iGEN
Visit IGEN World Explore IGEN Expo
EXPLORE UPGRADE PLANS
BREAKING
Home ›› Technology ›› Ai ›› Computer Vision ›› A Zoom Screen-Sharing Bug Let Anyone Take Over Other Devices on a Call

A Zoom Screen-Sharing Bug Let Anyone Take Over Other Devices on a Call

Researchers at A Security uncovered Zoom screen-sharing vulnerabilities using publicly available AI models, enabling silent device takeover on any supported platform. Fewer than 20 prompts were needed to create a working attack. Zoom has issued server and client patches, but the disclosure highlights the democratization of AI-driven hacking.

iG
iGEN Editorial
August 11, 2026
A Zoom Screen-Sharing Bug Let Anyone Take Over Other Devices on a Call

According to WIRED, researchers from the digital defense firm A Security disclosed vulnerabilities in Zoom's video conferencing platform that could let anyone on a call involving screen sharing — whether participant or host — silently take over a target's device, with no indication and no interaction from the victim. The flaws affected devices running Windows, macOS, Linux, iOS, and Android, and could allow an attacker to capture credentials and move laterally inside an enterprise network.

AI-Driven Discovery in Under 20 Prompts

According to WIRED, A Security discovered the bug in early June using publicly available AI models. The researchers said it took fewer than 20 prompts to uncover the vulnerabilities and create a working attack. A Security cofounder Omer Gull told WIRED ahead of the disclosure:

What is interesting for us and what we believe is dangerous is the democratization of these capabilities—the barrier to entry is dropping rapidly. Before it would have taken a team of five people maybe six months with a lot of refining and iteration to find this. Now people can reach the same results with under 20 prompts.

— Omer Gull, cofounder, A Security

The vulnerabilities resided specifically in the protocol used to facilitate real-time annotation during screen sharing. WIRED reported that the AI bug hunting systems delved into this component because, like human bug hunters, they were trained that convoluted and obscure functions often contain overlooked vulnerabilities, particularly in proprietary, closed source software. An established company like Zoom presumably does extensive code review, but without public open review, complex features such as annotation are more likely to contain mistakes.

Silent Exploitation and Lateral Movement Risk

The attack vector required nothing more than getting the victim onto a Zoom call. A Security cofounder Yossi Torati told WIRED on a call — which was, incidentally, hosted on Microsoft Teams:

If you just get on a Zoom with us, we can take over your device. The worst case scenario is that we can take over an enterprise just by having this vulnerability in our hands. If I'm an attacker I can be on a call with someone from a company, take control of their computer and their credentials, and then use them to move laterally in the enterprise.

— Yossi Torati, cofounder, A Security

WIRED noted that joining a call is in itself a gesture of trust, but given how ubiquitous video calling is in both personal and professional contexts — and that Zoom is widely used for events and semi-public activities like webinars — people typically have their guard down when joining a Zoom.

Category Details
Discovery period Early June
AI prompts to exploit Fewer than 20
Affected platforms Windows, macOS, Linux, iOS, Android
Attack vector Screen-sharing real-time annotation protocol
Patch scope Server-side and client-side fixes
Disclosure Tuesday, via Zoom security advisory

Zoom's Response: Server and Client Patches Issued

According to WIRED, Zoom issued a security advisory on Tuesday, including details about fixes the company has already begun rolling out to address the flaws. The bugs are now patched, with Zoom issuing both server and client-side fixes — or patches for both Zoom's own servers and the applications that run on customer devices. Zoom did not respond to multiple requests for comment from WIRED about the A Security findings.

The Acceleration of the Security Race

Practitioners often call security a "cat and mouse game," but as AI bug hunting proliferates, this delicate dance has become an all-out race, WIRED reported. The Zoom disclosure offers a concrete example of how AI models can find exploitable flaws in trusted enterprise collaboration tools with minimal effort — a dynamic that enterprise security and procurement teams must account for when selecting and maintaining video conferencing and remote work platforms.


Sources: WIRED – Security

Keep Reading

Recommended Stories

Apple's Hide My Email Vulnerability Exposes User Addresses for Over a Year Technology

Apple's Hide My Email Vulnerability Exposes User Addresses for Over a Year

A vulnerability in Apple's Hide My Email service has been leaking users' real email addresses for at least a year, according to security researcher Tyler Murphy. In tests, all Hide My Email addresses were exploitable. Apple has acknowledged the issue but it remains unpatched. This story is part of a broader security roundup covering Pegasus spyware, Google's EU warnings, Meta chatbot testing, and the arrest of a Scattered Spider hacker.

July 4, 2026
Oracle Warns of Critical PeopleSoft Vulnerability Exploited by ShinyHunters, Affecting Hundreds of Organizations Technology

Oracle Warns of Critical PeopleSoft Vulnerability Exploited by ShinyHunters, Affecting Hundreds of Organizations

Oracle has issued a security advisory for a critical remote code execution vulnerability (CVE-2026-35273, CVSS 9.8) in PeopleSoft versions 8.61 and 8.62. The extortion group ShinyHunters is exploiting it, claiming to have breached over 100 organizations and exfiltrated data from ~300 instances. Google's Mandiant reported zero-day exploitation between May 27 and June 9, 2026, and alerted over 100 potentially vulnerable entities.

June 15, 2026
Reverse-Lookup Service Exposed Millions of Photos of People's Faces Technology

Reverse-Lookup Service Exposed Millions of Photos of People's Faces

Independent security researcher Jeremiah Fowler found that the people-search service ClarityCheck left more than 9 million image files, including photos of faces, publicly accessible in an unsecured Amazon S3 bucket. A second misconfiguration exposed email addresses and phone numbers. The company secured the data after WIRED reached out but disputed that the data was publicly exposed.

August 19, 2026
OpenAI's Browser Could Be Hijacked to Spam Your WhatsApp Contacts Technology

OpenAI's Browser Could Be Hijacked to Spam Your WhatsApp Contacts

Security researchers at Zenity demonstrated that OpenAI's Atlas browser can be tricked into spamming WhatsApp contacts and manipulating Amazon shopping sessions. The findings, presented at Black Hat, are part of a broader discovery of about 20 flaws in AI-enabled browsers from major tech companies.

August 5, 2026