Security researchers at the firm A Security say they uncovered vulnerabilities in Zoom that could let anyone on a screen-sharing call quietly hijack another participant’s device, with no click and no visible warning. The company shipped fixes this week, but the disclosure lands as a blunt illustration of how cheap automated hacking has become.
The Silent Takeover Hidden in Screen Sharing
The bug lived in the protocol that powers real-time annotation during shared screens. Because joining a call is an act of trust, victims would have had no reason to suspect that simply being on the line exposed their machine. An attacker could ride that trust to grab credentials and pivot deeper into a victim’s organization.
How AI Found the Flaw in Under Twenty Prompts
What makes the finding notable is the speed of discovery. The team says a publicly available AI model needed fewer than twenty prompts to surface the weakness and build a working exploit. A few years ago, the same result might have taken a five-person crew half a year of painstaking reverse engineering.
Annotation Protocol Was the Weak Point
Like human hunters, the AI was pointed at convoluted, obscure functions where mistakes hide. Proprietary annotation code, rarely scrutinized by outside eyes, proved a fertile hunting ground. Established vendors review their components, but closed source leaves exactly these esoteric features least examined.
Patched, But the Warning Remains
Zoom issued both server- and client-side remedies covering Windows, macOS, Linux, iOS, and Android. The researchers stress the real lesson is architectural: a flaw that turns a trusted meeting into a breach point is the kind of risk that scales with how ubiquitous the app has become.
The Democratization of Bug Hunting
The firm’s cofounders frame the episode as a dropping barrier to entry. When a capable attacker needs only a short prompt chain instead of a specialist team, the threat model for every conferencing platform shifts. The cat-and-mouse game of security is now an outright race.
What Users Should Do Right Now
Keep the Zoom client updated, treat unexpected annotation prompts with suspicion, and avoid sharing screens on calls with untrusted participants. Enterprises should assume meeting links are not a safe perimeter.
Outlook: As AI-assisted discovery spreads, expect more “boring” features to reveal serious holes. Vendors that once relied on obscurity now compete with tireless, prompt-driven scanners, and the only durable defense is relentless, public review of the code users never see.
Source: Original report. Rewrite for Your News Website.


