Zoom Bug Handed Attackers Full Control of Devices

Photo Credit: ymphotos / Shutterstock.com
Cybersecurity researchers uncovered a vulnerability in Zoom that allowed attackers to take complete control of another participant's device during a call by exploiting a flaw in the screen-sharing function. The bug was found in the Zoom Workspace app across Windows, Mac, iOS, Android and Linux. As a result, no major platform was exempt from the risk.
The attack was designed to be silent. It required nothing from the victim. There was no visible warning and no interaction needed. However, when someone launched the annotation tool while sharing their screen, the vulnerability let a bad actor remotely execute malicious code and gain access, opening a path to controlling the machine outright.
Whether the flaw was ever exploited in real-world attacks remains unclear, and no evidence has surfaced that it was used in the wild. What stands out is how quickly the exploit was built. The researchers who discovered it used AI prompts to develop the screen-sharing attack in under 24 hours, an illustration of how AI can lower the barrier to sophisticated cyberattacks.
The cybersecurity company framed the finding as a shift in what individual actors can now accomplish. "This class of capability would previously have only been available to nation-state threat actors, but the model requiring elite teams, months of effort and weapons-grade budgets has collapsed," it wrote in a blog post. "Today, a single researcher was able to develop a nation-state-level exploit in less than a day." Therefore, the point cuts against the assumption that this caliber of attack demands a large, well-funded team.
Zoom was notified about the vulnerability and has deployed several fixes to mitigate the threat. The company said "users can help keep themselves secure by applying the latest updates." The flaw exists in all Zoom Workspace versions prior to those updates. Consequently, anyone still running older builds remains exposed until they update. Given that the attack leaves no visible trace, applying the patch is the practical line of defense.
The Zoom disclosure lands alongside a comparable problem at Apple, which recently issued a round of macOS updates to close its own screen-sharing weakness. A vulnerability in the Screen Sharing feature could allow attackers on the same network to bypass authentication and gain access without valid credentials. Apple has released fixes in macOS Tahoe 26.6.1, Sequoia 15.7.9 and Sonoma 14.8.9. Those newer versions are safe. In contrast, users on older releases are advised to update their Macs.
The two incidents point to screen-sharing functionality as a recurring soft spot across widely used software. Both were resolved the same way. Vendor patches, however, only help users who actually install them. For anyone relying on Zoom for regular video calls, the takeaway is direct: update the Workspace app to the latest version, since older builds carry the unpatched flaw. Mac owners should confirm they are running one of the fixed macOS releases as well.
The speed of the Zoom exploit's development is the detail worth watching. A single researcher assembling a nation-state-level attack in under a day suggests the pace of vulnerability discovery is accelerating. As a result, it puts added pressure on both vendors and users to keep software current.

