Skip to main content
← Back to market wire
AI toolsArs Technica

Researchers found a way to hijack devices through Zoom screen sharing

A public AI tool found the dangerous Zoom flaw in under 20 prompts.

Desk analysis

AI-assisted2 min read

The disclosure from A Security is a quiet landmark, not because Zoom was found vulnerable, but because of how the flaw was found. A public AI model, guided by fewer than 20 prompts, produced a working attack against a platform trusted by hundreds of millions. The barrier to entry for offensive cyber capability just dropped from a six-month specialist project to an afternoon experiment.

For the remote work economy, this is not a hypothetical. Zoom is the connective tissue of distributed teams, boardrooms, and client calls. A vulnerability in screen sharing means every participant on a call is a potential entry point, with no click required from the victim. The attack is silent, which is precisely what makes it dangerous. Trust in the tool becomes the attack surface.

The fix is already rolling out, and Zoom's advisory is a model of responsible disclosure. But the deeper signal is structural. The democratization of vulnerability research means the security industry's old calculus is obsolete. Teams of five and six-month timelines are no longer the benchmark. The cost of finding a flaw is now measured in prompts, not person-months.

This shifts the burden onto every organization that relies on remote collaboration. Patching is no longer a quarterly ritual; it is a daily discipline. The tools that enable distributed work must be treated as critical infrastructure, not convenience software. The next vulnerability may not be announced with a press release. It may simply be used.