A reported Zoom screen sharing vulnerability could have let a person on a call take control of another participant’s device without any action or visible warning from the target, according to researchers at security firm A Security. The risk applied when a Zoom call involved screen sharing, and reporting says both hosts and participants could have been exposed.
Zoom has issued fixes on its servers and in its client applications, according to WIRED. The company’s patches cover Zoom-supported Windows, macOS, Linux, iOS, and Android devices. Users should update the Zoom app rather than assume a video-call client quietly takes care of itself.
What did the Zoom screen sharing vulnerability affect?
The reported bugs were in the protocol Zoom uses for real-time annotations during screen sharing, not screen sharing as a whole. An annotation protocol is the part of the software that coordinates marks, drawings, and other live on-screen comments between people in a meeting. A Security said defects in that component could have supported a silent device takeover during a call involving screen sharing.
That distinction matters. This was not the familiar “Zoom-bombing” problem, where an unwanted person enters or disrupts a meeting. The reported issue concerned the potential compromise of a participant’s device. The available reporting does not document exploitation in the wild or identify victims.
WIRED reported that Zoom did not respond to its requests for comment about A Security’s findings. The reporting also says Zoom’s remediation included both server-side and client-side fixes, but does not detail how those measures operate or which part of the exposure each addresses.
What should Zoom users do now?
Install the current Zoom client update. PCMag reported that versions before 7.1.5 and 7.0.6 were affected, though that version information comes from secondary reporting rather than the text of Zoom’s advisory included in the available material.
- Update Zoom on desktop and mobile devices.
- Check that managed work devices receive the organization’s approved Zoom update.
- Keep the app current on every operating system used for calls, including phones and tablets.
A Security said it found the flaws in early June with publicly available AI models and created a working attack in fewer than 20 prompts. That is the researchers’ account of this case, not a general benchmark for AI-assisted vulnerability research. Omer Gull, A Security’s cofounder, said the result showed his view that AI was lowering the barrier to finding software defects.
Yossi Torati, another A Security cofounder, described a potential enterprise compromise as a worst-case outcome: an attacker who took control of a device could obtain credentials and move through a company’s systems. That scenario is a researcher’s assessment, not evidence that such an intrusion occurred through these flaws.
This story draws on original reporting from Ars Technica.