Tech

AI tools uncover critical Zoom vulnerability allowing silent device takeover

Zoom has issued patches for a security flaw that permitted participants to hijack devices without victim interaction, highlighting the rapid lowering of barriers for AI-driven cyber exploits.

Editorial persona
Owen Mercer
Markets and Finance Editor
Published
Draft
Source: WIRED · View original source
A Zoom Screen-Sharing Bug Let Anyone Take Over Other Devices on a Call
Digital defence firm A Security finds flaw in screen-sharing protocol using public models

Zoom has released server and client-side patches for a critical security vulnerability in its screen-sharing protocol, a flaw that allowed any call participant to silently hijack another user’s device. The discovery, made in early June by researchers at the digital defence firm A Security, underscores the growing capability of public artificial intelligence models to identify complex software exploits with minimal human intervention.

The vulnerability affected all operating systems supported by the platform, including Windows, macOS, Linux, iOS, and Android. Crucially, the exploit could be executed without any interaction or indication from the victim, turning a standard screen-sharing session into a potential entry point for device takeover. The flaw specifically resided in the protocol governing real-time annotation during screen shares, a proprietary feature that researchers noted is often less scrutinised than open-source components.

A Security cofounders Omer Gull and Yossi Torati disclosed that the bug was identified using publicly available AI models. According to the researchers, it required fewer than 20 prompts to uncover the vulnerability and construct a working attack vector. This efficiency marks a significant shift in the cybersecurity landscape, where tasks that previously demanded extensive manual effort can now be automated.

Gull described this trend as the "democratisation" of hacking capabilities, noting that the barrier to entry is dropping rapidly. He contrasted the current ease of discovery with traditional methods, stating that finding such a flaw might have previously required a team of five people working for six months. He also highlighted that Zoom is a particularly attractive target because users associate the platform with trust, often lowering their guard during calls.

The researchers emphasised the potential severity of the exploit, noting that joining a call is inherently an act of trust. Torati demonstrated the capability by stating that simply getting a target onto a call could allow attackers to take control of their device and credentials, potentially enabling lateral movement within an enterprise network. While Zoom did not respond to requests for comment regarding the findings, the company has since deployed fixes to address the security advisory.

As AI bug hunting proliferates, the traditional "cat and mouse" dynamic of cybersecurity is evolving into a more intense race. The incident serves as a stark reminder that complex, closed-source features remain vulnerable to automated discovery, challenging organisations to adapt their security protocols to an environment where sophisticated exploits can be generated with minimal input.

Continue reading

More from Tech

Read next: XMPP Essay Says Visibility, Not Features, Is the Key to Growth
Read next: The world’s biggest IMAX theatre depends on how it is measured
Read next: USB-C has more audio potential, but the DAC matters more than the port