Security researchers at the firm A Security disclosed vulnerabilities in Zoom that could have allowed any participant or host in a screen-sharing call to silently take over another attendee's device, with no visible indication and no interaction required from the victim. The flaws affected every operating system Zoom supports: Windows, macOS, Linux, iOS, and Android.
The bugs were found in early June using publicly available AI models. According to the researchers, it took fewer than 20 prompts to identify the vulnerabilities and build a working exploit. The flaws sat in the protocol that handles real-time annotation during screen sharing — an obscure, complex component the AI bug-hunting systems targeted specifically because such features in closed-source software often harbor overlooked mistakes.
A Security cofounder Omer Gull framed the finding as evidence of a rapid democratization of offensive capability: work that previously might have required a five-person team and six months can now be achieved with a handful of prompts. He noted Zoom is a particularly sensitive target because users inherently treat joining a call as an act of trust.
Cofounder Yossi Torati warned of enterprise-scale consequences: an attacker on a call with a company employee could seize their machine and credentials, then move laterally through the organization's network.
Zoom published a security advisory (ZSB-26015) on Tuesday and has begun rolling out both server-side and client-side fixes. The company did not respond to WIRED's requests for comment. The researchers describe the episode as part of an accelerating race between AI-driven vulnerability discovery and patching.
Comments
No comments yet — be the first.
Open the discussion
No account or password needed — just enter your e-mail and we’ll send you a one-time sign-in link. First time here? You’re set up automatically.
Your rating will be applied automatically after you sign in.
Check your inbox
We’ve sent a sign-in link to …. Open it on this device — this tab will sign you in automatically.
Nothing arrived? Check your spam folder — and mark the mail as "Not spam" so it lands in your inbox next time.