According to WIRED, researchers from the digital defense firm A Security disclosed vulnerabilities in Zoom's video conferencing platform that could let anyone on a call involving screen sharing — whether participant or host — silently take over a target's device, with no indication and no interaction from the victim. The flaws affected devices running Windows, macOS, Linux, iOS, and Android, and could allow an attacker to capture credentials and move laterally inside an enterprise network.
AI-Driven Discovery in Under 20 Prompts
According to WIRED, A Security discovered the bug in early June using publicly available AI models. The researchers said it took fewer than 20 prompts to uncover the vulnerabilities and create a working attack. A Security cofounder Omer Gull told WIRED ahead of the disclosure:
What is interesting for us and what we believe is dangerous is the democratization of these capabilities—the barrier to entry is dropping rapidly. Before it would have taken a team of five people maybe six months with a lot of refining and iteration to find this. Now people can reach the same results with under 20 prompts.
— Omer Gull, cofounder, A Security
The vulnerabilities resided specifically in the protocol used to facilitate real-time annotation during screen sharing. WIRED reported that the AI bug hunting systems delved into this component because, like human bug hunters, they were trained that convoluted and obscure functions often contain overlooked vulnerabilities, particularly in proprietary, closed source software. An established company like Zoom presumably does extensive code review, but without public open review, complex features such as annotation are more likely to contain mistakes.
Silent Exploitation and Lateral Movement Risk
The attack vector required nothing more than getting the victim onto a Zoom call. A Security cofounder Yossi Torati told WIRED on a call — which was, incidentally, hosted on Microsoft Teams:
If you just get on a Zoom with us, we can take over your device. The worst case scenario is that we can take over an enterprise just by having this vulnerability in our hands. If I'm an attacker I can be on a call with someone from a company, take control of their computer and their credentials, and then use them to move laterally in the enterprise.
— Yossi Torati, cofounder, A Security
WIRED noted that joining a call is in itself a gesture of trust, but given how ubiquitous video calling is in both personal and professional contexts — and that Zoom is widely used for events and semi-public activities like webinars — people typically have their guard down when joining a Zoom.
| Category | Details |
|---|---|
| Discovery period | Early June |
| AI prompts to exploit | Fewer than 20 |
| Affected platforms | Windows, macOS, Linux, iOS, Android |
| Attack vector | Screen-sharing real-time annotation protocol |
| Patch scope | Server-side and client-side fixes |
| Disclosure | Tuesday, via Zoom security advisory |
Zoom's Response: Server and Client Patches Issued
According to WIRED, Zoom issued a security advisory on Tuesday, including details about fixes the company has already begun rolling out to address the flaws. The bugs are now patched, with Zoom issuing both server and client-side fixes — or patches for both Zoom's own servers and the applications that run on customer devices. Zoom did not respond to multiple requests for comment from WIRED about the A Security findings.
The Acceleration of the Security Race
Practitioners often call security a "cat and mouse game," but as AI bug hunting proliferates, this delicate dance has become an all-out race, WIRED reported. The Zoom disclosure offers a concrete example of how AI models can find exploitable flaws in trusted enterprise collaboration tools with minimal effort — a dynamic that enterprise security and procurement teams must account for when selecting and maintaining video conferencing and remote work platforms.