Zoom Patched the Screen-Sharing Door
Researchers at A Security used fewer than 20 prompts with public AI models to find Zoom screen-sharing flaws that could enable device takeover; Zoom issued server and client fixes.
A compromised call could expose devices across Zoom-supported operating systems, while users and organizations remain responsible for installing client updates and limiting sharing privileges.
The prompt count is the flashy number. The operative system includes researchers who validated the attack, a disclosure process, Zoom engineers who patched servers and clients, and users who must install the fix. Discovery became security only because people completed that chain.
Researchers at digital defense firm A Security found flaws in Zoom that could have allowed someone on a call to take over another participant’s device. They discovered the vulnerabilities in early June with publicly available AI models and fewer than 20 prompts. Zoom has issued server-side and client-side fixes covering Windows, macOS, Linux, iOS and Android.
The vulnerable mechanism was the protocol supporting real-time annotation during screen sharing. That feature looks minor: a way to mark a shared page while people talk. It also accepts and coordinates input across devices. The useful collaboration surface was therefore an attack surface.
The AI-assisted discovery deserves attention, but not mythology. A model helped researchers search an obscure component and develop a working attack quickly. It did not independently establish the real-world risk, manage responsible disclosure, write every fix or ensure that customer devices received the corrected software.
The patch has a supply chain
A Security had to validate what it found and report it. Zoom had to change both its own servers and the applications running on customer devices. Administrators and individual users now have to install the client update. Miss one stage and the celebrated discovery remains a documented opening.
Ordinary trust made the bug more serious. People join work meetings, webinars and personal calls expecting the danger to come from a suspicious link or attachment, not from the call’s shared controls. Screen sharing feels like showing. Underneath, it is a set of permissions, protocols and inputs connecting machines that may know little about one another.
The immediate response is plain. Update Zoom on every device, confirm that managed fleets have received the fixed client, and restart applications when installation requires it. Hosts should also review screen-sharing and annotation settings, restrict those powers to known participants or hosts where practical, and avoid granting broad control merely because a meeting link worked.
The next test is not whether AI can find another bug. It will. The useful measure is how quickly vendors disclose and repair flaws, how reliably organizations patch neglected devices, and whether meeting defaults grant only the access a call actually needs. Security finishes at installation, not announcement.
Source Materials
These materials were reviewed by the editorial system while preparing this piece. Muerte.casa may interpret, satirize, reframe, or disagree with them.
- A Zoom Screen-Sharing Bug Let Anyone Take Over Other Devices on a Call Wired · August 11, 2026 · Primary signal · Direct source
How did this story land?
This may be changed as you like.


