AI Finds Zoom Screen-Sharing Flaw in Under 20 Prompts
Researchers used publicly available AI models to discover vulnerabilities that could enable silent device takeover during video calls.
Security researchers have disclosed critical vulnerabilities in Zoom's screen-sharing feature that could have allowed attackers to silently take control of any participant's device during a video call—flaws discovered using publicly available AI models in a matter of hours rather than months.
Digital defense firm A Security found the bugs in early June and reported them to Zoom, which issued patches and a security advisory on Tuesday. The vulnerabilities affected all operating systems Zoom supports, including Windows, macOS, Linux, iOS, and Android.
How AI accelerated the discovery
What makes this disclosure particularly significant is the speed and ease with which AI-powered tools identified the security flaws. According to A Security cofounder Omer Gull, it took fewer than 20 prompts to uncover the vulnerabilities and create a working exploit—a process that would have previously required a team of five people working for roughly six months.
The AI systems targeted Zoom's real-time annotation protocol, the mechanism that enables users to mark up shared screens during calls. Like experienced human security researchers, the AI had been trained to focus on complex, obscure features where overlooked vulnerabilities often hide, particularly in proprietary closed-source software.
The attack scenario
The vulnerabilities could have been exploited against anyone on a call involving screen sharing, whether host or participant, with no visible indication to the victim. No user interaction was required for the attack to succeed.
"If you just get on a Zoom with us, we can take over your device," A Security cofounder Yossi Torati explained. The implications for enterprise security were especially concerning: an attacker could join a call with an employee, compromise their device and credentials, then move laterally through the corporate network.
Why it matters
The barrier to finding sophisticated software vulnerabilities is dropping rapidly as AI capabilities advance. What once required specialized expertise and significant time investment can now be accomplished by anyone with access to publicly available AI models and basic prompting skills. This democratization of offensive security capabilities means organizations face an expanding threat landscape where attackers can move faster than ever before.
Video conferencing platforms present particularly attractive targets because users inherently trust them and lower their guard when joining calls—especially for routine business meetings or public webinars.
Patches deployed
Zoom has rolled out both server-side and client-side fixes to address the flaws. The company did not respond to requests for comment from WIRED.
The disclosure underscores how AI is transforming the security landscape from a "cat and mouse game" into an all-out race between defenders and attackers, with both sides now leveraging autonomous systems to find and exploit—or patch—vulnerabilities at unprecedented speed.
These details were first reported by WIRED.
This is an original analysis by the Omega editorial team. Source reporting: WIRED.
Want systems like this working for your business?
Book a Call
