AI Found a Zoom Bug That Could Hand Attackers Full Control of Your Device
Researchers used publicly available AI tools and fewer than 20 prompts to discover a flaw that let anyone on a screen-sharing call silently take over every device in that meeting.

Key points
- Researchers at firm A Security discovered critical vulnerabilities in Zoom in early June 2025 using publicly available AI tools.
- Fewer than 20 AI prompts were needed to find the flaws and build a working attack.
- Any participant on a Zoom screen-sharing call, host or guest, could have had their device taken over without clicking anything.
- Zoom has now issued patches, fixes pushed to both its servers and the apps on users' devices, covering Windows, macOS, Linux, iOS, and Android.
- The researchers warn that AI is dropping the cost and skill needed to find this class of vulnerability to near zero.
A security bug inside Zoom's screen-sharing feature could have let an attacker silently seize full control of any device on a call. No click required. No warning on screen. Just join the meeting and your machine was at risk.
Researchers at digital defence firm A Security disclosed the findings on Tuesday, first reported by Wired. Zoom issued a security advisory the same day and confirmed it has already begun rolling out fixes.
How did the attack work?
The flaw sat inside the protocol, the set of rules two pieces of software follow to talk to each other, that Zoom uses for its real-time annotation feature during screen sharing. That is the tool that lets people draw arrows or highlight parts of a shared screen.
Annotation is obscure, complex code. Security researchers, human and AI alike, know that obscure and complex code is exactly where mistakes hide. A Security's AI-assisted tools zeroed in on that component for precisely that reason.
Anyone on a call where screen sharing was active was exposed. That means attendees of webinars, remote work meetings, and online classes were all potential targets, without doing anything wrong.
What could an attacker actually do?
"If you just get on a Zoom with us, we can take over your device," A Security co-founder Yossi Torati told Wired. The call where he said that, incidentally, was running on Microsoft Teams.
The worst-case picture is stark. An attacker joins a company call, exploits the bug to take control of one employee's computer, steals that employee's login credentials, and then uses those credentials to move through the company's internal systems. One meeting invitation becomes a door into an entire organisation.
Why does the AI angle matter?
This is the part that worries researchers beyond the Zoom bug itself.
"Before it would have taken a team of five people maybe six months," A Security co-founder Omer Gull told Wired. "Now people can reach the same results with under 20 prompts."
Publicly available AI models, the same large language models (technology behind consumer chatbots like ChatGPT) that anyone can access online, did the heavy work. The barrier that once kept this kind of research in the hands of well-funded teams is collapsing fast.
That cuts both ways. Defenders can use the same tools. But so can criminals with far fewer resources than before.
Are Zoom users safe now?
Yes, if your Zoom app is up to date. Zoom patched the flaw on both its own servers and in the applications people install on their devices. The fix covers every operating system Zoom supports: Windows, macOS, Linux, iOS, and Android.
Update your Zoom app now if you have not done so recently. Most devices update automatically, but it takes thirty seconds to check.
What should you watch for?
The attack left no visible trace, so you cannot spot it after the fact by feel. What you can do:
- Keep Zoom and every video-calling app updated at all times.
- Treat unexpected meeting invitations from strangers with the same scepticism you give unexpected emails.
- If your organisation uses Zoom for large events or webinars, confirm with your IT team that the latest client version is deployed across all devices.
- Remember that joining a call is not inherently safe. Screen-sharing features, annotation tools, file transfers: any of these are surfaces that researchers probe for exactly this kind of flaw.



