Main Logo, small version
CritchCorp Smart(TM)

Sponsored

A Zoom Screen-Sharing Bug Let Anyone Take Over Other Devices on a Call

A Zoom Screen-Sharing Bug Let Anyone Take Over Other Devices on a Call

Security researchers at the firm A Security say they uncovered vulnerabilities in Zoom that could let anyone on a screen-sharing call quietly hijack another participant’s device, with no click and no visible warning. The company shipped fixes this week, but the disclosure lands as a blunt illustration of how cheap automated hacking has become.

The Silent Takeover Hidden in Screen Sharing

The bug lived in the protocol that powers real-time annotation during shared screens. Because joining a call is an act of trust, victims would have had no reason to suspect that simply being on the line exposed their machine. An attacker could ride that trust to grab credentials and pivot deeper into a victim’s organization.

How AI Found the Flaw in Under Twenty Prompts

What makes the finding notable is the speed of discovery. The team says a publicly available AI model needed fewer than twenty prompts to surface the weakness and build a working exploit. A few years ago, the same result might have taken a five-person crew half a year of painstaking reverse engineering.

Annotation Protocol Was the Weak Point

Like human hunters, the AI was pointed at convoluted, obscure functions where mistakes hide. Proprietary annotation code, rarely scrutinized by outside eyes, proved a fertile hunting ground. Established vendors review their components, but closed source leaves exactly these esoteric features least examined.

Patched, But the Warning Remains

Zoom issued both server- and client-side remedies covering Windows, macOS, Linux, iOS, and Android. The researchers stress the real lesson is architectural: a flaw that turns a trusted meeting into a breach point is the kind of risk that scales with how ubiquitous the app has become.

The Democratization of Bug Hunting

The firm’s cofounders frame the episode as a dropping barrier to entry. When a capable attacker needs only a short prompt chain instead of a specialist team, the threat model for every conferencing platform shifts. The cat-and-mouse game of security is now an outright race.

What Users Should Do Right Now

Keep the Zoom client updated, treat unexpected annotation prompts with suspicion, and avoid sharing screens on calls with untrusted participants. Enterprises should assume meeting links are not a safe perimeter.

Outlook: As AI-assisted discovery spreads, expect more “boring” features to reveal serious holes. Vendors that once relied on obscurity now compete with tireless, prompt-driven scanners, and the only durable defense is relentless, public review of the code users never see.

Source: Original report. Rewrite for Your News Website.

Subscribe our newsletter

  • Special Offer Codes
  • Unlimited access to all
  • Priority Support
Thank You, we'll be in touch soon.

Top Categories

Share article

Comments

Add A Comment

We're glad you have chosen to leave a comment. Please keep in mind that all comments are moderated according to our privacy policy, and all links are nofollow. Do NOT use keywords in the name field. Let's have a personal and meaningful conversation.

News Categories
Site Pages
Social
Newsletter

Register now to get latest News stories and special offers to your email.

Thank You, we'll be in touch soon.

© 2025 Copyright Your News Website