AI Models Uncover Critical Zoom Vulnerability in Screen Sharing with Fewer Than 20 Prompts

Reviewed byNidhi Govil

12 Sources

Share

Researchers at A Security discovered a critical Zoom vulnerability using publicly available AI models with fewer than 20 prompts. The flaw in Zoom's screen sharing annotation feature allowed attackers to hijack devices through remote code execution across Windows, macOS, Linux, iOS, and Android platforms without any victim interaction.

AI Models Expose Critical Zoom Vulnerability in Record Time

Researchers from digital defense firm A Security uncovered a severe Zoom vulnerability using publicly available AI models with fewer than 20 prompts

1

2

. The discovery, made in early June, demonstrates how AI-assisted research is fundamentally changing cybersecurity by enabling attackers to develop nation-state-level exploits in under 24 hours. The democratization of hacking capabilities means what previously required a team of five people working for six months can now be achieved in a single day

3

.

How the Screen Sharing Exploit Worked

The Zoom vulnerability existed in the protocol used to facilitate real-time annotation during screen sharing

1

. Anyone on a call involving screen sharing—whether participants or the host—became vulnerable to a silent attack requiring no interaction from the victim. The exploit enabled remote code execution, allowing attackers to take complete control of target devices across all platforms Zoom supports: Windows, macOS, Linux, iOS, and Android

5

. This zero-click exploit showed no visual cue indicating the compromise, making it particularly dangerous

3

.

Source: Wired

Source: Wired

The technical vulnerability involved a buffer overrun in the code library handling annotations

4

. The annotation feature received objects in serialized form with count fields, but the code failed to check maximum size boundaries. Attackers could exploit this by sending oversized data chunks padded with malicious code.

The Scope and Impact of Zoomsday

Dubbed the "Zoomsday vulnerability," this flaw affected Zoom Workplace versions before 7.0.6 and 7.1.5 on the fast track branch

4

. With Zoom's monthly active users estimated at around 220 million and commanding approximately 56% of the global conferencing market share, the exploitable area was substantial

4

.

"If you just get on a Zoom with us, we can take over your device," A Security cofounder Yossi Torati explained

2

. The worst-case scenario involved enterprise takeovers, where an attacker could join a call with a company employee, seize control of their computer and credentials, then move laterally throughout the enterprise network.

AI-Assisted Research Reshapes Cybersecurity Landscape

The discovery highlights how AI models are lowering the barrier to entry for sophisticated cyber threats. "What is interesting for us and what we believe is dangerous is the democratization of these capabilities—the barrier to entry is dropping rapidly," said A Security cofounder Omer Gull

2

. The AI bug hunting systems specifically targeted the annotation feature because, like human bug hunters, they've been trained to recognize that convoluted and obscure functions often contain overlooked vulnerabilities

1

.

Source: Tom's Hardware

Source: Tom's Hardware

Vulnerability researcher Idan Levcovich from A Security emphasized that "producing a working exploit against it has always been nation-state work: elite teams, months of effort, budgets that governments regulate as weapons"

3

. That model has now collapsed, with offensive security capabilities becoming accessible through publicly available AI models.

Zoom Patches and Response Timeline

A Security notified Zoom about the vulnerability on June 10, and the company acknowledged it the following day

5

. Zoom issued security advisories on Tuesday, detailing both server-side and client-side fixes—Zoom patches for both the company's servers and applications running on customer devices

1

. The company deployed fixes within weeks to mitigate the threat

5

. Users running updated versions of Zoom Workplace should now be protected from this exploit.

Why This Development Matters

This incident underscores a critical shift in the cybersecurity landscape. The traditional 90-day security bug disclosure window appears increasingly inadequate when AI models can identify and weaponize vulnerabilities in hours rather than months

4

. Video conferencing platforms like Zoom occupy a unique position of trust in both personal and professional contexts, making them attractive targets. People typically have their guard down when joining a Zoom call, viewing it as a gesture of trust rather than a potential threat vector

2

.

Source: Android Authority

Source: Android Authority

The proprietary, closed-source nature of Zoom's software made the annotation feature particularly vulnerable. While established companies conduct extensive code review and vetting, esoteric yet complex features like annotation are more likely to contain mistakes without the benefit of public, open review

1

. As A Security researchers noted, "the barrier that kept these weapons scarce has collapsed, and it will not come back"

4

, signaling that organizations must fundamentally rethink their security postures in an era where AI models accelerate both vulnerability research and exploit development.

Today's Top Stories

© 2026 TheOutpost.AI All rights reserved