mimile
Back to feed

Zoom fixes screen-sharing flaw that allowed silent device takeover

AI digest

This digest was compiled by AI from multiple sources — links to the originals are below.

Zoom fixes screen-sharing flaw that allowed silent device takeover

Zoom has patched a vulnerability in its screen-sharing protocol that could let attackers hijack devices on calls without any user interaction. Researchers from A Security discovered the flaw using publicly available AI models in fewer than 20 prompts. The bug affected all platforms that Zoom supports, including Windows, macOS, Linux, iOS, and Android.

The Vulnerability

The flaw resided in the protocol for real-time annotation during screen sharing. Anyone on a call, whether host or participant, could have been silently attacked with no indication. All Zoom-supported operating systems were affected, including Windows, macOS, Linux, iOS, and Android. A Security's AI bug-hunting systems targeted this component because obscure, convoluted functions in proprietary software often conceal overlooked mistakes.

AI Bug Hunting

The vulnerability was discovered in early June using publicly available AI models. A Security cofounder Omer Gull said it took fewer than 20 prompts to create a working exploit. Previously, such a find might have required a five-person team and six months of refinement. Gull warned that the democratization of these capabilities is rapidly lowering the barrier to entry, making trusted platforms like Zoom attractive targets as users lower their guard.

Zoom's Response

Zoom issued a security advisory on Tuesday detailing the bug and its fixes. Both server-side and client-side patches have been rolled out. The company did not respond to WIRED's multiple requests for comment on the A Security findings. While the vulnerabilities are now mitigated, the incident illustrates the risk that any participant on a Zoom call could potentially be a vector for device takeover.

What's Next

A Security cautions that similar vulnerabilities may exist in other widely trusted platforms. It remains uncertain whether AI-driven bug hunting will lead to a flood of discovered threats or a more resilient software ecosystem.

3 sources

Zoom fixes screen-sharing flaw that allowed silent device takeover