Zoom flaw allowed attackers to take control of your iOS and Android devices
An AI tool was able to quickly discover the vulnerability, which was subsequently reported to Zoom.
Zoom flaw could have taken control of your iOS or Android devices. | Image by PhoneArena
An AI tool helped cybersecurity firm A Security find a flaw with Zoom that bad actors could have exploited to take over devices used by those on a Zoom video conference call. Anyone connected to a Zoom call involving screen sharing, whether the host or participant, would be left open and exposed to a silent attack that required no interaction from the victim, who also would have no idea that their device was under attack.
Devices powered by platforms supported by Zoom were at risk
All of the platforms that Zoom supports were at risk. So devices powered by iOS, Android, Windows, macOS, and Linux were vulnerable. A Security, the cybersecurity firm that discovered the flaw, said that the scary part of this whole thing was how easy it was for AI to find the flaw. Actually, the bug was discovered in June and was recreated using less than 20 prompts on a publicly available AI model.
The vulnerabilities have since been patched
A Security reported to Zoom about the vulnerability and it has since been patched. The cybersecurity firm's co-founder, Omer Gull, said that before the availability of public AI models, it would have taken a team of five people about six months to find the vulnerability. Gull said that Zoom is an important target because most people trust the Zoom platform and do not see it as a threat.
The worst-case scenario is that we can take over an enterprise just by having this vulnerability in our hands. If I’m an attacker, I can be on a call with someone from a company, take control of their computer and their credentials, and then use them to move laterally in the enterprise.
Yossi Torati, A Security cofounder
Zoom has recently released a security advisory
Yesterday, Zoom disseminated a security advisory that included the details about how it fixed the flaws that could have been exploited. Zoom was forced to patch its own servers and the apps that run on the devices used by its customers. The researchers were calling it alarming that there were bugs that could be used to take over a person's device simply by getting a potential victim to join a Zoom call.

Zoom has just released a security advisory. | Image by Zoom
"If you just get on a Zoom with us, we can take over your device," A Security co-founder Yossi Torati told WIRED. Zoom is used every day by for consumer-related chats including some between doctors and their patients. In fact, I had a Zoom call earlier this week with my endocrinologist. And of course, Zoom is also used by companies for intra-company communications and more.
Are security issues your thing? Check out these articles:
Pixel users can patch some flaws now
Apple tried to confuse hackers by making a change
Things that are NOT allowed:
To help keep our community safe and free from spam, we apply temporary limits to newly created accounts: