Researchers from A Security discovered critical vulnerabilities in Zoom’s screen-sharing annotation protocol that could allow attackers to take control of a target's device without any user interaction.
Key Points
- A Security researchers identified the flaws in early June using publicly available AI models with fewer than 20 prompts.
- The vulnerabilities affected all Zoom-supported operating systems, including Windows, macOS, Linux, iOS, and Android.
- Zoom has released both server-side and client-side patches to address the security risks associated with the real-time annotation feature.
- The exploit allowed for silent device takeovers simply by joining a call, bypassing the need for victim interaction.