Imagine you're on a regular Zoom meeting. Someone shares their screen, you do nothing, you click no suspicious links, and your computer is quietly taken over in the background. This is exactly the kind of terrifying vulnerability that researchers at A Security have uncovered, and what's alarming is how little time and resources it took them, less than 24 hours and about twenty queries to publicly available AI models.
The vulnerability lies in the annotation protocol during screen sharing in the Zoom Workspace app. The problem is that the attack requires no interaction from the victim and displays no visible warning. It's enough for the attacker to be on the same call and run malicious code, and the target remains completely unaware that they've been compromised.
From Elite Teams to a Solo Researcher
Omer Gull, co-founder of A Security, described to Wired how dramatic the lowering of the barrier for such attacks is. "Previously, it would take a team of five people maybe six months with a lot of refinement and iteration to find this. Now people can achieve the same results with fewer than 20 queries," Gull said, adding that Zoom is a particularly important target because users have an innate trust in it and don't perceive it as a threat.
This claim is also supported by a statement from the company itself, as reported by Engadget. "This class of capability would previously have been available only to state actors, but the model that required elite teams, months of effort, and weapons-grade budgets has collapsed. Today, a single researcher managed to develop a state-level exploit in less than a day."
From an Individual to an Entire Company
Although the vulnerability has now been patched, A Security demonstrated its potentially catastrophic reach. Yossi Torati, another co-founder, explained to Wired the chain reaction that could follow. "If you just join a Zoom call with us, we can take over your device. The worst-case scenario is that we can take over a company just by having this vulnerability in hand. If I'm an attacker, I can be on a call with someone from the company, take control of their computer and credentials, and then use them for lateral movement within the enterprise."
The vulnerability was discovered in early June, and Zoom issued a security advisory on Tuesday and began rolling out fixes at the server and client application levels. The issue existed on all platforms Zoom supports: Windows, macOS, Linux, iOS, and Android. Zoom did not respond to multiple inquiries from Wired for comment on A Security's findings, but the company stated that "users can help maintain security by applying the latest updates."
Apple Patches Its Own Flaw in the Same Week
Interestingly, in almost the same period, Apple also faced a similar critical flaw. A vulnerability in screen sharing on macOS allowed attackers on the same network to bypass authentication and gain access without valid credentials. Apple released emergency security patches on Monday, August 10, in macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9 updates.
Although there is no confirmation that any attackers have exploited these vulnerabilities in the real world, researchers emphasize that the speed and ease with which they were discovered using artificial intelligence is a serious warning for the future of cybersecurity. The race between attackers and defenders has just gained a whole new acceleration.