Zoom screen-sharing bug let people fully take over other devices on a call
Cybersecurity researchers have uncovered a serious vulnerability in Zoom's screen-sharing feature that could allow attackers to take full remote control of a victim's device. The flaw affects the Zoom Workspace app across Windows, Mac, iOS, Android and Linux, and requires no action from the victim, giving no visible warning that an attack is under way. Zoom has since released updates to fix the issue, and the company is urging all users to apply the latest patches.
The bug is triggered when someone activates the annotation tool while sharing their screen, which then lets an attacker remotely execute malicious code to gain access. Researchers say they built a working exploit using AI prompts in under 24 hours, noting that such nation-state-level attack capabilities once required elite teams, months of work and huge budgets. It is not yet known whether the vulnerability was exploited before being disclosed. The disclosure follows a separate, unrelated flaw recently found in Apple's macOS Screen Sharing feature, which Apple has already patched in macOS 26.6.1, 15.7.9 and 14.8.9.
- Zoom screen-sharing bug allowed silent full device takeover
- AI helped researchers build the exploit in under 24 hours
- Zoom has issued a fix; users should update immediately