating the compromise,” according to A Security.
This content isn't visible due to your cookie preferences. To load this content, click the Allow button below to opt in to "Social Media & Embedded Content" cookies. These cookies are set and controlled by the third party sources from which the embedded content originates.
“Producing a working exploit against it has always been nation-state work: elite teams, months of effort, budgets that governments regulate as weapons,” Idan Levcovich, a vulnerability researcher at A Security, writes in the blog post. “A [Security] did it in a single day, with an AI agent and models anyone can access today.” Zoom issued a fix for the vulnerability on Tuesday, which impacted the app across Windows, macOS, Linux, Android, and iOS.
Follow topics and authors from this story to see more like this in your personalized homepage feed and to receive email updates.
- Emma Roth
-
-
-
-
関連記事
今日のまとめ
AIデイリーブリーフで今日の重要ニュースをまとめ読み