Researchers found a way to hijack devices through Zoom screen sharing
Ars Technica Lily Hay Newman, wired.com ● Covered by 2 sources
Researchers found a Zoom bug that could let someone take over a device during screen sharing. They said AI helped find it fast, which makes this kind of attack easier to copy.
Based on reporting by Ars Technica, Lily Hay Newman, wired.com — read the original for the full story.
Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error
Researchers have disclosed a Zoom flaw that could have let an attacker take over a target’s device during a screen-sharing call. The nasty part is how little the victim would have had to do: nothing. If the call involved screen sharing, a participant or host could have been hit by a silent attack with no warning and no interaction required.
The bug was found in early June by researchers at the digital defense firm A Security, using publicly available AI models. According to the company, it took fewer than 20 prompts to uncover the vulnerability and build a working attack. That is a short runway for something with device-takeover potential.
Zoom responded on Tuesday with a security advisory and said fixes were already being rolled out. The flaws affected every operating system Zoom supports: Windows, macOS, Linux, iOS, and Android. So this was not a corner-case issue tucked away on one platform.
A Security cofounder Omer Gull framed the bigger problem as the shrinking barrier to entry. He said attacks like this used to demand a small team and months of work; now, he said, the same result can come from a handful of prompts. And Zoom is an attractive target for exactly the reason most people use it without thinking twice: trust.
My take — AI-written commentary, not fact-checked reporting
This is the ugly part of AI security hype that people keep trying to skip over. The tools are getting good enough that “exploit developer” no longer sounds like a specialist job title, which is bad news for anyone who treats trusted apps as harmless by default. Zoom is just the latest reminder that convenience and blind trust make a lovely pair for attackers.
Read more about this at: Ars Technica
Related stories
Microsoft Copilot reveals secret input that allowed it to be hacked
Ars Technica · 2 weeks ago ·
39
New Pass-ta-key attack reveals all the things we didn't know about passkeys
Ars Technica · 3 weeks ago ·
1
Hackers are persuading coding agents to ignore their own safety rules
Axios · 4 weeks ago ·
24