AI-Discovered Zero-Click Zoom Bug Enabled Silent Device Takeover During Screen Sharing
Summary
- • A critical Zoom vulnerability allowed attackers to silently take over any participant's device with zero victim interaction during screen-sharing calls.
- • Security firm A Security discovered the bug using publicly available AI models in fewer than 20 prompts — a task that previously required a 5-person team six months.
- • The flaw existed in Zoom's proprietary real-time annotation protocol and affected all platforms: Windows, macOS, Linux, iOS, and Android.
- • Zoom has issued server and client-side patches; the vulnerability is now fixed as of August 11, 2026.
Details
Zero-click device takeover
Silent attack required no victim interaction — simply joining a Zoom call with an attacker was enough to expose any participant's device to full compromise.
AI found bug in <20 prompts
A Security discovered and weaponized the vulnerability using publicly available AI models in fewer than 20 prompts; the same work previously required a team of five experts for ~6 months.
Annotation protocol flaw
Vulnerability was in Zoom's proprietary real-time annotation protocol for screen sharing — closed-source code with limited external review and high complexity.
Enterprise lateral movement risk
Exploiting one device on a call could give an attacker access to credentials for lateral movement across an entire enterprise network.
Patches now live
Zoom issued both server-side and client-side fixes on August 11, 2026, across all supported operating systems.
A fully patched Zoom vulnerability reveals the urgent new reality: AI is now a mass-market offensive hacking tool.
What This Means
This Zoom vulnerability is a concrete, alarming demonstration of AI radically lowering the skill floor for sophisticated cyberattacks. The fact that a critical zero-click exploit in one of the world's most widely used platforms was discovered in under 20 AI prompts signals a paradigm shift in offensive security: capabilities once reserved for nation-states are now accessible to almost anyone. While the bug is patched, the methodology is not — organizations must now assume that complex, proprietary attack surfaces are being probed by AI-assisted tools at unprecedented scale and speed.
Sentiment
Concerned about AI making sophisticated exploits trivially easy
“An AI agent found a zero-click RCE in Zoom in under 24 hours, from less than 20 prompts on a public frontier model. One malformed message in the annotation protocol could own every device in the meeting. This is the part that should worry everyone. Not the exploit itself. The fact that exploit development just became a prompt engineering exercise.”
“Fewer than 20 prompts to a publicly available AI model produced a silent, interaction-free exploit chain for Zoom screen sharing that would have handed an attacker full device takeover on every platform Zoom supports. Fewer than 20 prompts changes threat modeling for every video-conferencing vendor.”
“🚨 BREAKING: An AI agent found a zero-click RCE in video conferencing tool Zoom in under 24 hours. A researcher at 'A Security' say fewer than 20 prompts on publicly available frontier models produced a working exploit against Zoom's annotation protocol: one malformed message takes over any participant's device.”
Split
~90/10 concerned vs neutral reporting (near-universal agreement on the 'AI lowers the bar' implication, with most discussion focused on the methodology rather than the specific Zoom bug).
