Zoom patch issued after AI-assisted exploit reveals critical screen-sharing flaw
A vulnerability in Zoom Workspace allows full device takeover without user interaction, prompting urgent updates across Windows, Mac, iOS, Android, and Linux.

Cybersecurity researchers have identified a critical vulnerability in Zoom’s screen-sharing function that permits attackers to fully control victims’ devices without interaction or visible warning. The flaw affects the Zoom Workspace application across Windows, Mac, iOS, Android, and Linux platforms. Zoom has deployed fixes and urged users to apply the latest updates to mitigate the threat.
The vulnerability exists in all Zoom Workspace versions prior to the latest releases. When a user launches the annotation tool while sharing their screen, the flaw allows bad actors to remotely execute malicious code. This capability enables attackers on the same network to bypass authentication and gain access without valid credentials.
Notably, the exploit was constructed by researchers using artificial intelligence prompts in under 24 hours. This demonstration illustrates how AI is lowering the barrier for developing sophisticated cyberattacks, a trend that has significant implications for the broader security landscape.
A cybersecurity company blog post highlighted the shift in threat capabilities, stating that the model requiring elite teams, months of effort, and weapons-grade budgets has collapsed. The researchers noted that a single individual was able to develop a nation-state-level exploit in less than a day, a capability previously restricted to well-resourced state actors.
Apple has also released corresponding fixes for macOS versions Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9. These updates address similar screen-sharing vulnerabilities, with the newer versions now considered safe.
It remains to be seen if this specific Zoom vulnerability has been exploited in the wild. Zoom was notified of the bug and has since issued patches, advising users to update immediately to ensure their systems are protected against this class of remote code execution.

