Zoom Patches Critical Security Flaw Exposing User Screens

Zoom fixed a critical screen-sharing annotation flaw after researchers showed it could enable remote control during calls across major platforms.

Atlas Newsdesk ·

Zoom Patches Critical Security Flaw Exposing User Screens

Zoom has remediated a critical security vulnerability tied to its screen-sharing annotation protocol after security researchers disclosed the issue. Officials said the weakness could have allowed an unauthorized party to take remote control of a participant’s device during a Zoom call without any user interaction and without alerting the victim.

The researchers said the flaw was not limited to a single device type or operating system. According to their findings, the exposure affected all supported Zoom platforms, including Windows, macOS, Linux, iOS, and Android.

How the Zoom annotation protocol was abused The

How the Zoom annotation protocol was abused

The reported attack path centered on the mechanism The reported attack path centered on the mechanism used for on-screen annotations during screen sharing. Researchers said the bug could be leveraged to gain control silently, which raises the stakes for enterprises that rely on Zoom for meetings, support sessions, and day-to-day collaboration.

The researchers also described how they identified the vulnerability using publicly available artificial intelligence models. They said fewer than 20 prompts were needed to reach a functional exploit, a detail that points to how quickly an attacker could iterate from idea to working proof-of-concept when tooling is readily accessible.

Patches deployed and what organizations should do Zoom said it has addressed the issue through a combination of server-side and client-side updates. That approach matters operationally because server-side changes can reduce exposure quickly, while client updates are often required to fully close off a device-level path.

Organizations were advised to ensure every Zoom application instance is updated to the latest version. The researchers warned that unpatched endpoints can create an opening for lateral movement inside enterprise networks, particularly if a compromised device can reach other internal services or user accounts.

Why the discovery method is drawing attention

Researchers said the use of public AI models helped uncover a complex flaw in a proprietary, closed-source application. They argued this demonstrates a lower barrier to finding sophisticated vulnerabilities even when traditional methods, such as manual code review, are constrained by limited visibility into the underlying code.

The incident adds to broader security concerns around The incident adds to broader security concerns around real-time collaboration tools used in professional settings. When such platforms are embedded into daily workflows across departments and geographies, a single high-impact weakness can create risk at scale if patching lags behind active use.

Some uncertainty remains in public descriptions of the issue, including how widely the exploit technique may have circulated before remediation and whether any abuse occurred. Zoom and the researchers emphasized patching as the immediate mitigation step.

More stories