A Security researchers find Zoom device-hijacking bug using AI in under 20 prompts
A flaw in Zoom's screen-sharing annotation protocol could let attackers silently take over participant devices; now patched.
Conversation activity · last 13 hours peak 3/30m
Summary, timeline and people extracted by Claude from 7 items across 3 sources · 2h ago. Quotes are verbatim.
Researchers at digital defense firm A Security discovered critical vulnerabilities in Zoom's screen-sharing protocol that could allow attackers to silently take control of any participant's device. Using publicly available AI models, they required fewer than 20 prompts to uncover the flaws and create a working exploit. Zoom has issued patches for all operating systems and the incident highlights the rapid democratization of AI-powered security vulnerability discovery.
- A Security discovered Zoom screen-sharing vulnerabilities in June 2026 using publicly available AI models with fewer than 20 prompts, demonstrating rapid AI-powered vulnerability discovery.
- The flaws in Zoom's annotation protocol could allow silent, undetected device takeover of any call participant, affecting all operating systems Zoom supports.
- Zoom has already patched the vulnerabilities with both server and client-side fixes as of the August 11 disclosure.
- The incident underscores the democratization of AI-powered security testing, lowering barriers that previously required expert teams months to achieve.
How it unfolded
-
Researchers disclose that the vulnerabilities could allow anyone on a Zoom call with screen sharing enabled to silently take over a target device with no victim interaction. The flaws affect Windows, macOS, Linux, iOS, and Android.
“Before it would have taken a team of five people maybe six months with a lot of refining and iteration to find this. Now people can reach the same results with under 20 prompts.”
Omer Gull · Press ↗ -
Zoom releases security advisory with details of fixes already being rolled out to address the flaws. Both server-side and client-side patches are issued.
-
Researchers emphasize the severity, noting that attackers could exploit the vulnerability to compromise enterprise networks by hijacking an employee's device during a call and using their credentials for lateral movement.
“If you just get on a Zoom with us, we can take over your device…The worst-case scenario is that we can take over an enterprise just by having this vulnerability in our hands.”
Yossi Torati · Press ↗ - 10 weeks quiet
-
Researchers at A Security identify critical flaws in Zoom's real-time annotation feature during screen sharing using publicly available AI models. The discovery process took fewer than 20 AI prompts.
What people are saying verbatim
“Before it would have taken a team of five people maybe six months with a lot of refining and iteration to find this. Now people can reach the same results with under 20 prompts.”
Omer Gull, A Security cofounder · WIRED ↗
“What is interesting for us and what we believe is dangerous is the democratization of these capabilities—the barrier to entry is dropping rapidly.”
Omer Gull, A Security cofounder · WIRED ↗
“If you just get on a Zoom with us, we can take over your device. The worst-case scenario is that we can take over an enterprise just by having this vulnerability in our hands.”
Yossi Torati, A Security cofounder · WIRED ↗
“And Zoom is an important type of target because people assume trust when using it. They don't see it as a threat.”
Omer Gull, A Security cofounder · WIRED ↗
“Anyone on a call that involved screen sharing, whether participants or the host, would have been vulnerable to a silent attack that could be carried out with no indication and no interaction from the victim.”
WIRED, Publication reporting · WIRED ↗