3 weeks ago

Researchers expose 'Zoomsday' zero-click flaw in Zoom screen sharing

Researchers expose 'Zoomsday' zero-click flaw in Zoom screen sharing
‘Zoomsday’ security flaw exposes new risk of screen sharing: What we know · indianexpress.com

Zoom is an app that lets people talk and meet on computers and phones.

Sometimes, people share their screens so everyone on the call can see the same thing.

Smart computer experts called researchers found a secret problem, called a bug, in Zoom's screen-sharing feature.

This bug was a zero-day, which means nobody knew about it before.

It was also a zero-click attack, meaning a bad person could take over a device without the person clicking anything.

Just joining a Zoom call could have been enough to let an attacker take control.

The researchers found the bug using AI, with fewer than 20 prompts to powerful computer programs.

Zoom fixed the problem after the researchers told them about it.

The experts say this shows how careful we all need to be with the apps we trust.

Key facts

Vulnerability
'Zoomsday' - zero-day, zero-click flaw in screen sharing
Disclosed by
A Security researchers on Tuesday, August 11
First discovered
June
Affected platforms
Windows, macOS, Linux, iOS, Android
Attack requirement
No victim action needed (zero-click)
AI prompts used to find flaw
Fewer than 20
Fix status
Patched by Zoom on server and client sides

Quotes

Yossi Torati

Co‑founder of A Security

“If you just get on a Zoom with us, we can take over your device. The worst‑case scenario is that we can take over an enterprise just by having this vulnerability in our hands. If I’m an attacker, I can be on a call with someone from a company, take control of their computer and their credentials, and then use them to move laterally in the enterprise.”
indianexpress.com
“What is interesting for us and what we believe is dangerous is the democratisation of these capabilities—the barrier to entry is dropping rapidly.”
indianexpress.com

Sources

Related news