Ask Runable forDesign-Driven General AI AgentTry Runable For Free
Runable
Back to Blog
Technology7 min read

A dangerous Zoom screen-sharing bug could have let hackers hijack other devices on a call | TechRadar

Patch Zoom now or possibly pay a big price Discover insights about a dangerous zoom screen-sharing bug could have let hackers hijack other devices on a call | t

TechnologyInnovationBest PracticesGuideTutorial
A dangerous Zoom screen-sharing bug could have let hackers hijack other devices on a call | TechRadar
Listen to Article
0:00
0:00
0:00

A dangerous Zoom screen-sharing bug could have let hackers hijack other devices on a call | Tech Radar

Overview

News, deals, reviews, guides and more on the newest computing gadgets

Start exploring exclusive deals, expert advice and more

Details

Unlock and manage exclusive Techradar member rewards.

Unlock instant access to exclusive member features.

Get full access to premium articles, exclusive features and a growing list of member rewards.

A dangerous Zoom screen-sharing bug could have let hackers hijack other devices on a call

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works.

AI‑found Zoom flaws enabled device takeover through malicious annotation messages

Exploits worked across all platforms and required only joining a video call

Researchers warn AI now enables rapid, nation‑state‑level exploit development

Experts have warned that Zoom, one of the most popular collaboration tools in the world, carried multiple vulnerabilities that allowed malicious actors to take over people’s devices, entirely.

What makes these vulnerabilities particularly dangerous is that the victims need not do much to be compromised - participating in a video call with the attacker is enough.

The bugs were said to be present in every version of Zoom, on every device and operating system - Windows, Mac, i Phone, Android, and Linux, in all versions up to and including 7.0.5 - with patches available now, so be sure to update immediately.

The flaws were discovered by security researchers A Security, which focuses on “autonomous offensive security”, using AI agents to simulate real-work attacks, identify vulnerabilities, and chain them into exploitable attack paths.

The company “simply” used publicly available frontier models and within 24 hours and fewer than 20 prompts, went from finding the flaws to building a working exploit.

Zoom patches critical security flaw which could have let hackers hijack accounts

Hackers use fake Adobe and Zoom updates to load malware onto victim devices

Experts warn Chat GPT's Workspace Agent Builder can be hijacked to create malicious AI workers

The flaws are described as memory corruption bugs exploiting Zoom’s annotation feature. That feature, built on a proprietary protocol (meaning it has no public documentation or specifications, as opposed to being open source), meant that the Zoom client parsed everything it received, including specially crafted, malicious messages.

During the call, a malicious actor could send a message to each visitor that would corrupt their device’s memory and execute weaponized code, all without the victim knowing, being prompted to do anything, or clicking anything at all.

The vulnerability can be exploited regardless of if the attacker hosted, or simply joined, a call. All participants, regardless of their status in the call, were equally at risk. There were no visual cues indicating the compromise whatsoever.

A Security responsibly disclosed their findings to Zoom, who labeled the vulnerabilities as CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415, and all given a severity score of 9.0/10 (critical).

Experts say they were able to create a rogue agent in Google’s AI platform with just a single edit permission

Claude Cowork can break its bonds and access Mac files, experts claim

Microsoft warns AI agents are being 'Auto Jack'-ed by browsing untrusted websites

Furthermore, all Zoom Workplace clients on all supported platforms before version 7.1.5 and 7.0.6 using end-to-end encryption settings are considered vulnerable. A Security recommends updating the client to the latest version.

In its writeup, A Security stressed the simplicity and ease with which it managed to find the bugs and develop the exploits. It warned that AI has dramatically lowered the barrier for entry, and argued that in the pre-AI era, exploits like these were “reserved” for nation-state threat actors with virtually limitless resources:

“This class of capability would previously have only been available to nation-state threat actors, but the model requiring elite teams, months of effort, and weapons-grade budgets has collapsed,” the researchers warned. “Today, a single researcher was able to develop a nation-state-level exploit in less than a day.”

To add insult to injury, these flaws were found using “publicly available frontier models” such as GPT-5.6 Sol, Claude Opus 5, and the likes. Besides the frontier models, these companies also have dedicated cybersecurity programs where they offer specialized models with fewer guardrails and more flexibility for both offensive and defensive actions.

Earlier this week, Open AI said that its Daybreak project now offers GPT-5.6-Cyber, a model built on GPT‑5.6 Sol and trained to improve capabilities on several specialized cybersecurity tasks such as finding zero-day vulnerabilities and developing exploit chains.

Daybreak came as a direct response to Anthropic’s Project Glasswing. This is an offering that came with Mythos Preview, an AI model that proved unusually capable at cybersecurity tasks. Allegedly, Mythos can autonomously identify and exploit zero-day flaws across major operating systems and browsers, as well as develop complex exploit chains. Because of those capabilities, Anthropic did not release Mythos Preview broadly. Instead, it made the model available to a limited group of organizations.

While some expressed their skepticism over Mythos, saying Anthropic is engaging in fear-based marketing, others have backed the company, saying Mythos proved exceptionally useful at identifying and fixing flaws. Microsoft, for example, is one of the original Project Glasswing partners, and ever since it started using it, the number of flaws patched through its Patch Tuesday cumulative update quadrupled.

Mozilla is also among those showering Mythos with praise, saying earlier this year that it is “every bit as capable” as the world’s best security researchers.

If A Security managed to find such dangerous flaws with publicly available models, there’s no telling what these dedicated models can do.

➡️ Read our full guide to the best antivirus

  1. Best overall: Bitdefender Total Security
  2. Best for families: Norton 360 with Life Lock
  3. Best for mobile: Mc Afee Mobile Security

Follow Tech Radar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, Io T, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

You must confirm your public display name before commenting

The Xbox Elite Series 3 seems to have leaked — and, in a twist no one expected, might have a built-in screen

Watch out, Waze fans — there's a bug that means reports of police aren't showing up for many

Google is building three huge new subsea cables to connect North, Central and South America

Lioness season 3 episode 2 has already revealed my biggest issue with how LGBT+ women are portrayed on TV is true — even using Taylor Sheridan's 'exceptional' female characters

EU study proposes 30-minute takedown of illegal streams, and your VPN is in the crosshairs

Tech Radar is part of Future US Inc, an international media group and leading digital publisher. Visit our corporate site.

© Future US, Inc. Full 7th Floor, 130 West 42nd Street, New York, NY 10036.

Key Takeaways

  • News, deals, reviews, guides and more on the newest computing gadgets
  • Start exploring exclusive deals, expert advice and more
  • Unlock and manage exclusive Techradar member rewards
  • Unlock instant access to exclusive member features
  • Get full access to premium articles, exclusive features and a growing list of member rewards

Cut Costs with Runable

Cost savings are based on average monthly price per user for each app.

Which apps do you use?

Apps to replace

ChatGPTChatGPT
$20 / month
LovableLovable
$25 / month
Gamma AIGamma AI
$25 / month
HiggsFieldHiggsField
$49 / month
Leonardo AILeonardo AI
$12 / month
TOTAL$131 / month

Runable price = $9 / month

Saves $122 / month

Runable can save upto $1464 per year compared to the non-enterprise price of your apps.