Researchers Discover Zoom Vulnerabilities Allowing Device Hijacking via Screen Sharing

Published:

spot_img

Researchers have identified serious vulnerabilities in the video conferencing platform Zoom that could allow attackers to hijack devices during screen sharing sessions. According to a report by Ars Technica, these flaws could be exploited without any interaction from the victim, making them particularly dangerous.

The vulnerabilities were discovered by the digital defense firm A Security, which utilized publicly available AI models to identify the issues. The researchers noted that it took fewer than 20 prompts to uncover the vulnerabilities and develop a working attack. Zoom has since issued a security advisory and is rolling out fixes to address the flaws, which affect devices across all operating systems supported by the platform, including Windows, macOS, Linux, iOS, and Android.

Omer Gull, cofounder of A Security, highlighted the alarming trend of democratization in cybersecurity capabilities, stating, “Before it would have taken a team of five people maybe six months with a lot of refining and iteration to find this. Now people can reach the same results with under 20 prompts.” He emphasized that Zoom is a significant target because users generally trust the platform and do not perceive it as a threat.

Vulnerability Details

The vulnerabilities specifically lie within the protocol used for real-time annotation during screen sharing. The researchers indicated that their AI-driven bug hunting systems focused on this component, as complex and obscure functions often harbor overlooked vulnerabilities, especially in proprietary software like Zoom. Despite the company’s extensive code review processes, the lack of public scrutiny can lead to mistakes in such intricate features.

Follow Cyber Warriors Middle East for further global cybersecurity developments.

spot_img

Related articles

Recent articles

Flock Safety Implements Stricter Privacy Controls Following Misuse of License Plate Readers by Law Enforcement

The controversial license plate reader company Flock Safety is implementing new policies to address the misuse of its technology by law enforcement, following significant...

Enterprise Cyber Defenses Show Improvement at Perimeter but Struggle Internally, Reports Blue Report 2026

Enterprise defenses are showing notable improvements at the perimeter, but internal vulnerabilities remain a significant concern, according to the Blue Report 2026 by Picus...

Kaspersky Reports Nearly 400 Million Cyber Attacks Blocked in Q2 2026

In the second quarter of 2026, Kaspersky reported a staggering nearly 400 million cyber attacks blocked across various online resources, highlighting the persistent and...

Q2 2026 Report Reveals 1.99 Million Mobile Malware Attacks Blocked, Banking Trojans Dominate

The latest quarterly report from Kaspersky Security Network reveals a significant decline in mobile malware attacks, with 1.99 million incidents blocked in Q2 2026,...