Critical Zoom Security Flaw Allowed Remote Device Takeover via Screen Sharing
Cybersecurity researchers have uncovered a severe vulnerability in the Zoom Workspace application that enabled attackers to remotely control devices by exploiting a weakness in the screen sharing annotation tool. This flaw affected Zoom versions on Windows, macOS, Linux, iOS, and Android, and notably did not require any user interaction such as clicking links, downloading files, or approving suspicious permissions. The exploit could be executed silently without alerting the user.
The vulnerability was tied to Zoom's annotation feature during screen sharing, which attackers could manipulate to run malicious code remotely and gain full device access. It remains unclear whether this security gap has been exploited in real-world attacks. Researchers also highlighted how artificial intelligence tools accelerated the development of this exploit, with a single researcher creating a working attack within 24 hours, a process that previously demanded extensive resources and time typically available only to state-sponsored actors.
Zoom was promptly informed of the issue and has released multiple patches to mitigate the threat. The company urges all users to update their Zoom Workspace applications to the latest versions to ensure protection. The vulnerability exists in all versions prior to these updates, making immediate upgrading critical for regular Zoom users.
The same event, reported separately by each outlet. Open a few to compare what different newsrooms emphasize — and what they leave out.
Not the same event — other stories that share this one’s people, places, or theme: background, reactions, and follow-ups.