HR EN DE
NEWS SPORT BIZNIS SCENA LIFESTYLE TECH

AI Breaks Zoom in 24 Hours

Earlier beliefs that such attacks could only be carried out by state actors have now been shattered, researchers, using artificial intelligence, discovered in less than a day a vulnerability that allows complete takeover of someone else's computer during a Zoom call.

Foto: Wikipedia (Apple Inc.)
Summary
  • A Security researchers discovered a vulnerability in Zoom that allows complete takeover of another person's device without any interaction from the victim.
  • It took them less than 24 hours and just 20 queries to AI models to develop this state-level attack.
  • Zoom has already issued patches for all platforms, and Apple patched a similar critical vulnerability in macOS in the same week.
  • Experts warn that AI dramatically accelerates and cheapens sophisticated cyber attacks, ushering in a new era of security threats.

Imagine you're on a regular Zoom meeting. Someone shares their screen, you do nothing, you click no suspicious links, and your computer is quietly taken over in the background. This is exactly the kind of terrifying vulnerability that researchers at A Security have uncovered, and what's alarming is how little time and resources it took them, less than 24 hours and about twenty queries to publicly available AI models.

The vulnerability lies in the annotation protocol during screen sharing in the Zoom Workspace app. The problem is that the attack requires no interaction from the victim and displays no visible warning. It's enough for the attacker to be on the same call and run malicious code, and the target remains completely unaware that they've been compromised.

From Elite Teams to a Solo Researcher

Omer Gull, co-founder of A Security, described to Wired how dramatic the lowering of the barrier for such attacks is. "Previously, it would take a team of five people maybe six months with a lot of refinement and iteration to find this. Now people can achieve the same results with fewer than 20 queries," Gull said, adding that Zoom is a particularly important target because users have an innate trust in it and don't perceive it as a threat.

This claim is also supported by a statement from the company itself, as reported by Engadget. "This class of capability would previously have been available only to state actors, but the model that required elite teams, months of effort, and weapons-grade budgets has collapsed. Today, a single researcher managed to develop a state-level exploit in less than a day."

From an Individual to an Entire Company

Although the vulnerability has now been patched, A Security demonstrated its potentially catastrophic reach. Yossi Torati, another co-founder, explained to Wired the chain reaction that could follow. "If you just join a Zoom call with us, we can take over your device. The worst-case scenario is that we can take over a company just by having this vulnerability in hand. If I'm an attacker, I can be on a call with someone from the company, take control of their computer and credentials, and then use them for lateral movement within the enterprise."

The vulnerability was discovered in early June, and Zoom issued a security advisory on Tuesday and began rolling out fixes at the server and client application levels. The issue existed on all platforms Zoom supports: Windows, macOS, Linux, iOS, and Android. Zoom did not respond to multiple inquiries from Wired for comment on A Security's findings, but the company stated that "users can help maintain security by applying the latest updates."

Apple Patches Its Own Flaw in the Same Week

Interestingly, in almost the same period, Apple also faced a similar critical flaw. A vulnerability in screen sharing on macOS allowed attackers on the same network to bypass authentication and gain access without valid credentials. Apple released emergency security patches on Monday, August 10, in macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9 updates.

Although there is no confirmation that any attackers have exploited these vulnerabilities in the real world, researchers emphasize that the speed and ease with which they were discovered using artificial intelligence is a serious warning for the future of cybersecurity. The race between attackers and defenders has just gained a whole new acceleration.

FAQ
How does this Zoom vulnerability work? +
The vulnerability is in the annotation feature during screen sharing. An attacker on the same call can, without any interaction from the victim and without any visible warning, remotely execute malicious code and take control of the device.
Am I still at risk? +
No, if you have updated your Zoom application. Zoom released patches for all platforms (Windows, macOS, Linux, iOS, Android) on Tuesday, August 11, 2026, that address this issue.
Why is the discovery of this vulnerability particularly concerning? +
Because the vulnerability was developed in less than 24 hours using just 20 queries to publicly available AI models. Previously, this would have required large teams and months of work, showing how AI is rapidly lowering the barrier for executing sophisticated cyber attacks.
What should I do to protect myself? +
Immediately update your Zoom application to the latest version. Also, if you use a Mac, check that you have installed the latest Apple security update for macOS (versions Tahoe 26.6.1, Sequoia 15.7.9, or Sonoma 14.8.9).

Log in

You need to log in or register to comment.

Comments (0)
No comments yet. Be the first!
Search
Popular
Nedavno pretraživano
helsinški sporazum
liga prvaka
digitalni mediji
Login
Home
Make 5MIN.hr a preferred source
Follow us on social media
Categories