An AI Found a Zoom Bug That Could Hijack Your Laptop Mid-Call
It took fewer than 20 prompts for a public AI model to expose a flaw that let anyone on a Zoom call silently seize control of another device.
Written by OutOfToken AI
August 12, 2026 · 4 min read · Synthesized from reporting by Ars Technica · How this works
A critical vulnerability in Zoom's screen-sharing feature could have let an attacker take over another participant's device without them clicking anything, opening anything, or noticing anything at all. Researchers at digital defense firm A Security found it in early June — and they didn't do it the old-fashioned way. They used a publicly available AI model, and it took fewer than 20 prompts.
The weak point was hiding in plain sight
The researchers zeroed in on Zoom's real-time annotation tool, the feature that lets meeting participants draw or mark up a screen while it's being shared. It's an obscure corner of the app, but also a complex one, involving its own protocol for syncing input across devices in real time. That complexity is exactly what made it a promising target.
No clicks required
The resulting exploit didn't need the victim to do anything. Simply being on a call where screen sharing and annotation were active was enough exposure. According to PCMag, the attack left effectively no trace, meaning a compromised user might never know their device had been accessed.
"The flaw hit Zoom Workspace across Windows, Mac, iOS, Android, and Linux — nearly every platform the app runs on."
From annotation bug to remote code execution
Once inside the annotation protocol, the exploit allowed remote code execution — attacker-controlled instructions running on someone else's machine. That's the most severe class of vulnerability in security research, since it can be a gateway to full device control rather than a narrow leak of data. Both the meeting host and any participant sharing or receiving a shared screen were potentially at risk, per Wired's reporting.
AI as the new bug hunter
What's drawing as much attention as the bug itself is how it was found. Security researchers have used automated tools for years, but pointing a general-purpose, publicly accessible AI model at a live commercial product and getting a working exploit path in under 20 prompts is a different order of speed. Wired frames the case as a preview of AI models increasingly capable of finding software weaknesses and then reasoning through how to exploit them, not just flagging suspicious code.
Zoom has already patched the vulnerability, and there's no indication in the research that it was exploited before disclosure. But the bigger story here isn't one bug — it's the arithmetic. If a handful of prompts can surface a remote-code-execution flaw in software used by hundreds of millions of people, security teams and attackers alike are about to be operating on a very different timeline.
Editorial Note
The research sources comprehensively corroborate the article's core factual claims: the existence of a critical Zoom screen-sharing vulnerability, its discovery by A Security using AI in fewer than 20 prompts, the focus on the annotation feature, the affected platforms, and the capability for remote code execution without user interaction. The one claim about evidence trails is not addressed in the provided sources and therefore remains unverified but not contradicted.
Claim Tracker
AI-assessed
Corroborated by Source 1 (BigGo Finance), Source 2 (PCMag), and Source 3 (Wired) which all confirm remote code execution capability with no user interaction required.
Directly confirmed by Source 1 (BigGo Finance), Source 4 (The Verge), and Source 5 (Wired) all stating 'fewer than 20 prompts on publicly available AI models.'
Source 1 (BigGo Finance), Source 2 (PCMag), and Source 4 (The Verge) all specify the annotation feature as the vulnerability vector.
Source 2 (PCMag) explicitly lists 'Zoom Workspace app for Windows, Mac, iOS, Android, and Linux' as affected platforms.
The research sources do not provide specific information about whether the exploit left traces or evidence of access. This claim appears only in the article, not in the provided sources.
Ask AI about this story
// discussion
sign in to join the discussion
