Zoom Screen-Sharing Bug Allowed Full Device Takeover

Original: A Zoom Screen-Sharing Bug Let Anyone Take Over Other Devices on a Call

Why This Matters

AI-assisted exploit discovery is compressing timelines from months to hours, raising urgent security concerns for enterprise software.

A Security researchers disclosed vulnerabilities in Zoom's screen-sharing annotation protocol that allowed any call participant to silently hijack another user's device across Windows, macOS, Linux, iOS, and Android. The flaws were found using a public AI tool in fewer than 20 prompts. Zoom has issued server and client-side patches.

Researchers from digital defense firm A Security disclosed on Tuesday that they discovered critical vulnerabilities in Zoom's real-time annotation protocol used during screen sharing. The flaws allowed any participant on a Zoom call—host or attendee—to silently take over another participant's device with no interaction or indication to the victim. All operating systems supported by Zoom were affected: Windows, macOS, Linux, iOS, and Android.

The vulnerabilities were discovered in early June using publicly available AI models. According to A Security cofounder Omer Gull, it took fewer than 20 AI prompts to uncover the flaws and build a working exploit—a task that previously would have required a team of five people working for roughly six months. The researchers targeted the annotation component specifically because complex, proprietary, closed-source features are historically prone to overlooked flaws.

Zoom issued a security advisory Tuesday and has already begun rolling out both server-side and client-side fixes. Zoom did not respond to WIRED's requests for comment. A Security cofounder Yossi Torati stated: 'If you just get on a Zoom with us, we can take over your device.' The researchers warned that the democratization of AI-assisted vulnerability discovery is rapidly lowering the barrier to entry for finding critical flaws in widely trusted platforms.

Source

wired.com — Read original →