Security

AI Finds Zoom Screen-Sharing Flaw in Under 20 Prompts

Researchers used publicly available AI models to discover vulnerabilities that could enable silent device takeover during video calls.

Omega Editorial· August 11, 2026· 3 min read

Security researchers have disclosed critical vulnerabilities in Zoom's screen-sharing feature that could have allowed attackers to silently take control of any participant's device during a video call—flaws discovered using publicly available AI models in a matter of hours rather than months.

Digital defense firm A Security found the bugs in early June and reported them to Zoom, which issued patches and a security advisory on Tuesday. The vulnerabilities affected all operating systems Zoom supports, including Windows, macOS, Linux, iOS, and Android.

How AI accelerated the discovery

What makes this disclosure particularly significant is the speed and ease with which AI-powered tools identified the security flaws. According to A Security cofounder Omer Gull, it took fewer than 20 prompts to uncover the vulnerabilities and create a working exploit—a process that would have previously required a team of five people working for roughly six months.

The AI systems targeted Zoom's real-time annotation protocol, the mechanism that enables users to mark up shared screens during calls. Like experienced human security researchers, the AI had been trained to focus on complex, obscure features where overlooked vulnerabilities often hide, particularly in proprietary closed-source software.

The attack scenario

The vulnerabilities could have been exploited against anyone on a call involving screen sharing, whether host or participant, with no visible indication to the victim. No user interaction was required for the attack to succeed.

"If you just get on a Zoom with us, we can take over your device," A Security cofounder Yossi Torati explained. The implications for enterprise security were especially concerning: an attacker could join a call with an employee, compromise their device and credentials, then move laterally through the corporate network.

Why it matters

The barrier to finding sophisticated software vulnerabilities is dropping rapidly as AI capabilities advance. What once required specialized expertise and significant time investment can now be accomplished by anyone with access to publicly available AI models and basic prompting skills. This democratization of offensive security capabilities means organizations face an expanding threat landscape where attackers can move faster than ever before.

Video conferencing platforms present particularly attractive targets because users inherently trust them and lower their guard when joining calls—especially for routine business meetings or public webinars.

Patches deployed

Zoom has rolled out both server-side and client-side fixes to address the flaws. The company did not respond to requests for comment from WIRED.

The disclosure underscores how AI is transforming the security landscape from a "cat and mouse game" into an all-out race between defenders and attackers, with both sides now leveraging autonomous systems to find and exploit—or patch—vulnerabilities at unprecedented speed.

These details were first reported by WIRED.

#zoom#cybersecurity#artificial intelligence#vulnerability disclosure#video conferencing#ai security

This is an original analysis by the Omega editorial team. Source reporting: WIRED.

Want systems like this working for your business?

Book a Call

More in Security

Security· 2 min read

Security researchers exploit Zoom flaw using AI in under 20 prompts

The vulnerability allowed attackers to hijack devices during meetings through Zoom's annotation feature, requiring no victim interaction.

Via AI Watch · Aug 11, 2026
Security· 3 min read

Anthropic Embeds Watermarks in Claude to Track AI-Generated Text

The AI lab's new feature aims to make ghostwritten content detectable, though heavy editing can still defeat the system.

Via AI Watch · Aug 11, 2026
Security· 2 min read

OpenAI Launches Two-Tier Daybreak Cybersecurity Program

The AI company introduces Blue and Red access levels as defensive response to recent security incidents across the industry.

Via AI Watch · Aug 11, 2026