AI bug hunters find Zoom flaw letting anyone hijack devices on a call

Researchers from the digital defense firm A Security disclosed vulnerabilities in Zoom's video conferencing platform that could have let an attacker silently take over the device of anyone on a call involving screen sharing, whether that person was a participant or the host, with no interaction from the victim and no indication anything was wrong. The bugs sat in the protocol Zoom uses for real-time annotation during screen sharing, and they affected devices running every operating system Zoom supports: Windows, macOS, Linux, iOS, and Android.
A Security says it discovered the bug in early June using publicly available AI models, and that it took fewer than 20 prompts to uncover the vulnerabilities and build a working attack. Cofounder Omer Gull told WIRED ahead of the disclosure that the same result would previously have taken a team of five people about six months of refining and iteration. He called the shift "the democratization of these capabilities," saying the barrier to entry for this kind of bug hunting is dropping rapidly, and noted that Zoom is a particularly attractive target because people trust it and do not see it as a threat.
The researchers say their AI systems zeroed in on the annotation feature because, like human bug hunters, they have learned that convoluted, obscure functions tend to hide overlooked vulnerabilities, especially in proprietary, closed-source software that never gets public review. Cofounder Yossi Torati put the risk starkly: getting someone onto a Zoom call would have been enough to take over their device, and from there an attacker could seize a person's computer and credentials and use them to move laterally through an entire enterprise.
Zoom issued a security advisory on Tuesday alongside details of fixes it had already begun rolling out, and the company has since shipped both server-side and client-side patches. Zoom did not respond to WIRED's multiple requests for comment on A Security's findings.
Key facts
- A Security found the Zoom vulnerability in early June using publicly available AI models, taking fewer than 20 prompts to uncover it and build a working attack.
- The flaw was in Zoom's real-time screen-sharing annotation protocol and could silently hand an attacker control of any participant's or host's device, no interaction needed.
- It affected every operating system Zoom supports: Windows, macOS, Linux, iOS, and Android.
- Cofounder Omer Gull says the same discovery would previously have taken a team of five people about six months.
- Zoom issued a security advisory on Tuesday and has already shipped server- and client-side patches; the company did not respond to WIRED's requests for comment.
Why it matters
The case is less about Zoom specifically than about what AI bug hunting now costs. A Security says a vulnerability that once needed a five-person team working for roughly six months was found and turned into a working exploit with fewer than 20 prompts to publicly available AI models. That collapse in effort, cofounder Omer Gull argues, is the real story: the barrier to entry for finding serious software flaws is dropping fast, for defenders and attackers alike.
Who it affects
Anyone using Zoom for screen sharing was exposed, both call participants and hosts, on any of the operating systems Zoom supports: Windows, macOS, Linux, iOS, and Android. Because joining a Zoom call is treated as a low-risk, routine action in both personal and professional settings, the researchers single out enterprise users as especially at risk: an attacker able to take over one person's device during a call could use their credentials to move laterally across an organization.
How to use it
There is nothing for users to configure. Zoom issued a security advisory on Tuesday describing the fixes and has already rolled out both server-side patches and client-side patches to the applications running on customer devices, so an up-to-date Zoom client and account already carry the fix.
How solid is it
The account comes directly from A Security's two cofounders, Omer Gull and Yossi Torati, speaking to WIRED, and is corroborated by Zoom's own security advisory and the fixes it has shipped. WIRED notes Zoom did not respond to its multiple requests for comment on A Security's specific findings, so Zoom's side of the story beyond the advisory itself is not represented.
Risks and caveats
The article does not give a CVE identifier, a severity score, a calendar date for discovery or disclosure beyond "early June" and "Tuesday," a count of how many distinct bugs were involved, or any figure for how many users or organizations were exposed. There is also no indication the flaw was ever exploited in the wild before A Security found and reported it; this was researcher disclosure, not an observed attack.
“If you just get on a Zoom with us, we can take over your device.”
— Yossi Torati, A Security cofounder