All NewsEducationTV
Equities & FundsCrypto & Digital AssetsAI & TechnologyBusiness & CorporateUS Politics & PolicyGeopolitics & Global RiskMacro, Rates & FXCommodities & EnergyEuropean Politics & MarketsAsia-PacificReal Estate & Property
Story archiveAll categories
← All Stories

Researchers use AI to find Zoom screen sharing vulnerabilities

Created at 12 Aug · 1:46 PM1 source↑ Market-relevant
IN SHORT

Researchers discovered vulnerabilities in Zoom's screen sharing feature that could allow attackers to hijack devices silently. The exploit was found using AI models with minimal prompts, highlighting the increasing accessibility of sophisticated hacking capabilities.

✉Newsletter

PiQ Daily

Pick your topics. Get only what matters, on your cadence.

Key Numbers

20prompts to uncover vulnerabilities

Who's Involved

A Security
digital defense firm that discovered the Zoom vulnerabilities
Omer Gull
cofounder of A Security
Zoom
video conferencing platform affected by the vulnerabilities
Researchers use AI to find Zoom screen sharing vulnerabilities

↳ Why This Matters

The discovery highlights the growing threat of AI-powered cyberattacks and the increasing accessibility of sophisticated hacking tools, posing a significant risk to widely used platforms like Zoom and the security of their users' devices.

Key facts

  • Vulnerabilities in Zoom's screen sharing annotation protocol could allow for silent device takeover.
  • AI models were used to discover these flaws with minimal prompts.
  • Zoom has begun issuing security advisories and rolling out fixes.
  • The vulnerabilities affected all supported operating systems: Windows, macOS, Linux, iOS, and Android.
  • Researchers noted the increasing ease with which sophisticated hacking capabilities can be accessed.

Researchers have disclosed vulnerabilities in Zoom's video conferencing platform that could enable attackers to silently hijack users' devices through screen sharing. The flaws were discovered in early June by researchers from the digital defense firm A Security, who utilized publicly available AI models and required fewer than 20 prompts to identify and create a working exploit. Zoom has since issued a security advisory and begun deploying fixes for the vulnerabilities, which impacted all supported operating systems, including Windows, macOS, Linux, iOS, and Android.

Omer Gull, cofounder of A Security, expressed concern over the rapid decrease in the barrier to entry for sophisticated hacking capabilities, noting that what previously required significant time and resources from a team of experts can now be achieved with minimal AI prompts. He highlighted Zoom as a particularly concerning target due to users' inherent trust in the platform. The vulnerabilities specifically resided within the protocol used for real-time annotation during screen sharing. Researchers targeted this area, reasoning that complex and obscure functions in proprietary, closed-source software are often overlooked.

Frequently asked questions

Attackers could potentially take over a target's device silently during a Zoom call with screen sharing enabled, with no indication or interaction from the victim.

Researchers used AI models to find the flaws in Zoom's screen sharing annotation protocol, requiring fewer than 20 prompts.

The vulnerabilities affected devices running all operating systems supported by Zoom, including Windows, macOS, Linux, iOS, and Android.

Zoom has issued a security advisory and has begun rolling out fixes to address the identified flaws.

What Happens Next

01Zoom continues to roll out fixes for the identified vulnerabilities.

Get the newsletter.

Pick the topics you actually care about. We'll email when there's news worth your time, on the cadence you choose. Cancel any time from your account.

Cadence

How It Developed

Researchers found vulnerabilities in Zoom's screen sharing feature.
The exploit could allow attackers to take over devices silently.
AI models were used to discover the vulnerabilities with fewer than 20 prompts.
Zoom has begun rolling out fixes for the affected operating systems.
The democratization of hacking capabilities is a growing concern.

Sources

T1
Researchers found a way to hijack devices through Zoom screen sharingvar abtest_2167133 = new ABTest(2167133, 'impression');Ars Technica

Related Stories

DEF CON attendees suspected of spoofing Delta flight Wi-Fi
12 Aug · 12:15 AM
AI adoption leaves accountancy firms vulnerable to cyberattacks
12 Aug · 2:51 PM
Chrome rolls out new defense against account takeovers
11 Aug · 9:06 PM
Researcher Discloses Windows Zero-Day After Microsoft Legal Threat
12 Aug · 3:31 PM
AI firms bulk buy rare books, sparking fears of destructive scanning
12 Aug · 3:26 PM