Zoom Screen-Sharing Vulnerability Could Let Attackers Take Over Devices
Zoom Video Communications Inc.
Researchers from A Security disclosed vulnerabilities in Zoom's screen-sharing feature that could allow silent device takeover. The bugs were found using public AI models in under 20 prompts, prompting Zoom to release patches. The discovery highlights the democratization of AI-powered hacking capabilities.
Researchers at the digital defense firm A Security discovered vulnerabilities in Zoom's real-time annotation protocol during screen sharing, which could be exploited to silently take over a target's device without interaction. The bugs were found in early June using publicly available AI models, requiring fewer than 20 prompts to identify and craft a working exploit. Zoom issued a security advisory and rolled out fixes for both server and client sides, affecting all supported operating systems. The researchers emphasize the ease of exploitation, as joining a Zoom call is an act of trust, and the vulnerabilities could enable lateral movement within enterprises.
Source: Wired AI —
original
