Zoom Screen-Sharing Bug Could Have Let Anyone on a Call Take Over Other Devices

A now-patched vulnerability in Zoom’s screen-sharing feature could have allowed anyone on a call to silently take over another participant’s device, with no interaction required from the victim. Zoom issued a security advisory on August 11, 2026, confirming it has begun rolling out fixes for the flaws, which affected all operating systems Zoom supports — Windows, macOS, Linux, iOS, and Android.

Researchers at digital defense firm A Security discovered the bugs in early June using publicly available AI models. According to the firm, it took fewer than 20 prompts to uncover the vulnerabilities and develop a working exploit. The flaws were located in the protocol handling real-time annotation during screen sharing — a complex, proprietary feature that the researchers say AI tools, like human bug hunters, are trained to target because obscure functions in closed-source software are more likely to contain overlooked mistakes.

“Before it would have taken a team of five people maybe six months with a lot of refining and iteration to find this,” A Security cofounder Omer Gull told WIRED. “Now people can reach the same results with under 20 prompts.”

The attack could have been carried out silently, with no indication to the victim, by any participant or host on a call that involved screen sharing. Zoom has issued both server-side and client-side patches to address the flaws. The company did not respond to WIRED’s requests for comment.

A Security cofounder Yossi Torati described a worst-case scenario in which an attacker joins a Zoom call with a company employee, takes control of their computer and credentials, and uses that access to move through an enterprise network. The researchers warn that Zoom’s widespread use in professional and semi-public settings — including webinars — means users typically have their guard down when joining a call, making it a high-value target. Zoom has not yet commented publicly on the findings.

Source: WIRED

This article was generated by AI and cites original sources.
Scroll to Top