Researchers report that Zoom has patched a security vulnerability that could allow an attacker to hijack devices during a meeting via screen sharing and the app’s annotation features. Multiple outlets describe the flaw as one that could let a participant take control of another person’s device without the victim needing to click anything.
The reporting ties the discovery to a technique using publicly available AI models. Ars Technica, The Verge, and Decrypt state that researchers were able to develop the exploit quickly—citing fewer than 20 AI prompts and describing the work as taking about one day. The articles also note that a public AI tool helped identify or drive the process that led to a working exploit.
While details of the exploit mechanics are broadly consistent across outlets, the coverage emphasizes different aspects: some focus on the speed and ease with which AI can be used to generate an attack, while others center on the potential impact and the fact that Zoom has already issued a patch. The common throughline is that the vulnerability has been addressed and that the disclosure highlights accelerating methods for security testing and exploitation.