9 Sources
[1]
Researchers found a way to hijack devices through Zoom screen sharing
As AI models gain advanced capabilities to find vulnerabilities in software, develop ways to exploit them, and even carry out autonomous hacking sprees, researchers offered a sobering new example on Tuesday, disclosing vulnerabilities in the video conferencing platform Zoom that could have been exploited to take over targets' devices. Anyone on a call that involved screen sharing, whether participants or the host, would have been vulnerable to a silent attack that could be carried out with no indication and no interaction from the victim. Researchers from the digital defense firm A Security say the bug was discovered in early June using publicly available AI models, and that it took fewer than 20 prompts to uncover the vulnerabilities and create a working attack. Zoom issued a security advisory on Tuesday, including details about fixes the company has already begun rolling out to address the flaws, which affected devices running all operating systems that Zoom supports -- Windows, macOS, Linux, iOS, and Android. "What is interesting for us and what we believe is dangerous is the democratization of these capabilities -- the barrier to entry is dropping rapidly," A Security cofounder Omer Gull told WIRED ahead of the disclosure. "Before it would have taken a team of five people maybe six months with a lot of refining and iteration to find this. Now people can reach the same results with under 20 prompts. And Zoom is an important type of target because people assume trust when using it. They don't see it as a threat." The vulnerabilities were specifically in the protocol used to facilitate real-time annotation during screen sharing. The researchers say that their AI bug hunting systems specifically delved into this component because, like human bug hunters, they have been trained that convoluted and obscure functions often contain overlooked vulnerabilities. This is particularly true with proprietary, closed-source software. An established company like Zoom presumably does extensive code review and vetting on all components and functions, but without the benefit of public, open review, esoteric yet complex features like annotation are more likely to contain mistakes. Zoom did not respond to multiple requests for comment from WIRED about the A Security findings. The bugs are now patched, with Zoom issuing both server and client-side fixes -- or patches for both Zoom's own servers and the applications that run on customer devices. But the researchers emphasize that it was alarming to contemplate bugs that could have been exploited to take over a target device simply by getting someone onto a Zoom call. Joining a call is in itself a gesture of trust, but given how ubiquitous video calling is in both personal and professional contexts -- and given that Zoom in particular is also widely used for events and semipublic activities like webinars -- people typically have their guard down when joining a Zoom. "If you just get on a Zoom with us, we can take over your device," A Security cofounder Yossi Torati told WIRED on a call. (It was, incidentally, hosted on Microsoft Teams.) "The worst-case scenario is that we can take over an enterprise just by having this vulnerability in our hands. If I'm an attacker, I can be on a call with someone from a company, take control of their computer and their credentials, and then use them to move laterally in the enterprise." Practitioners often call security a "cat-and-mouse game," but as AI bug hunting proliferates, this delicate dance has become an all-out race. This story originally appeared on wired.com.
[2]
A Zoom Screen-Sharing Bug Let Anyone Take Over Other Devices on a Call
As AI models gain advanced capabilities to find vulnerabilities in software, develop ways to exploit them, and even carry out autonomous hacking sprees, researchers offered a sobering new example on Tuesday, disclosing vulnerabilities in the video conferencing platform Zoom that could have been exploited to take over targets' devices. Anyone on a call that involved screen sharing, whether participants or the host, would have been vulnerable to a silent attack that could be carried out with no indication and no interaction from the victim. Researchers from the digital defense firm A Security say the bug was discovered in early June using publicly available AI models, and that it took fewer than 20 prompts to uncover the vulnerabilities and create a working attack. Zoom issued a security advisory on Tuesday, including details about fixes the company has already begun rolling out to address the flaws, which affected devices running all operating systems that Zoom supports -- Windows, macOS, Linux, iOS, and Android. "What is interesting for us and what we believe is dangerous is the democratization of these capabilities -- the barrier to entry is dropping rapidly," A Security cofounder Omer Gull told WIRED ahead of the disclosure. "Before it would have taken a team of five people maybe six months with a lot of refining and iteration to find this. Now people can reach the same results with under 20 prompts. And Zoom is an important type of target because people assume trust when using it. They don't see it as a threat." The vulnerabilities were specifically in the protocol used to facilitate real-time annotation during screen sharing. The researchers say that their AI bug hunting systems specifically delved into this component because, like human bug hunters, they have been trained that convoluted and obscure functions often contain overlooked vulnerabilities. This is particularly true with proprietary, closed source software. An established company like Zoom presumably does extensive code review and vetting on all components and functions, but without the benefit of public, open review, esoteric yet complex features like annotation are more likely to contain mistakes. Zoom did not respond to multiple requests for comment from WIRED about the A Security findings. The bugs are now patched, with Zoom issuing both server and client-side fixes -- or patches for both Zoom's own servers and the applications that run on customer devices. But the researchers emphasize that it was alarming to contemplate bugs that could have been exploited to take over a target device simply by getting someone onto a Zoom call. Joining a call is in itself a gesture of trust, but given how ubiquitous video calling is in both personal and professional contexts -- and given that Zoom in particular is also widely used for events and semi-public activities like webinars -- people typically have their guard down when joining a Zoom. "If you just get on a Zoom with us, we can take over your device," A Security cofounder Yossi Torati told WIRED on a call. (It was, incidentally, hosted on Microsoft Teams.) "The worst case scenario is that we can take over an enterprise just by having this vulnerability in our hands. If I'm an attacker I can be on a call with someone from a company, take control of their computer and their credentials, and then use them to move laterally in the enterprise." Practitioners often call security a "cat and mouse game," but as AI bug hunting proliferates, this delicate dance has become an all out race.
[3]
'Zoomsday' hack uncovered using fewer than 20 AI prompts
Zoom has patched a major security vulnerability that could allow an attacker to hijack anyone's device during a meeting. In a blog post on Tuesday, researchers at A Security say they uncovered the flaw using "fewer than 20 prompts on publicly available AI models," as reported earlier by Wired. The exploit involved Zoom's annotation feature, which allows users to draw on their screen while sharing it with other meeting participants. With the exploit, an attacker could join or host a meeting and run malicious code on victims' devices, allowing them to steal data, turn on the camera or microphone, or install malware. The attack required no action from victims and showed "no visual cue indicating the compromise," according to A Security. "Producing a working exploit against it has always been nation-state work: elite teams, months of effort, budgets that governments regulate as weapons," Idan Levcovich, a vulnerability researcher at A Security, writes in the blog post. "A [Security] did it in a single day, with an AI agent and models anyone can access today." Zoom issued a fix for the vulnerability on Tuesday, which impacted the app across Windows, macOS, Linux, Android, and iOS.
[4]
Zoom Screen-Sharing Flaw Could Give Attackers Control of Participants' Devices
(Credit: Thomas Fuller/SOPA Images/LightRocket via Getty Images) Researchers at A Security have discovered a critical bug in Zoom that allows attackers to assume full control of a participant's device by exploiting a flawed screen-sharing function. The vulnerability exists in the Zoom Workspace app for Windows, Mac, iOS, Android, and Linux. When a user launches the annotation tool while sharing their screen, the bug allows attackers to remotely execute malicious code and access participants' devices. The attack requires no action from a victim's end and leaves no visible warning, A Security says in its blog post. The firm discovered the bug and developed a working exploit for it in just 24 hours. They did it using just 20 prompts on a publicly available AI model, highlighting how AI can make cyberattacks easier to carry out. "This class of capability would previously have only been available to nation-state threat actors, but the model requiring elite teams, months of effort, and weapons-grade budgets has collapsed," A Security says. "Today, a single researcher was able to develop a nation-state-level exploit in less than a day." A Security notified Zoom about the bug on June 10. Zoom acknowledged it the next day and deployed client-side and server-side fixes to mitigate the threat a few weeks later. The video-conferencing service also published security bulletins noting that the vulnerability exists across all Zoom Workplace platforms prior to versions 7.1.5 and 7.0.6. "Users can help keep themselves secure by applying the latest updates," Zoom adds. This comes after Apple issued emergency macOS updates to fix a similar screen-sharing flaw that allowed attackers to view a user's screen, open files, and launch apps.
[5]
Zoom screen-sharing bug let people fully take over other devices on a call - Engadget
Cybersecurity researchers discovered a fairly insidious bug in Zoom that lets people quite literally take control of someone else's device. This is done by exploiting a flaw in the screen-sharing function. The vulnerability has been found in the Zoom Workspace app for Windows, Mac, iOS Android and Linux. Attacks do not require the victim to do anything and there's no visible warning. When someone launches the annotation tool while sharing the screen, the vulnerability lets bad actors remotely execute malicious code for access. However, it remains to be seen if this vulnerability has ever been used in the wild. The researchers that found it used AI prompts to develop the screen-sharing exploit in under 24 hours, illustrating how AI could assist in cyberattacks. "This class of capability would previously have only been available to nation-state threat actors, but the model requiring elite teams, months of effort and weapons-grade budgets has collapsed," the cybersecurity company wrote in a blog post. "Today, a single researcher was able to develop a nation-state-level exploit in less than a day." Zoom was notified about the bug and has deployed various fixes to mitigate the threat. It says "users can help keep themselves secure by applying the latest updates." The vulnerability exists in all Zoom Workspace versions prior to the latest updates. Something similar just happened to Apple computers, forcing the company to issue various macOS updates. The newest versions, including Tahoe 26.6.1, Sequoia 15.7.9 and Sonoma 14.8.9 are all safe.
[6]
Zoom fixed three bugs that let anyone on a call take over your machine
The flaws needed no click and left no visible trace, but the patches went out two months ago and the AI discovery story is thinner than it looks Zoom has patched three memory corruption flaws in its annotation feature that allowed any meeting participant to run code on another attendee's device with no interaction. The fixes shipped in June and July 2026, roughly two months before the research was made public. Zoom has patched three flaws in the annotation tools used during screen sharing that let anyone on a call run code on another participant's device. No click was needed and nothing visible happened. The fixes shipped in June and July. That timing is worth stating plainly, because the story has been written up as an emergency. Zoom closed the holes roughly two months before the research went public, so anyone on a current client is already covered. The fixed builds are Zoom Workplace 7.1.5 and 7.0.6, Rooms and the Meeting SDK at 7.1.5, and the Windows VDI client at 7.0.11 and 6.6.16. Anything older remains exposed. The severity is also softer than reported. A Security, the firm that found the bugs, scored all three at 9.0 out of 10. Zoom rates CVE-2026-53413 and CVE-2026-53415 at 8.3 and CVE-2026-53414 at 6.5. The mechanics are ordinary memory-safety failures. Annotations cross the network as a run of counts followed by data, and the receiving client trusted those counts, letting one value overrun a 128-byte buffer and corrupt a return address. A second flaw let the dispatcher accept annotation messages without checking which participant had sent them. An attacker on the call, host or guest, could send a crafted message that executed on other machines with no prompt and no indication. What follows is the usual menu, file theft, camera and microphone access, credential and wallet harvesting, second-stage payloads. The headline claim is that AI did the work. A Security says it went from flaws to working exploit in under a day, using fewer than 20 prompts on publicly available models, and argues that this capability was until recently the preserve of nation states. OpenAI has meanwhile shipped a cyber model trained to refuse less. Its own writeup complicates that. An automated ranking pass across 3,762 functions missed the vulnerable library entirely, placing it 45th, and the bug only surfaced when a researcher traced a live call by hand. AI weaponised it fast, but a human found it. The wider shift is real regardless. Anthropic's Mythos has found 10,000 critical vulnerabilities in a month, faster than anyone can patch them.
[7]
Turns Out You Don't Need The Most Powerful AI Models to Cause a Major Cybersecurity Incident
There are few things more mortifying than the prospect of sharing something you didn't intend to on a work Zoom call. Now imagine it's entirely out of your control. That is the risk of a security flaw discovered and disclosed by a cybersecurity company called A Security, which found a vulnerability that allowed an attacker to hijack the device of any user involved in a call with screen sharing. Notably, the group claims to have found the issue with just a few AI prompts. According to the firm, the vulnerability was about as bad as it gets: a zero-click remote code execution that takes advantage of the way Zoom's annotation feature works. The company explained in a blog post that because Zoom's client "automatically parses whatever it receives" while the annotation feature is in use, an attacker could send a "specially crafted message to corrupt the receiving client's memory and run code on it." And because the protocol within the app creates a direct channel between the viewer and sharer, each participant on the call could be targeted individually. That's pretty bad, made worse by the fact that the vulnerability was apparently present in every version of Zoom on every operating system, and was even exploitable in calls where end-to-end encryption was active. It has since been patched, but you'll have to update to make sure you're not subject to the hijacking technique. What makes the flaw particularly worth mentioning is how it was discovered in the first place. According to A Security, the company was able to find the vulnerability using publicly available AI models, which were able to identify and exploit the issue in fewer than 20 prompts and in under 24 hours. Of course, the models were guided by security researchers with real know-how providing direction on what to look for, but it does speak to the ways that AI models are impacting the cybersecurity landscape. All of the frontier AI labs have made hay about just how powerful their top-tier models are -- so powerful, in fact, that access to them must be restricted so the power doesn't fall into the wrong hands. But even the publicly available tools seem to be upending the cyber industry. Just last week, officials from the United States and the United Kingdom warned at the Black Hat cybersecurity conference in Las Vegas that the speed at which people are discovering vulnerabilities is quickly surpassing the ability to patch them. Safety was never guaranteed, but it seems we're all increasingly vulnerable without fully realizing it.
[8]
This shocking Zoom bug allowed silent device takeovers on Android and iOS
Zoom has patched the flaws, so updating the Zoom app is the most important thing you can do. Over the past few months, we have watched frontier AI models rapidly alter the cybersecurity landscape -- from AI models breaking technical barriers to mounting regulatory scrutiny over weaponized AI capabilities. Now, a newly disclosed Zoom flaw shows just how serious that can become. Researchers used undisclosed publicly available AI models to uncover a vulnerability that could have allowed someone on a Zoom call to take control of another participant's device. The flaw affected Zoom clients on Windows, macOS, Linux, iOS, and Android. Worse, the attack required no click, download, or other action from the victim. Simply being in the same meeting could be enough. The vulnerability was found in Zoom's annotation system, which handles features such as drawing and adding text while sharing a screen. A Security discovered (via Wired) that specially crafted annotation data could trigger memory corruption in the receiving client and ultimately enable remote code execution. What's even scarier is that it took fewer than 20 prompts to find the flaws and produce a working exploit in under 24 hours, something that previously took lots of time and resources. That puts a real-world example behind growing concerns about AI-assisted security research. The same technology can help defenders find vulnerabilities faster, but it can also reduce the effort required to discover weaknesses in widely used software. Google, for example, is already using AI agents to uncover and help address vulnerabilities in Chrome. What makes this bug particularly dangerous for everyday users is its zero-click execution and cross-platform reach. The flaw existed inside Zoom's proprietary screen-sharing annotation engine (libannotate.so), an always-on component that automatically parses incoming drawing and text data. Because the same binary source compiles across all native Zoom Workplace apps, devices running Android, iOS, Windows, macOS, and Linux were equally exposed. Without requiring any clicks, downloads, or interactions from the victim, an attacker could silently corrupt system memory, extract personal data, activate the device's camera or microphone, or install secondary malware, undetected. For Zoom users, there's a straightforward takeaway: update the app. A Security reported the vulnerabilities to Zoom in June, and the company subsequently deployed client-side and server-side fixes. The flaws are tracked as CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415. Affected products include Zoom Workplace on all supported platforms before versions 7.1.5 and 7.0.6 in their respective branches, Zoom Workplace VDI Client for Windows before versions 7.0.11 and 6.6.16, Zoom Rooms on all supported platforms before version 7.1.0, and Zoom Meeting SDK on all supported platforms before version 7.1.0. So, while there's no indication that ordinary Zoom users need to stop making calls, running an outdated client isn't worth the risk. If your Zoom app hasn't updated recently, check for an update before your next meeting.
[9]
A dangerous Zoom screen-sharing bug could have let hackers hijack other devices on a call
* AI‑found Zoom flaws enabled device takeover through malicious annotation messages * Exploits worked across all platforms and required only joining a video call * Researchers warn AI now enables rapid, nation‑state‑level exploit development Experts have warned that Zoom, one of the most popular collaboration tools in the world, carried multiple vulnerabilities that allowed malicious actors to take over people's devices, entirely. What makes these vulnerabilities particularly dangerous is that the victims need not do much to be compromised - participating in a video call with the attacker is enough. The bugs were said to be present in every version of Zoom, on every device and operating system - Windows, Mac, iPhone, Android, and Linux, in all versions up to and including 7.0.5 - with patches available now, so be sure to update immediately. AI-powered security The flaws were discovered by security researchers A Security, which focuses on "autonomous offensive security", using AI agents to simulate real-work attacks, identify vulnerabilities, and chain them into exploitable attack paths. The company "simply" used publicly available frontier models and within 24 hours and fewer than 20 prompts, went from finding the flaws to building a working exploit. The flaws are described as memory corruption bugs exploiting Zoom's annotation feature. That feature, built on a proprietary protocol (meaning it has no public documentation or specifications, as opposed to being open source), meant that the Zoom client parsed everything it received, including specially crafted, malicious messages. During the call, a malicious actor could send a message to each visitor that would corrupt their device's memory and execute weaponized code, all without the victim knowing, being prompted to do anything, or clicking anything at all. The vulnerability can be exploited regardless of if the attacker hosted, or simply joined, a call. All participants, regardless of their status in the call, were equally at risk. There were no visual cues indicating the compromise whatsoever. Once the threat actor runs the malware on the victim's device, they can do all sorts of things, from stealing sensitive files, to switching on the device's camera or microphone. They can also deploy stage-two malware, steal login credentials and crypto wallet information, access the inbox, and more. A Security responsibly disclosed their findings to Zoom, who labeled the vulnerabilities as CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415, and all given a severity score of 9.0/10 (critical). Furthermore, all Zoom Workplace clients on all supported platforms before version 7.1.5 and 7.0.6 using end-to-end encryption settings are considered vulnerable. A Security recommends updating the client to the latest version. Lowering the barrier In its writeup, A Security stressed the simplicity and ease with which it managed to find the bugs and develop the exploits. It warned that AI has dramatically lowered the barrier for entry, and argued that in the pre-AI era, exploits like these were "reserved" for nation-state threat actors with virtually limitless resources: "This class of capability would previously have only been available to nation-state threat actors, but the model requiring elite teams, months of effort, and weapons-grade budgets has collapsed," the researchers warned. "Today, a single researcher was able to develop a nation-state-level exploit in less than a day." To add insult to injury, these flaws were found using "publicly available frontier models" such as GPT-5.6 Sol, Claude Opus 5, and the likes. Besides the frontier models, these companies also have dedicated cybersecurity programs where they offer specialized models with fewer guardrails and more flexibility for both offensive and defensive actions. Earlier this week, OpenAI said that its Daybreak project now offers GPT-5.6-Cyber, a model built on GPT‑5.6 Sol and trained to improve capabilities on several specialized cybersecurity tasks such as finding zero-day vulnerabilities and developing exploit chains. Daybreak came as a direct response to Anthropic's Project Glasswing. This is an offering that came with Mythos Preview, an AI model that proved unusually capable at cybersecurity tasks. Allegedly, Mythos can autonomously identify and exploit zero-day flaws across major operating systems and browsers, as well as develop complex exploit chains. Because of those capabilities, Anthropic did not release Mythos Preview broadly. Instead, it made the model available to a limited group of organizations. While some expressed their skepticism over Mythos, saying Anthropic is engaging in fear-based marketing, others have backed the company, saying Mythos proved exceptionally useful at identifying and fixing flaws. Microsoft, for example, is one of the original Project Glasswing partners, and ever since it started using it, the number of flaws patched through its Patch Tuesday cumulative update quadrupled. Mozilla is also among those showering Mythos with praise, saying earlier this year that it is "every bit as capable" as the world's best security researchers. If A Security managed to find such dangerous flaws with publicly available models, there's no telling what these dedicated models can do. Via The Hacker News Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
Share
Copy Link
A Security researchers uncovered a critical Zoom vulnerability using fewer than 20 AI prompts that allowed attackers to take over other devices on a call through screen sharing. The zero-click vulnerability affected all platforms and required no user interaction, highlighting the democratization of hacking capabilities through AI in cybersecurity.
Cybersecurity researchers at A Security discovered a severe Zoom vulnerability that could allow attackers to hijack devices through Zoom screen sharing, and they did it using fewer than 20 AI prompts on publicly available AI models
1
2
. The discovery, made in early June, took less than a day to develop into a working exploit, demonstrating how AI in cybersecurity is lowering barriers for both defenders and potential attackers. According to A Security cofounder Omer Gull, what previously would have required a team of five people working for six months can now be achieved with under 20 prompts2
.
Source: Wired
The Zoom screen-sharing bug specifically targeted the annotation feature, which allows users to draw on their screen during meetings. This zero-click vulnerability enabled attackers to remotely execute malicious code on victims' devices with no user interaction required and no visual cue indicating the compromise
3
5
. Anyone on a call involving screen sharing, whether participants or the host, would have been vulnerable to a silent attack. The vulnerability affected devices running all operating systems that Zoom supports—Windows, macOS, Linux, iOS, and Android1
4
.Vulnerability researcher Idan Levcovich emphasized the severity of this shift: "Producing a working exploit against it has always been nation-state work: elite teams, months of effort, budgets that governments regulate as weapons. A [Security] did it in a single day, with an AI agent and models anyone can access today"
3
. This democratization of hacking capabilities means sophisticated cyber threats are now accessible to a broader range of actors. A Security cofounder Yossi Torati outlined the enterprise risks: "If I'm an attacker, I can be on a call with someone from a company, take control of their computer and their credentials, and then use them to move laterally in the enterprise"2
.
Source: Android Authority
Related Stories
A Security notified Zoom about the bug on June 10, and the company acknowledged it the following day
4
. Zoom issued a security advisory on Tuesday, deploying both server-side and client-side fixes—patches for both Zoom's own servers and the applications running on customer devices1
. The vulnerability existed in all Zoom Workplace platforms prior to versions 7.1.5 and 7.0.64
. Users are urged to apply the latest updates immediately to protect themselves from potential exploitation.The researchers emphasized that Zoom represents a particularly concerning target because people assume trust when using it and don't see it as a threat
2
. Given how ubiquitous video calling has become in both personal and professional contexts, and that Zoom is widely used for events and semi-public activities like webinars, participants typically have their guard down when joining calls2
. The AI bug hunting systems specifically targeted the annotation protocol because, like human bug hunters, they have been trained that convoluted and obscure functions in proprietary, closed-source software often contain overlooked vulnerabilities1
. As AI bug hunting proliferates, what practitioners once called a "cat-and-mouse game" has become an all-out race between security researchers and potential attackers2
.
Source: Engadget
Summarized by
Navi
31 Jul 2026•Technology

12 Jun 2025•Technology

28 Jul 2026•Technology

1
Technology

2
Science and Research

3
Technology
