
Researchers disclosed critical vulnerabilities in Zoom's screen-sharing feature that could allow attackers to silently take over any participant's device during a call.
The flaws, discovered using publicly available AI models in under 20 prompts, highlight how artificial intelligence is making sophisticated hacking accessible to people with minimal expertise.
Zoom has already begun deploying fixes across all supported operating systems.
What happened
Researchers at A Security disclosed vulnerabilities in Zoom's screen-sharing annotation protocol on Tuesday that could have allowed anyone on a call—participants or host—to silently take over targets' devices across all operating systems Zoom supports (Windows, macOS, Linux, iOS, Android). The researchers used publicly available AI models to discover the flaws in early June with fewer than 20 prompts. Zoom has already begun rolling out server and client-side fixes.
Why it matters
The attack required no user action or indication of compromise, and worked simply by joining a Zoom call—an act people treat as inherently trustworthy. A Security cofounder Omer Gull emphasized that the real danger is "the democratization of these capabilities—the barrier to entry is dropping rapidly." What once took "a team of five people maybe six months" to discover, AI can now uncover in under 20 prompts. Attackers could potentially gain credentials and move laterally through an entire enterprise.
What to watch
Zoom did not respond to requests for comment from WIRED. The company has issued a security advisory with details of the fixes already in progress. The incident underscores how AI tools are lowering the cost and skill required to find and exploit software vulnerabilities, even in mature, widely-trusted platforms.
On Tuesday, researchers from A Security publicly disclosed vulnerabilities in Zoom's video conferencing platform that could have allowed any participant in a screen-sharing session to silently take over another person's device. The flaws affected all operating systems Zoom supports: Windows, macOS, Linux, iOS, and Android. Critically, an attacker would need no special interaction from or indication to the victim; joining the call itself would be sufficient to launch a successful exploit.
The vulnerabilities were discovered in early June using only publicly available AI models and required fewer than 20 prompts to uncover and weaponize. The specific target was Zoom's annotation protocol—the real-time system that enables drawing and markup during screen sharing. A Security researchers deliberately focused on this component because they recognized, as human security researchers do, that convoluted and obscure functions in proprietary, closed-source software are statistically more likely to contain overlooked vulnerabilities. While an established company like Zoom presumably conducts extensive code review, the lack of public, open-source scrutiny leaves esoteric features more exposed.
Zoom issued a security advisory on Tuesday disclosing the flaws and detailing fixes the company had already begun rolling out via both server-side and client-side patches. The company did not respond to WIRED's requests for comment. However, A Security's cofounders emphasized the severity of what had been possible. Yossi Torati stated: "If you just get on a Zoom with us, we can take over your device. The worst case scenario is that we can take over an enterprise just by having this vulnerability in our hands. If I'm an attacker I can be on a call with someone from a company, take control of their computer and their credentials, and then use them to move laterally in the enterprise." Omer Gull highlighted the structural shift: "What is interesting for us and what we believe is dangerous is the democratization of these capabilities—the barrier to entry is dropping rapidly. Before it would have taken a team of five people maybe six months with a lot of refining and iteration to find this. Now people can reach the same results with under 20 prompts."
The Zoom vulnerabilities represent a watershed moment in the intersection of artificial intelligence and cybersecurity. Researchers discovered flaws in a proprietary, closed-source platform—the very type of software that traditionally benefits from extended code review and vetting by established companies. Yet AI tools identified exploitable weaknesses in Zoom's annotation protocol, a convoluted and obscure function that human bug hunters have long recognized as a typical hiding place for overlooked vulnerabilities. What makes this discovery alarming is not the vulnerability itself but the method and speed of discovery: publicly available AI models needed fewer than 20 prompts to replicate work that would have taken a specialized team months.
A Security cofounder Omer Gull framed the central threat as "the democratization of these capabilities." Zoom is particularly dangerous as a target because users extend implicit trust when joining a call, lowering their guard in professional and personal contexts alike. The potential attack surface is staggering: an attacker could join an enterprise Zoom call, compromise a single employee's device, steal their credentials, and then pivot laterally through the entire organization. The fixes Zoom has already rolled out address the immediate flaw, but the incident signals a structural shift in the security landscape—one in which AI tools are collapsing the time and expertise barriers that once protected complex systems from exploitation.
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · takes 30 seconds · unsubscribe anytime
Ask AI anything about this article. Q&As are published on this page for other readers too.
HireRoad, an HR software company, scrapped its 18-month legacy product rewrite plan and instead reorganized it…

Spotify will label artist profiles as "AI Persona" if they do not represent a real person, starting mid-Septem…

A portable, open-source tool called Se-harness (seh) generates unified instruction files (AGENTS.md) that work…

Snowflake held the inaugural CTO Circle event during Snowflake Summit 2026 in San Francisco, bringing together…

Snowflake held the inaugural CTO Circle event during Snowflake Summit 2026 in San Francisco, bringing together…

GitHub released the Copilot SDK for Java (version 1.0.7-preview.1), a client library that lets Java developers…

The AI news that matters, in one minute each morning.
Sign up free