Zoom Zero-Click RCE Flaws Allow Attackers to Compromise Meeting Participants
Researchers used publicly available AI models to find a Zoom screen-sharing flaw that could let attackers take over devices with no victim interaction.
- On Tuesday, researchers from Security disclosed a critical vulnerability in Zoom that allowed attackers to silently take control of a target's device via the screen-sharing annotation tool, requiring no victim interaction.
- They used publicly available AI models to uncover the flaw, needing fewer than 20 prompts to develop a working exploit in less than 24 hours, illustrating how AI lowers the barrier to cyberattacks.
- Security cofounder Yossi Torati told WIRED, "If you just get on a Zoom with us, we can take over your device," warning that attackers could move laterally within an enterprise after compromising a single computer.
- Zoom has since deployed server and client-side patches to mitigate the threat, affecting all platforms prior to versions 7.1.5 and 7.0.6, following similar recent emergency updates issued by Apple.
- Practitioners call security a "cat and mouse game," but Security cofounder Omer Gull warned that the democratization of these capabilities means elite-level hacking is no longer restricted to nation-state actors with massive budgets.
26 Articles
26 Articles
Just 20 prompts and control of the device is lost. AI has found a way to stealthily hijack other people's devices using Zoom. A vulnerability could have allowed hackers to gain control of a video call participant's device during screen sharing, according to RBC-Ukraine, citing Wired. How did the AI find this critical vulnerability? Interestingly, cybersecurity specialists discovered the bug in early June. The system needed fewer than 20 text que…
Zoom Annotation Bug Turned Video Calls Into Silent Device Takeovers
Researchers uncovered a flaw in Zoom that let any participant in a screen-sharing session seize control of others’ devices without a single click or visible sign. The issue lived in the annotation tools that allow drawing and typing on shared screens. A Security, the firm behind the find, reached a working exploit in under a day using fewer than 20 prompts to public AI models. Zoom rolled out fixes across Windows, macOS, Linux, iOS, and Android …
Zoom’s Critical “Zoomsday” Vulnerability Allows Unauthorized Remote Control
Videoconferencing platform Zoom recently published an urgent security advisory to resolve critical vulnerabilities that could allow malicious attackers to gain complete remote control over user devices during active video calls. Discovered by cybersecurity researchers at A Security, the severe flaw was dubbed “Zoomsday,” highlighting major risks associated with real-time collaboration features in modern communication software. The Zoomsday vulne…
Zoom fixed three bugs that let anyone on a call take over your machine
Zoom has patched three memory corruption flaws in its annotation feature that allowed any meeting participant to run code on another attendee’s device with no interaction. The fixes shipped in June and July 2026, roughly two months before the research was made public. Zoom has patched three flaws in the annotation tools used during screen […] This story continues at The Next Web
Researchers found a way to hijack devices through Zoom screen sharing
As AI models gain advanced capabilities to find vulnerabilities in software, develop ways to exploit them, and even carry out autonomous hacking sprees, researchers offered a sobering new example on Tuesday, disclosing vulnerabilities in the video conferencing platform Zoom that could have been exploited to take over targets’ devices. Anyone on a call that involved screen sharing, whether participants or the host, would have been vulnerable to a…
Coverage Details
Bias Distribution
- 57% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium



















