A Zoom Screen-Sharing Bug Let Anyone Take Over Other Devices on a Call

A Zoom Screen-Sharing Bug Let Anyone Take Over Other Devices on a Call

Researchers say a public AI tool needed fewer than 20 prompts to surface a flaw that turned Zoom's screen-share feature into a takeover tool.

Written by OutOfToken AI

August 11, 2026 · 4 min read · Synthesized from reporting by Wired · How this works

AI Likely Accurate · 6/10

Zoom has patched a screen-sharing vulnerability that researchers say could let a malicious participant hijack another attendee's device mid-call. According to Wired, the flaw was uncovered using a public AI tool in fewer than 20 prompts, a detail that has alarmed security researchers more than the bug itself. Zoom says the issue has been fixed, but the episode raises hard questions about how fast AI can now find flaws that once took human researchers weeks.

A Familiar Weak Spot, Again

Screen sharing has long been one of Zoom's most exploited features. Back in March 2021, The Hacker News reported a separate screen-sharing bug that let users peek into restricted apps during a call, forcing Zoom to ship emergency fixes. The newly disclosed flaw follows that same pattern: a feature built for convenience becoming a backdoor for control.

How the Takeover Reportedly Worked

The exact technical mechanics of the new bug haven't been fully detailed publicly, but the underlying risk is consistent with how remote-control permissions work in Zoom. Normally, taking control of someone else's screen requires an explicit request and an on-screen consent prompt. Security researchers have already shown how easily that consent step can be gamed.

Social Engineering Meets Software Flaws

Malwarebytes documented a related attack in April 2025 involving a group it calls ELUSIVE COMET, which tricked victims into approving remote-control requests by disguising the sender's screen name as "Zoom" itself. The fraudulent prompt read as if the app, not a person, was asking for access. That kind of manipulation shows attackers don't always need a new bug — sometimes the interface itself is enough of a weapon.

"It reportedly took fewer than 20 prompts to a public AI tool to expose a flaw letting someone seize control of another user's device on a Zoom call."

AI Is Changing Who Finds These Bugs

What sets this incident apart isn't the vulnerability class — screen-sharing and remote-control flaws in video conferencing software are well documented — it's the speed of discovery. If a general-purpose AI tool can identify an exploitable flaw in a widely used enterprise product with minimal prompting, the barrier to finding similar bugs drops sharply. That could work in defenders' favor if companies adopt the same tools for internal testing, or it could hand a similar shortcut to attackers with less technical skill than traditional exploit development demands.

Zoom's Pattern of Patch-and-Move-On

Zoom has a track record of responding to disclosed vulnerabilities with fixes rather than structural redesigns. As recently reported by The Hacker News, the company patched a separate critical Windows flaw that could enable account takeover, underscoring that screen-sharing and remote-access features remain a recurring target. Zoom brought in outside security expertise, including Stanford Internet Observatory's Alex Stamos, following its pandemic-era security scrutiny, but new flaws keep surfacing in the same feature areas.

Zoom says the specific bug described here has been resolved, but the incident is less a story about one flaw than about how fast flaws can now be found. As AI-assisted vulnerability discovery becomes routine, video conferencing platforms — used for everything from board meetings to remote IT support — may need to treat screen-sharing and remote-control permissions as a permanent attack surface, not a one-time fix.

Editorial Note

The research corroborates historical Zoom screen-sharing vulnerabilities (March 2021 bug) and confirms the April 2025 ELUSIVE COMET attack with social engineering tactics. However, the research does not contain details about the specific new vulnerability, the AI discovery methodology, or patch confirmation. The article's framing around AI speed-of-discovery lacks supporting evidence in the provided sources.

AI Security Alert

Claim Tracker

AI-assessed

VerifiedIn March 2021, The Hacker News reported a separate screen-sharing bug that let users peek into restricted apps during a call

Source 1 (The Hacker News, Mar 19, 2021) confirms a screen-sharing vulnerability allowing access to restricted apps

VerifiedMalwarebytes documented a related attack in April 2025 involving a group called ELUSIVE COMET, which tricked victims into approving remote-control requests by disguising the sender's screen name as 'Zoom' itself

Source 5 (Malwarebytes, April 2025) confirms ELUSIVE COMET campaign where attackers changed their screen name to 'Zoom' to trick victims into approving remote control requests

VerifiedNormally, taking control of someone else's screen requires an explicit request and an on-screen consent prompt

Source 4 (Zoom support documentation) and Source 5 both confirm remote control requires explicit request and notification to the target user

UnverifiedA public AI tool found the flaw in fewer than 20 prompts

The research summary mentions this claim but no provided source contains technical details about the AI discovery methodology or confirms the exact prompt count

UnverifiedZoom has patched the screen-sharing vulnerability

The article claims the flaw is 'now fixed' but no provided research sources confirm the specific patch or its status

Ask AI about this story

// discussion

sign in to join the discussion