[research] · · 1 min read
Zoom Screen-Sharing Flaws Could Have Let Attackers Hijack Devices—Found in Under 20 AI Prompts
Researchers used AI to uncover critical Zoom vulnerabilities in the annotation protocol, highlighting the democratization of hacking.
By ByteBulletin Editors · Editorial Team
Security researchers have disclosed a set of vulnerabilities in Zoom's screen-sharing feature that could have allowed an attacker to silently take over a target's device—simply by getting them onto a call. The flaws, found in the real-time annotation protocol used during screen sharing, affect all supported platforms: Windows, macOS, Linux, iOS, and Android. Zoom has already issued patches for both its servers and client applications.
The discovery came from A Security, a digital defense firm, which used publicly available AI models to find the bugs. Remarkably, it took fewer than 20 prompts to uncover the vulnerabilities and develop a working exploit. According to Omer Gull, cofounder of A Security, what was once a task requiring a team of five people over six months can now be accomplished with a handful of prompts. "The barrier to entry is dropping rapidly," he told WIRED, emphasizing the danger of this democratization.
The vulnerabilities were buried in a complex, obscure part of the screen-sharing protocol—exactly the kind of code that human bug hunters have learned to scrutinize. In closed-source software like Zoom, such features may not receive the same level of public review, making them more prone to oversight. The researcher's AI systems were trained to target these convoluted functions, and they hit pay dirt.
While Zoom has since patched the flaws, the incident underscores a growing concern: AI is enabling faster, cheaper, and more accessible vulnerability discovery. The researchers warn that if an attacker exploits such a bug, they could take over a device and use it to pivot into an enterprise network. As Gull put it, "If you just get on a Zoom with us, we can take over your device."
This race between AI-powered attackers and defenders is accelerating. For developers and security teams, the message is clear: AI is no longer just a tool for writing code or summarizing docs—it's becoming a standard part of the security landscape, and the threats it enables are evolving just as quickly.
SHARE
RELATED
[research] ·
Agent Coalitions and Pricing: A New Model for AI-Driven Markets
A fresh framework from arXiv proposes how autonomous agents can form coalitions and set prices in decentralized markets, with implications for the future of AI-driven commerce.

[research] ·
Bridging the Knowing-Saying Gap: New Research Explores Why AI Can't Always Explain Itself
A new arXiv paper examines the disconnect between what AI systems know and what they can articulate, with implications for transparency in code generation and other developer tools.

[research] ·
WebGrader: An Automated Tool for Evaluating LLM-Generated Web Code
A new framework uses automated evaluation to grade web code generated by large language models, moving beyond manual review.
