← All stories
● Covered by 6 sources · 6 reportsMedium impact3 negative3 neutral

Zoom Patches Critical Vulnerability Allowing Device Takeover During Screen Sharing

🔄 Updated 1d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Vulnerability allowed remote code execution and device takeover.
  • Affected Windows, macOS, Linux, iOS, and Android devices.
  • Exploit required no victim interaction or visual cues.
  • Discovered by A Security using fewer than 20 AI prompts.
  • Zoom released patches in June and July; no exploitation reported.

Critical Zoom Vulnerability Discovered and Patched

Zoom has addressed a critical security vulnerability that could have allowed an attacker to remotely take over a participant's device during a screen-sharing session. The flaw, which affected all supported operating systems including Windows, macOS, Linux, iOS, and Android, enabled remote code execution without any interaction or visual indication from the victim.

Cybersecurity firm A Security discovered the vulnerability in early June and reported it to Zoom. Zoom subsequently released patches for the affected clients in June and July, prior to the public disclosure of the flaw. As of publication, there have been no reports of this vulnerability being exploited in the wild.

Exploiting the Annotation Feature

The vulnerability was found within Zoom's annotation feature, which allows users to draw and type on a shared screen. While the annotation tool was the exploitable area, participants did not need to actively use it for the exploit to work, as the underlying code was always active. An attacker could join or host a meeting and run malicious code on victims' devices, potentially stealing data, activating cameras or microphones, or installing malware.

AI Accelerates Exploit Development

A Security researchers utilized publicly available AI models to discover the vulnerability and create a working exploit. They reported that it took fewer than 20 prompts to uncover the flaws and develop the attack, demonstrating a significant reduction in the time and resources typically required for such complex exploit development. This capability was previously considered nation-state level work, requiring elite teams and months of effort.

The ease with which AI tools facilitated the discovery and exploitation of this bug highlights a new challenge in cybersecurity, as advanced attack capabilities become more accessible.

Affected Versions and Remediation

The remote code execution vulnerabilities were present in Zoom Workplace versions before 7.1.5 and 7.0.6. Specific patches were also released for Zoom Workplace VDI Client for Windows (before 7.0.11 and 6.6.16) and Zoom Rooms and Zoom Meeting SDK (before 7.1.0, and before 7.1.5 for a third related flaw). Users who have updated their Zoom Workplace client to the current versions are protected against this vulnerability.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~7 min · 6 stories · Aug 15

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

Security researchers at A.Security discovered a critical vulnerability, dubbed 'Zoomsday,' in Zoom Workplace that allowed any meeting participant to gain full control over another participant's device. This exploit, reportedly developed with only 20 AI prompts, highlights the increasing ease of creating sophisticated exploits, even for proprietary software.

Researchers from A Security discovered vulnerabilities in Zoom's screen sharing protocol that could have allowed attackers to silently take over devices during calls. Zoom has released fixes for these flaws, which affected all supported operating systems. The discovery highlights the increasing capability of AI models to find and exploit software vulnerabilities.

Security researchers discovered critical vulnerabilities in Zoom's annotation tool that could have allowed any meeting participant to remotely hijack another attendee's client without interaction. Zoom released patches for these flaws in June and July, prior to public disclosure, and no exploitation has been reported.

Cybersecurity researchers discovered a critical vulnerability in Zoom's screen-sharing function that allowed remote code execution and device takeover without user interaction. Zoom has released updates for its Workspace app across all platforms to mitigate this threat. The discovery highlights how AI tools can accelerate exploit development, making advanced attack capabilities more accessible.

Zoom has patched a critical security vulnerability that allowed attackers to hijack devices during meetings across Windows, macOS, Linux, Android, and iOS. Researchers at A Security uncovered the flaw using fewer than 20 AI prompts, demonstrating a new method for discovering complex exploits.

A critical vulnerability in Zoom, discovered with the help of AI tools, allowed attackers to remotely execute code on participants' devices during screen-sharing sessions. This flaw affected all supported operating systems and has since been patched by Zoom. The ease with which AI found this bug highlights a new challenge in cybersecurity.