Researchers from the digital defense firm A Security uncovered a critical vulnerability in Zoom that could have allowed attackers to take over devices during screen-sharing calls. The flaw, which affects all major operating systems including Windows, macOS, Linux, iOS, and Android, could be exploited without any interaction from the victim. Zoom issued a security advisory on Tuesday, providing details about the fixes it has already started rolling out to address the issue.
The vulnerability lies in the protocol used for real-time annotation during screen sharing. A Security’s AI bug hunting systems specifically targeted this component because it is known to often contain overlooked vulnerabilities, especially in proprietary, closed-source software. The researchers noted that while companies like Zoom typically conduct extensive code reviews, the lack of public, open review makes esoteric features like annotation more prone to errors. The AI models used to discover the bug required fewer than 20 prompts and were able to uncover the vulnerabilities quickly, highlighting the growing accessibility of these tools.
Zoom did not respond to multiple requests for comment from WIRED about the findings. The bugs are now patched with both server and client-side fixes, but the researchers emphasized the alarming nature of the vulnerability. Joining a Zoom call is a gesture of trust, and given the platform’s widespread use in both personal and professional settings, users often have their guard down. The researchers warned that the vulnerability could have allowed attackers to take over enterprise systems by simply joining a call and exploiting the flaw.
Source: wired