AUTO-UPDATED

A Zoom Screen-Sharing Bug Let Anyone Take Over Other Devices on a Call

Researchers from A Security discovered critical vulnerabilities in Zoom’s screen-sharing annotation protocol that could allow attackers to take control of a target's device without any user interaction.

Key Points

  • A Security researchers identified the flaws in early June using publicly available AI models with fewer than 20 prompts.
  • The vulnerabilities affected all Zoom-supported operating systems, including Windows, macOS, Linux, iOS, and Android.
  • Zoom has released both server-side and client-side patches to address the security risks associated with the real-time annotation feature.
  • The exploit allowed for silent device takeovers simply by joining a call, bypassing the need for victim interaction.

Why it Matters

The democratization of AI-driven vulnerability research significantly lowers the barrier for attackers to discover complex exploits in widely used enterprise software. This shift forces companies to accelerate their security patching cycles as the speed of automated threat discovery continues to outpace traditional manual code reviews.
Wired Published by Lily Hay Newman
Read original