HeadlinesBriefing favicon HeadlinesBriefing.com

Zoom Hack via Screen Sharing: AI Found Bug in 20 Prompts

Ars Technica •
×

Researchers have disclosed vulnerabilities in Zoom's video conferencing platform that could have allowed attackers to silently take over devices during screen sharing. The bug was discovered in early June using publicly available AI models, requiring fewer than 20 prompts to uncover the flaws and create a working exploit. Anyone on a call involving screen sharing—host or participant—was vulnerable with no indication or interaction needed.

The vulnerabilities were in the real-time annotation protocol during screen sharing. The researchers from digital defense firm A Security used AI bug hunting systems trained to target obscure, complex features common in proprietary software. Co-founder Omer Gull noted the democratization of such capabilities: what once required a team of five people six months to find can now be achieved with under 20 prompts.

Zoom issued a security advisory on Tuesday and has begun rolling out fixes for all supported operating systems—Windows, macOS, Linux, iOS, and Android. The researchers emphasized that Zoom is a high-value target because users inherently trust the platform, making the silent attack particularly dangerous.