Zoom Bug Let Hackers Take Over Devices
A vulnerability in Zoom's screen-sharing feature allowed attackers to take control of other devices on a call without any interaction from the victim, but a fix has been issued

A vulnerability in Zoom's screen-sharing feature allowed attackers to take control of other devices on a call without any interaction from the victim. The vulnerability, which was discovered by researchers using AI models, affected devices running Windows, macOS, Linux, iOS, and Android.
The researchers used fewer than 20 prompts to develop the screen-sharing exploit in under 24 hours, highlighting the potential for AI to assist in cyberattacks. The vulnerability existed in all Zoom Workspace versions prior to the latest updates, but Zoom has since issued a fix.
The fixed builds are Zoom Workplace 7.1.5 and 7.0.6, Rooms and the Meeting SDK at 7.1.5, and the Windows VDI client at 7.0.11 and 6.6.16. A Security, the firm that found the bugs, scored all three vulnerabilities at 9.0 out of 10, while Zoom rates CVE-2026-53413 and CVE-2026-53415 at 8.3 and CVE-2026-53414 at 6.5.
## What happened The vulnerability was discovered in Zoom's annotation system, which handles features such as drawing and adding text while sharing a screen. Specially crafted annotation data could trigger memory corruption in the receiving client and ultimately enable remote code execution.
## Why it matters The discovery of this vulnerability highlights the growing concern about AI-assisted security research. While AI can help defenders find vulnerabilities faster, it can also reduce the effort required to discover and exploit them. This vulnerability is a sobering example of the potential risks of AI-powered cyberattacks, and the need for companies to stay vigilant in protecting their users' security.
The fact that the vulnerability was discovered using publicly available AI models in under 24 hours is particularly concerning, as it suggests that the barrier to entry for cyberattacks is dropping rapidly. As AI models gain advanced capabilities to find vulnerabilities in software and develop ways to exploit them, the risk of silent and autonomous hacking sprees increases.
## What happens next Zoom has issued a security advisory and has begun rolling out fixes to address the flaws. Users can help keep themselves secure by applying the latest updates. The company's swift response to the vulnerability is a positive step, but it also highlights the need for ongoing vigilance in the face of evolving cyber threats.
The discovery of this vulnerability is a reminder of the importance of staying up to date with the latest security patches and being aware of the potential risks of using video conferencing platforms. As the use of AI in cyberattacks continues to grow, it is essential for companies and individuals to prioritize security and take steps to protect themselves against these types of threats.



