Attacker Takes over Zoom AI

Security researchers have identified a vulnerability in Zoom's AI agent, ZoomMate, which allows attackers to exfiltrate data through malicious prompts or plugins. The agent's unrestricted network access enables attackers to bypass user controls and maintain persistence.
Why it matters
This highlights significant security risks in the deployment of agentic AI tools that have broad access to sensitive user data and connected services.
Attacker takes over the victim’s Zoom AI, exfiltrating data from across Zoom and connected services Context Zoom’s flagship AI feature is ZoomMate, an agentic chatbot that operates on data from across a user’s Zoom account and any connected services (e.g., OneDrive, Google, connectors, etc). The agent appears to have been given an environment with unrestricted HTTPS network access, with no user or admin-level configuration to lock it down.
In this article, we explore how a malicious Skill (or a prompt injection) can manipulate Zoom’s agent into connecting to an attacker’s server, allowing the attacker to issue their own commands and exfiltrate data from the victim’s tenant.
Further compounding this risk, the attacker’s connection can remain active even if the user clicks ‘stop’ on the agent and closes Zoom . Additionally, the final chat output to the user appears completely normal.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in