AIToday
Large Language ModelsAI Safety & AlignmentArs Technica AIPublished: Aug 13, 2026, 01:00 JST2 min read

AI found Zoom flaw in under 20 prompts; Zoom patches device takeover bug

AI found Zoom flaw in under 20 prompts; Zoom patches device takeover bug

Key takeaway

  • Researchers at A Security discovered vulnerabilities in Zoom's screen-sharing feature that could allow silent device takeovers, using publicly available AI models and fewer than 20 prompts to uncover and exploit the flaws.

  • Zoom issued a security advisory and began rolling out patches to all supported platforms on Tuesday.

  • The discovery underscores a growing risk: AI-powered vulnerability hunting is dramatically lowering the technical and time barriers for finding exploitable bugs, even in widely-trusted applications.

3 Key Points

  1. What happened

    Researchers at A Security disclosed vulnerabilities in Zoom's screen-sharing annotation protocol on Tuesday that could have allowed attackers to silently take over devices of anyone on a call—whether participant or host. The flaws affected all operating systems Zoom supports (Windows, macOS, Linux, iOS, and Android), and Zoom has begun rolling out fixes.

  2. Why it matters

    The vulnerabilities were discovered using publicly available AI models with fewer than 20 prompts, a dramatic shift from the traditional months-long process that once required a team of specialized researchers. A Security cofounder Omer Gull emphasized the danger: the barrier to entry for finding exploitable flaws is dropping rapidly, and Zoom is a particularly attractive target because users assume it is trustworthy.

  3. What to watch

    The attack required no user interaction or indication—victims would have no warning. The vulnerabilities were specifically in the annotation protocol used during real-time screen sharing, a complex and less-reviewed component of Zoom's closed-source software.

Ask the AI about this article →

Context & Analysis

The discovery highlights a fundamental shift in how software vulnerabilities are found and exploited. Traditionally, uncovering flaws in complex closed-source applications like Zoom required extensive human expertise, time, and resources—a team of five researchers might spend six months refining their approach. Zoom's annotation protocol is precisely the kind of target human hunters would focus on: it is convoluted and obscure, features that researchers have learned often harbor overlooked bugs. Closed-source software is particularly susceptible because it lacks the benefit of public review that can catch mistakes in esoteric components.

What makes this disclosure sobering is the democratization of this capability. By using fewer than 20 prompts to publicly available AI models, the researchers achieved in hours what once required months of specialized work. This dramatic reduction in the "barrier to entry" means that vulnerability discovery is no longer confined to well-resourced security teams. The risk is amplified by Zoom's position of trust: users do not typically perceive it as a threat vector, making it an especially attractive target for attackers wielding AI-powered tools.

FAQ

How were the vulnerabilities discovered?
Researchers from A Security used publicly available AI models and fewer than 20 prompts to uncover the vulnerabilities and create a working attack. The discovery occurred in early June.
Who was vulnerable to the attack?
Anyone on a Zoom call involving screen sharing was vulnerable—both participants and the host—regardless of the operating system (Windows, macOS, Linux, iOS, or Android).
What part of Zoom was affected?
The vulnerabilities were specifically in the protocol used to facilitate real-time annotation during screen sharing.
Ars Technica AIRead Original Article

Get the latest Large Language Models news every morning

For example, today's edition would include:

  • Visko raises $10M, launches live AI video model OrbisSiliconANGLE AI · 1h ago
  • Runway unveils Solaris, an AI that generates app interfaces in real timeTHE DECODER · 1h ago
  • Google AI Search flags Facebook users as dangerTHE DECODER · 1h ago

AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.

Free · takes 30 seconds · unsubscribe anytimeWhat is AIToday? →

Ask AI

Ask AI anything about this article. Q&As are published on this page for other readers too.

Related Articles

Next articlePixel 11 Gets AI Photo-Capture Mode, 120X Zoom, Faster Night Shots