A Zoom Screen-Sharing Vulnerability Allowed Unauthorized Control of Devices During Calls

As artificial intelligence models evolve to identify vulnerabilities in software, exploit them, and even autonomously execute hacking operations, researchers presented a concerning new case on Tuesday. They revealed vulnerabilities in the Zoom video conferencing platform that could have been utilized to compromise users’ devices. All participants in a call with screen sharing, whether they were hosts or attendees, would have been at risk from a covert attack that could occur without any warning or victim interaction.
According to researchers from the cybersecurity firm A Security, the flaw was detected in early June using publicly accessible AI models, and it took fewer than 20 prompts to expose the vulnerabilities and devise a functioning attack plan. Zoom issued a security advisory on Tuesday, detailing the fixes the company has begun implementing to resolve the issues, which impacted devices across all supported operating systems—Windows, macOS, Linux, iOS, and Android.
“What we find intriguing and concerning is the democratization of these capabilities—the entry barriers are rapidly diminishing,” A Security co-founder Omer Gull shared with WIRED prior to the announcement. “Previously, a team of five might have needed six months of rigorous refinement and iteration to discover this. Now, individuals can achieve similar results with fewer than 20 prompts. Zoom is a significant target as users inherently trust it; they don’t perceive it as a threat.”
The vulnerabilities were specifically located in the protocol that enables real-time annotation during screen sharing. The researchers noted that their AI bug-hunting systems specifically focused on this feature because, like human bug hunters, they recognize that complex and obscure functions often harbor overlooked weaknesses. This is particularly relevant for proprietary, closed-source software. Even a well-established company like Zoom likely conducts extensive code reviews and vetting for all components and functions, but without public open review, intricate features like annotation are more prone to errors.
Zoom did not reply to multiple inquiries from WIRED regarding the findings from A Security.
The vulnerabilities have now been addressed, with Zoom releasing both server-side and client-side fixes for its own servers and the applications utilized on user devices. However, researchers stress that it’s troubling to consider vulnerabilities that could have been exploited to take control of a device simply by having someone join a Zoom call. Participating in a call inherently implies trust, but given the prevalence of video calling in both personal and professional settings—and especially since Zoom is commonly used for events and semi-public activities like webinars—users often lower their guard when joining a Zoom meeting.
“If you just join a Zoom call with us, we can seize control of your device,” A Security co-founder Yossi Torati informed WIRED during a call. (Interestingly, it was hosted on Microsoft Teams.) “The worst-case scenario is that we could potentially take over an enterprise with this vulnerability at our disposal. If I’m an attacker, I can be on a call with someone from a company, gain control of their computer and credentials, and then use that access to navigate laterally within the enterprise.”
Experts often refer to security as a “cat and mouse game,” but as AI-based bug hunting becomes more widespread, this intricate dance has transformed into a full-blown race.
