3 weeks ago
Researchers expose 'Zoomsday' zero-click flaw in Zoom screen sharing
Zoom is an app that lets people talk and meet on computers and phones.
Sometimes, people share their screens so everyone on the call can see the same thing.
Smart computer experts called researchers found a secret problem, called a bug, in Zoom's screen-sharing feature.
This bug was a zero-day, which means nobody knew about it before.
It was also a zero-click attack, meaning a bad person could take over a device without the person clicking anything.
Just joining a Zoom call could have been enough to let an attacker take control.
The researchers found the bug using AI, with fewer than 20 prompts to powerful computer programs.
Zoom fixed the problem after the researchers told them about it.
The experts say this shows how careful we all need to be with the apps we trust.
Researchers from digital defense firm A Security disclosed a zero-day, zero-click flaw in Zoom's screen-sharing feature on Tuesday, August 11.
The vulnerability, first discovered in June, could let attackers take control of devices belonging to participants or hosts on calls with screen sharing.
The bug was uncovered and exploited by researchers using fewer than 20 prompts to publicly available AI models.
Any device running Windows, macOS, Linux, iOS, or Android was susceptible to the attack.
Zoom issued a security advisory and patched the flaw on both the server and client sides.
- Who
- Researchers from the digital defense firm A Security, including co-founders Omer Gull and Yossi Torati, who disclosed the flaw; Zoom, which issued the patch.
- What
- A zero-day, zero-click vulnerability in Zoom's screen-sharing feature that could let attackers take control of a device simply by joining a call.
- Where
- In Zoom's video conferencing platform; it affected any device running Windows, macOS, Linux, iOS, or Android.
- When
- Disclosed on Tuesday, August 11; first discovered in June this year.
- Why
- The flaw was traced to the protocol used for real-time annotation during screen sharing and required no action from the victim, making it easy to exploit.
AI democratization is a growing danger
AI strengthens cybersecurity defense
AI lowering the barrier to hacking
AI democratization is a growing danger
The democratization of AI capabilities is dangerous because the barrier to entry is dropping rapidly - finding a critical flaw once took a team of five people about six months and now takes fewer than 20 prompts.
AI strengthens cybersecurity defense
AI tools for hunting bugs have emerged as an important part of the cat-and-mouse game between threat actors and cyber defenders, helping to secure vulnerable software.
Best AI models for security research
AI democratization is a growing danger
Some in the tech industry argue Chinese open-weight models are more useful for cybersecurity research than frontier AI models from OpenAI and Anthropic, which they say are constrained by stricter cyber guardrails.
AI strengthens cybersecurity defense
Frontier AI companies such as OpenAI and Anthropic impose stricter cyber guardrails on their models as a deliberate safety measure to limit misuse, even if that restricts some security research.
Key facts
- Vulnerability
- 'Zoomsday' - zero-day, zero-click flaw in screen sharing
- Disclosed by
- A Security researchers on Tuesday, August 11
- First discovered
- June
- Affected platforms
- Windows, macOS, Linux, iOS, Android
- Attack requirement
- No victim action needed (zero-click)
- AI prompts used to find flaw
- Fewer than 20
- Fix status
- Patched by Zoom on server and client sides
Quotes
Yossi Torati
Co‑founder of A Security
“If you just get on a Zoom with us, we can take over your device. The worst‑case scenario is that we can take over an enterprise just by having this vulnerability in our hands. If I’m an attacker, I can be on a call with someone from a company, take control of their computer and their credentials, and then use them to move laterally in the enterprise.”
indianexpress.com
“What is interesting for us and what we believe is dangerous is the democratisation of these capabilities—the barrier to entry is dropping rapidly.”
indianexpress.com











