Zoom Vulnerability Lets Attackers Hijack Devices Through Screen Sharing Using AI Models

Reviewed byNidhi Govil

9 Sources

Share

A Security researchers uncovered a critical Zoom vulnerability using fewer than 20 AI prompts that allowed attackers to take over other devices on a call through screen sharing. The zero-click vulnerability affected all platforms and required no user interaction, highlighting the democratization of hacking capabilities through AI in cybersecurity.

AI Models Uncover Critical Zoom Screen-Sharing Bug in Under 24 Hours

Cybersecurity researchers at A Security discovered a severe Zoom vulnerability that could allow attackers to hijack devices through Zoom screen sharing, and they did it using fewer than 20 AI prompts on publicly available AI models

1

2

. The discovery, made in early June, took less than a day to develop into a working exploit, demonstrating how AI in cybersecurity is lowering barriers for both defenders and potential attackers. According to A Security cofounder Omer Gull, what previously would have required a team of five people working for six months can now be achieved with under 20 prompts

2

.

Source: Wired

Source: Wired

Zero-Click Vulnerability Exploited Annotation Feature Across All Platforms

The Zoom screen-sharing bug specifically targeted the annotation feature, which allows users to draw on their screen during meetings. This zero-click vulnerability enabled attackers to remotely execute malicious code on victims' devices with no user interaction required and no visual cue indicating the compromise

3

5

. Anyone on a call involving screen sharing, whether participants or the host, would have been vulnerable to a silent attack. The vulnerability affected devices running all operating systems that Zoom supports—Windows, macOS, Linux, iOS, and Android

1

4

.

Democratization of Hacking Capabilities Raises Enterprise Risks

Vulnerability researcher Idan Levcovich emphasized the severity of this shift: "Producing a working exploit against it has always been nation-state work: elite teams, months of effort, budgets that governments regulate as weapons. A [Security] did it in a single day, with an AI agent and models anyone can access today"

3

. This democratization of hacking capabilities means sophisticated cyber threats are now accessible to a broader range of actors. A Security cofounder Yossi Torati outlined the enterprise risks: "If I'm an attacker, I can be on a call with someone from a company, take control of their computer and their credentials, and then use them to move laterally in the enterprise"

2

.

Source: Android Authority

Source: Android Authority

Patches Deployed After Responsible Disclosure

A Security notified Zoom about the bug on June 10, and the company acknowledged it the following day

4

. Zoom issued a security advisory on Tuesday, deploying both server-side and client-side fixes—patches for both Zoom's own servers and the applications running on customer devices

1

. The vulnerability existed in all Zoom Workplace platforms prior to versions 7.1.5 and 7.0.6

4

. Users are urged to apply the latest updates immediately to protect themselves from potential exploitation.

Trust Assumptions in Video Conferencing Create New Attack Vectors

The researchers emphasized that Zoom represents a particularly concerning target because people assume trust when using it and don't see it as a threat

2

. Given how ubiquitous video calling has become in both personal and professional contexts, and that Zoom is widely used for events and semi-public activities like webinars, participants typically have their guard down when joining calls

2

. The AI bug hunting systems specifically targeted the annotation protocol because, like human bug hunters, they have been trained that convoluted and obscure functions in proprietary, closed-source software often contain overlooked vulnerabilities

1

. As AI bug hunting proliferates, what practitioners once called a "cat-and-mouse game" has become an all-out race between security researchers and potential attackers

2

.

Source: Engadget

Source: Engadget

Today's Top Stories

© 2026 TheOutpost.AI All rights reserved