A Security researchers uncover Zoom vulnerability exploitable via AI
Publicly available AI models identified the security gap in fewer than 20 prompts, prompting Zoom to release urgent patches across all supported operating systems.

Researchers from digital defence firm A Security have disclosed a critical vulnerability in Zoom’s real-time annotation protocol, enabling attackers to hijack devices during screen-sharing sessions without victim interaction. The flaw, identified in early June, allows participants to silently take control of a target’s device simply by joining a call that involves screen sharing.
The vulnerability was discovered using publicly available artificial intelligence models, with A Security cofounder Omer Gull noting that fewer than 20 prompts were required to uncover the bug and create a working exploit. This efficiency underscores a rapid shift in cybersecurity, where tasks that previously required a team of five people six months of refinement can now be achieved quickly with AI assistance.
Zoom has issued both server and client-side patches to address the security gap. The updates are available for all supported operating systems, including Windows, macOS, Linux, iOS, and Android. The company released a security advisory detailing the fixes, which target the complex and often overlooked functions within proprietary software that lack public open review.
A Security cofounder Yossi Torati demonstrated the severity of the exploit on a call hosted on Microsoft Teams, stating that joining a Zoom call with the researchers allowed for immediate device takeover. Torati warned that the worst-case scenario involves attackers using compromised credentials to move laterally within an enterprise network, highlighting the risks associated with the trust users place in video conferencing platforms.
The disclosure coincides with a broader industry trend where major AI platforms, such as Google’s Gemini and OpenAI’s ChatGPT, have surpassed one billion monthly active users. This widespread accessibility of AI tools is lowering barriers for cyber exploits, transforming security from a traditional cat-and-mouse game into an all-out race. Zoom did not respond to multiple requests for comment regarding the findings.

