A Zoom Screen-Sharing Bug Let Anyone Take Over Other Devices on a Call

| Source: Wired AI

Tags: Zoom, AI security, vulnerability discovery, zero-click exploit, A Security, Palo Alto Networks

An AI tool found a critical Zoom screen-sharing vulnerability in fewer than 20 prompts that let any call participant silently take over another device — demonstrating how AI is dramatically lowering the bar for software vulnerability discovery.

Details

Security researchers at A Security disclosed vulnerabilities in Zoom's screen-sharing annotation protocol that let any participant on a call — not just the host — silently hijack another participant's device across all platforms: Windows, macOS, Linux, iOS, and Android. The attack required no user interaction and left no visible indication.\n\nThe finding's most notable aspect is how it was discovered: using publicly available AI models, researchers found the vulnerability in fewer than 20 prompts. The same task would previously have required a five-person team working approximately six months. That is a fundamental shift in the economics of offensive security research.\n\nThe bugs lived in the convoluted annotation-during-screen-sharing protocol — exactly the kind of complex, proprietary, rarely-scrutinized code that AI bug hunters target. Zoom has now issued both server-side and client-side patches.\n\nThe broader takeaway is the democratization of AI-assisted vulnerability research. Security teams need to assume that adversaries with AI tools can find bugs in proprietary systems at dramatically lower cost and time than before — not as a future risk but as a present reality.