A Zoom Screen-Sharing Bug Let Anyone Take Over Other Devices on a Call

Researchers have disclosed two vulnerabilities in Zoom that allowed attackers to take over a user’s device simply by joining a screen-share call.In…

By Vane August 11, 2026 2 min read
A Zoom Screen-Sharing Bug Let Anyone Take Over Other Devices on a Call

Researchers have disclosed two vulnerabilities in Zoom that allowed attackers to take over a user’s device simply by joining a screen-share call.

The discovery

A Security, a digital defence firm, found the flaws in early June. The team used publicly available AI models to locate the issues. They required fewer than 20 prompts to generate a working exploit. Zoom issued a security advisory on Tuesday. The company has begun rolling out fixes for all supported operating systems: Windows, macOS, Linux, iOS, and Android.

Both server-side and client-side patches are now available. The vulnerabilities existed in the protocol used for real-time annotation during screen sharing.

Why the attack worked

The researchers noted that complex, obscure functions in proprietary software often hide overlooked mistakes. These areas lack the benefit of public, open review. Consequently, features like annotation are more likely to contain errors.

The attack required no interaction from the victim. There was no indication that anything was wrong. Anyone on a call involving screen sharing was at risk, whether they were the host or a participant.

The danger of AI tools

Omer Gull, cofounder of A Security, told WIRED ahead of the disclosure that the barrier to entry for such attacks is dropping rapidly. He stated that finding this vulnerability previously would have taken a team of five people six months with significant refining and iteration.

Now, individuals can achieve the same results with under 20 prompts. Gull described Zoom as an important target because users assume trust when using it. They do not typically view it as a threat.

Yossi Torati, another cofounder, explained the risk to WIRED while on a call hosted on Microsoft Teams. He said the worst-case scenario involves taking over an entire enterprise. An attacker could join a call with a company employee, seize control of their computer and credentials, and then move laterally within the organisation.

What it means

Joining a video call is a gesture of trust. People typically have their guard down when using Zoom for personal or professional contexts, including webinars and semi-public events. The researchers emphasise that the ability to compromise a device simply by getting someone onto a call is alarming.

Security has traditionally been a cat and mouse game. As AI bug hunting proliferates, that dynamic has become an all-out race.

Scroll to Top