Tech News

Zoomsday Security Flaw: Zoom Screen Sharing Puts Devices at Risk

A critical Zoom security flaw dubbed “Zoomsday” could let attackers remotely compromise devices through screen sharing. Researchers said the vulnerability required no victim interaction and affected Windows, macOS, Linux, iOS and Android.

Written By : Somatirtha
Reviewed By : Achu Krishnan

A critical security vulnerability in Zoom’s screen-sharing feature could have allowed attackers to remotely take control of participants’ devices without requiring any action from the victim. The flaw, dubbed ‘Zoomsday’ by cybersecurity researchers, affected Zoom users on Windows, macOS, Linux, iOS and Android.

Researchers at cybersecurity firm A Security discovered the vulnerability while examining Zoom’s real-time annotation protocol. They said the flaw could be exploited during a meeting involving screen sharing, potentially allowing an attacker to execute malicious code on another participant’s device.

Flaw Found in Zoom’s Annotation Feature

The bug was tied to Zoom’s annotation feature, where meeting attendees can write over the screen being shared. Researchers noted that certain crafted messages could exploit vulnerabilities in the protocol responsible for processing annotations.

The victim did not need to click on a link, download a file, or perform any other actions. The researchers stated that the compromise could occur without any indication to the user. 

Once a device was compromised, hackers could steal information, turn on the microphone and camera, and install malware. A security researcher said the bug was discovered in early June with the help of publicly available AI models. The researchers stated that it took less than 20 prompts to uncover the flaw and create the exploit.

AI Reduced Barrier to Exploitation

A Security cofounder Omer Gull said the development showed how quickly AI was lowering the barrier to sophisticated vulnerability research. According to the researchers, an exploit of this nature would previously have required a team of around five people, several months of work, and substantial resources. This time, the researchers reached a working result using publicly available AI tools in a single day.

The vulnerability was particularly concerning since Zoom is widely trusted and used for professional meetings, webinars, and other public or semi-public events.

Also Read: Zoho Expands Digital Learning with AI-Powered Classes 2.0 Across India with 22 Languages

Zoom Rolls Out Security Fixes

Zoom has released server-side and client-side fixes for the vulnerabilities. The company has also issued updates covering its supported platforms. Security researchers said the flaw demonstrated the risks posed by vulnerabilities in complex, less visible features such as real-time annotation.

However, a security expert noted that the repercussions could not be limited to one device only. If an attacker took over the computer of an organizational user, they would be able to gain access to credentials and use them to perform lateral movement within the company’s internal network.

It is also noteworthy that this issue raises a new cybersecurity threat. Modern AI tools can help researchers discover software flaws and create exploits much faster than before. However, the discovered flaws have already been fixed, which means that users should update their Zoom apps.

Join our WhatsApp Channel to get the latest news, exclusives and videos on WhatsApp

Bitcoin Volatility Hits 3-Year Low as Major Breakout Risk Builds

CZR Exchange Surpasses 200,000 Users Worldwide, Marking Major Milestone in Global Expansion

Crypto Custody: How Institutions Safely Store Digital Assets

Solana’s Stablecoin Economy Expands 11x as Crypto Payments Gain Momentum

Ethereum Price Prediction 2026: What Google Gemini Forecasts for ETH