Urgent.News

What's breaking now, across thousands of outlets.

AI

A Zoom Screen-Sharing Bug Let Anyone Take Over Other Devices on a Call

Researchers say it took fewer than 20 prompts for a public AI tool to find a flaw (now fixed) allowing anyone on a Zoom call to hijack another participants’ device.

A Zoom Screen-Sharing Bug Let Anyone Take Over Other Devices on a Call

The digital security firm A Security discovered a security flaw in Zoom's screen-sharing feature during a call in early June. The bug, which allows attackers to take control of any device connected to a Zoom call, can be exploited with less than 20 prompts using publicly available AI models. Zoom supports devices running on Windows, macOS, Linux, iOS, and Android operating systems.

According to A Security co-founder Omer Gull, "The democratization of these capabilities—the barrier to entry is dropping rapidly." The vulnerability lies in the real-time annotation protocol used during screen sharing. The researchers specifically focused on this component because obscure features are more likely to contain vulnerabilities in closed-source software like Zoom.

A Security's AI bug hunting system identified the flaw by analyzing convoluted and obscure functions. The company issued a security advisory detailing the fixes they have already begun implementing to address these flaws. However, the researchers stress that the possibility of exploiting this vulnerability with just a single Zoom call is alarming.

If an attacker successfully compromises a user's device during a Zoom call, they could potentially gain access to the company's credentials and move laterally within the enterprise.

Written by urgent.news from Wired's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

This story

This is one outlet's version. Read the fullest account.

Read the original at wired.com →

More in AI

More from Tuesday 11 August →