AI Found a Zoom Bug That Could Hand Attackers Full Control of Your Device

Researchers used publicly available AI tools and fewer than 20 prompts to discover a flaw that let anyone on a screen-sharing call silently take over every device in that meeting.

AI2Day NewsdeskUpdated Editor: Lee Brown4 min read
Full-frame overhead photoreal shot of a cluttered security researcher's desk at night, glowing monitor showing abstract code and highlighted lines, a paper note
Share

Key points

  • Researchers at firm A Security discovered critical vulnerabilities in Zoom in early June 2025 using publicly available AI tools.
  • Fewer than 20 AI prompts were needed to find the flaws and build a working attack.
  • Any participant on a Zoom screen-sharing call, host or guest included, could have had their device taken over without clicking anything.
  • Zoom has now issued patches covering Windows, macOS, Linux and Android, as well as iOS, pushed to both its own servers and the apps on users' devices.
  • The researchers warn that AI is dropping the cost and skill needed to find this class of vulnerability to near zero.

A security bug inside Zoom's screen-sharing feature could have let an attacker silently seize full control of any device on a call. No click required, no warning on screen. Just join the meeting and your machine was at risk.

Researchers at digital defence firm A Security disclosed the findings on Tuesday, first reported by Wired. Zoom issued a security advisory the same day and confirmed it has already begun rolling out fixes.

How did the attack work?

The flaw sat inside the protocol, the set of rules two pieces of software follow to talk to each other, that Zoom uses for its real-time annotation feature during screen sharing. That's the tool that lets people draw arrows or highlight parts of a shared screen.

Annotation is obscure, complex code, and obscure complex code is exactly where mistakes hide. A Security's AI-assisted tools zeroed in on that component for precisely that reason. Anyone on a call where screen sharing was active was exposed, whether they were running a webinar, a staff meeting or an online class, without doing anything wrong.

What could an attacker actually do?

"If you just get on a Zoom with us, we can take over your device," A Security co-founder Yossi Torati told Wired. The call where he said that was, incidentally, running on Microsoft Teams.

The worst case is stark. An attacker joins a company call, exploits the bug to take control of one employee's computer, steals that employee's login credentials, and then uses those credentials to move through the company's internal systems. One meeting invitation becomes a door into an entire organisation.

Why does the AI angle matter?

This is the part that worries researchers beyond the Zoom bug itself.

"Before it would have taken a team of five people maybe six months," A Security co-founder Omer Gull told Wired. "Now people can reach the same results with under 20 prompts."

Publicly available AI models, the large language models behind consumer chatbots like ChatGPT, did the heavy work. The barrier that once kept this kind of research in the hands of well-funded teams is collapsing fast. That cuts both ways: defenders can use the same tools, but so can criminals with far fewer resources than before. Our 5 August story "AI Found a New Class of Web Vulnerability. A Human Had to Explain Why It Mattered." showed the same dynamic playing out in web security research.

Are Zoom users safe now?

Yes, if your Zoom app is up to date. Zoom patched the flaw on both its own servers and in the applications people install on their devices, covering every operating system the platform supports.

Update your Zoom app now if you haven't done so recently. Most devices update automatically, but it takes thirty seconds to check.

What should you watch for?

The attack left no visible trace, so you can't spot it after the fact by feel. What you can do:

  • Keep Zoom and every video-calling app updated at all times.
  • Treat unexpected meeting invitations from strangers with the same scepticism you give unexpected emails.
  • If your organisation uses Zoom for large events or webinars, confirm with your IT team that the latest client version is deployed across all devices.
  • Remember that joining a call isn't inherently safe: screen-sharing features, annotation tools and file transfers are all surfaces that researchers probe for exactly this kind of flaw.

The real story here isn't the Zoom bug, which is now fixed. It's that the expertise needed to find and exploit that bug fits inside a twenty-prompt session. That's the number to remember.

© 2026 AI2Day