Key facts
- Vulnerabilities in Zoom's screen sharing annotation protocol could allow for silent device takeover.
- AI models were used to discover these flaws with minimal prompts.
- Zoom has begun issuing security advisories and rolling out fixes.
- The vulnerabilities affected all supported operating systems: Windows, macOS, Linux, iOS, and Android.
- Researchers noted the increasing ease with which sophisticated hacking capabilities can be accessed.
Researchers have disclosed vulnerabilities in Zoom's video conferencing platform that could enable attackers to silently hijack users' devices through screen sharing. The flaws were discovered in early June by researchers from the digital defense firm A Security, who utilized publicly available AI models and required fewer than 20 prompts to identify and create a working exploit. Zoom has since issued a security advisory and begun deploying fixes for the vulnerabilities, which impacted all supported operating systems, including Windows, macOS, Linux, iOS, and Android.
