Researchers have identified serious vulnerabilities in the video conferencing platform Zoom that could allow attackers to hijack devices during screen sharing sessions. According to a report by Ars Technica, these flaws could be exploited without any interaction from the victim, making them particularly dangerous.
The vulnerabilities were discovered by the digital defense firm A Security, which utilized publicly available AI models to identify the issues. The researchers noted that it took fewer than 20 prompts to uncover the vulnerabilities and develop a working attack. Zoom has since issued a security advisory and is rolling out fixes to address the flaws, which affect devices across all operating systems supported by the platform, including Windows, macOS, Linux, iOS, and Android.
Omer Gull, cofounder of A Security, highlighted the alarming trend of democratization in cybersecurity capabilities, stating, “Before it would have taken a team of five people maybe six months with a lot of refining and iteration to find this. Now people can reach the same results with under 20 prompts.” He emphasized that Zoom is a significant target because users generally trust the platform and do not perceive it as a threat.
Vulnerability Details
The vulnerabilities specifically lie within the protocol used for real-time annotation during screen sharing. The researchers indicated that their AI-driven bug hunting systems focused on this component, as complex and obscure functions often harbor overlooked vulnerabilities, especially in proprietary software like Zoom. Despite the company’s extensive code review processes, the lack of public scrutiny can lead to mistakes in such intricate features.
Follow Cyber Warriors Middle East for further global cybersecurity developments.


