A Zoom Screen-Sharing Bug Let Anyone Take Over Other Devices on a Call
Security researchers have disclosed vulnerabilities in Zoom's screen-sharing feature that could have let an attacker silently take control of another participant's device during a call, without any warning or interaction required from the victim. The flaws, found by the firm A Security, are particularly striking because they were uncovered using publicly available AI models in under 20 prompts, illustrating how AI is rapidly lowering the barrier to sophisticated hacking that once required teams of skilled researchers working for months.
The bugs lay in the protocol used for real-time annotation during screen sharing and affected Zoom clients across all supported platforms, including Windows, macOS, Linux, iOS and Android. Zoom issued a security advisory and has rolled out server- and client-side fixes, though it did not respond to requests for comment. Researchers warned the flaw was especially dangerous because joining a call implies trust, and an attacker could have used it to seize a victim's device and credentials to move laterally through an entire enterprise network.
- Zoom screen-sharing bug allowed silent, no-interaction device takeover on calls
- Flaw found via AI models in fewer than 20 prompts, not months of manual work
- Zoom has released patches; affected all major operating systems