Zoom Zero-Day Exploit Being Sold by Hackers for $500,000: Report

An exploit for Zoom Windows client is a Remote Code Execution (RCE) that means hackers can gain access to the targets machine by running code.

Advertisement
By Vineet Washington | Updated: 16 April 2020 16:36 IST
Highlights
  • Zoom Windows exploit being sold for $500,000 (roughly Rs. 3.83 crore)
  • Exploits are available for both Windows and macOS
  • Zoom says there is no evidence of these exploits

Zoom has been trying to address all of its security and privacy issues

Photo Credit: Zoom

Zoom is among the most used video conferencing apps and has gained a lot of users due to the ongoing coronavirus outbreak. But, there have been several security and privacy issues with the app and the team at Zoom is said to be trying to address all of them. Now, two “zero-day” flaws in the Zoom software have reportedly popped up online and exploits for these are being sold for huge sums of money. One of the flaws is present in the Windows version of Zoom client, whereas the other is part of the Zoom client for macOS.

According to a report by Motherboard, the exploit that takes advantage of ‘zero-day vulnerabilities' in Zoom's Windows client is up for sale via exploit brokers for $500,000 (roughly Rs. 3.83 crore). Zero-day flaws are unpatched and previously unknown vulnerabilities in a software or hardware.

Advertisement

Zoom vulnerabilities can allow someone to hack its users and spy on their calls, Motherboard states. The publication says three of its sources were contacted by brokers who were offering these exploits for sale.

“From what I've heard, there are two zero-day exploits in circulation for Zoom. [...] One affects OS X and the other Windows.. I don't expect that these will have a particularly long shelf-life because when a zero-day gets used it gets discovered,” the report quotes Adriel Desautels, the founder of Netragard, a company that used to sell and trade zero-days.

Advertisement

The exploit for Windows is a Remote Code Execution or RCE, as stated by one of the other two sources. These types of exploits allow hackers to execute code on the target's computer without having to rely on a phishing attack that generally depends upon deceiving the target into sharing personal information like bank account details. RCE also allows hackers to access the target's whole machine.

The exploit for Zoom for macOS is not RCE, “making it less dangerous and harder to use,” the report adds.

Advertisement

Zoom has responded to this report and said it did not find any evidence for these claims, Motherboard writes.

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Zoom, Windows, macOS, Remote Code Execution
Advertisement

Related Stories

Popular Mobile Brands
  1. Vivo X300 FE, iQOO 15R and More Discounted During Amazon Mega Deal Days Sale
  2. Vivo Y31s Launched in Malaysia With These Features
  3. OnePlus Could Launch a New Budget Smartphone Lineup in India Soon
  4. Infinix Hot 70 Pro India Launch Timeline, Key Specifications Leaked
  5. Samsung Galaxy S26 FE Tipped to Get New Look With Glossy Rear Panel
  6. New Leak Shows Us What Apple's Foldable iPhone Might Look Like
  7. Infinix Smart 20 vs Lava Bold N2 5G vs Redmi A7 Pro 5G: Here Is a Quick Comparison
  8. Samsung Galaxy S27 Pro's Battery May Match the One on the Galaxy S26 Ultra
  9. How to Watch WWDC 2026 Live on YouTube, Apple TV, and More
  10. Vivo V70 Lite 5G Silently Launched in Select Markets With These Features
  1. Samsung Galaxy S26 FE Said to Ditch Matte Finish for a Glossy Rear Panel
  2. OnePlus N Series Tipped to Launch in India Next Month, Could Be More Affordable Than the OnePlus Nord CE 6 Lite
  3. Vivo Y31s 5G Launched With Snapdragon 4 Gen 2 Chip, 6,500mAh Battery: Price, Specifications
  4. Chinese Court Classifies Bitcoin as Property in Case Involving 107 BTC Theft
  5. Resident Evil Veronica Revealed at Summer Game Fest; Launch Set for 2027
  6. iQOO Neo 12 Said to Bring Major Display Upgrade With Up to 185Hz Refresh Rate
  7. Samsung Galaxy Watch Ultra 2, Galaxy Watch 9 Clear Key Regulatory Hurdle Ahead of Anticipated Launch
  8. Microsoft Reportedly Working on Shared Audio Feature on Windows 11 Alongside Tweaked Widgets
  9. Redmi K100 Specifications Leak Again; May Feature 185Hz Display, 8,500mAh Battery
  10. WhatsApp Multi-Account Support on iOS Reportedly Rolling Out to More Users
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.