A set of now-patched Zoom vulnerabilities shows how quickly public AI tools can turn an obscure software feature into a working attack. Researchers at the digital defense company A Security say they needed fewer than 20 prompts to identify flaws in Zoom’s screen-sharing system and develop a technique capable of silently taking over another participant’s device.
The finding does not establish that any attacker exploited the bugs in the wild. It does demonstrate a worrying reduction in the effort needed to investigate proprietary software, connect several weaknesses and produce a practical attack. In a video call, where participation itself signals trust, that lower barrier changes the risk calculation.
An overlooked annotation protocol became the attack path
The vulnerabilities were located in the protocol that supports real-time annotation during screen sharing. A Security’s systems focused on that component because complicated, less visible functions often receive less attention than a product’s primary features. In closed-source software, outside researchers also have fewer opportunities to inspect such code before release.
According to the researchers, anyone on an affected call could have been vulnerable when screen sharing was involved, regardless of whether that person was the host or a participant. The attack required no interaction from the target and offered no obvious indication that control had been lost.
The flaws affected every operating system supported by Zoom: Windows, macOS, Linux, iOS and Android. A Security says it discovered them in early June with publicly available AI models. Zoom issued a security advisory when the work was disclosed and had already begun rolling out fixes on both its servers and client applications.
Those facts make updating important. A server-side correction can close part of an attack path, but client-side fixes still depend on users and organizations running a patched application. Zoom did not respond to WIRED’s requests for comment about the researchers’ findings.
Fewer prompts do not mean a fully autonomous attack
A Security’s central claim is that AI compressed work that might previously have required a team and months of iteration. Cofounder Omer Gull described the shift as a democratization of advanced bug-hunting capability. That assessment comes from the company that performed the research and cannot establish how every human researcher or AI system would handle the same target.
The reported prompt count also needs context. “Fewer than 20” does not mean the models independently chose Zoom, gained access and attacked users. Researchers directed the investigation, recognized promising output and assembled the result into a working exploit. Human expertise remained part of the process even as AI reduced the amount of manual exploration.
Still, the example is more concrete than a benchmark showing that a model can solve artificial security puzzles. The researchers examined a widely deployed commercial product and found a chain that could cross from an ordinary call into device control. Public availability matters because capable analysis is no longer restricted to specialized internal tools.
The same accessibility can help defenders. Vendors and independent researchers can use AI to search neglected components earlier. The difficult policy question is whether defensive review and patch deployment can keep pace as more people gain tools capable of finding the same mistakes.
Video calls create an unusually trusting attack surface
The potential consequences extended beyond one compromised device. A Security cofounder Yossi Torati said an attacker could have taken control of a company computer, captured credentials and moved laterally through an enterprise. That is a worst-case scenario described by the researchers, not a documented incident.
Zoom’s ubiquity nevertheless makes the scenario credible enough to take seriously. Employees routinely join meetings with customers and unfamiliar participants. Webinars and semipublic events can place many devices in the same session, while screen sharing and annotation appear to be normal collaboration rather than security-sensitive actions.
The episode therefore exposes two timelines. AI may shorten vulnerability discovery and exploit development to a conversation measured in prompts. Organizations must still distribute software updates, verify client versions and decide when an urgent patch justifies disrupting work.
Now that fixes are available, the immediate response is straightforward: apply current Zoom updates across every supported platform. The broader challenge is harder. Security teams need to treat secondary collaboration features as real attack surfaces and assume that obscurity will provide less protection as AI-assisted analysis becomes cheaper and more widely available.
Post Views: 113
Topics
Stay Ahead of AI
Get the AI developments that matter, delivered to your inbox.