Zoom patches critical flaw that let attackers hijack devices via annotation feature

Zoom has fixed a serious security vulnerability that could allow attackers to take control of any participant's device during a meeting. Researchers at A Security discovered the flaw using fewer than 20 prompts on publicly available AI models, as first reported by Wired. The exploit targeted Zoom's annotation feature, which lets users draw on their shared screen during calls. Through this flaw, a malicious actor could run harmful code on victims' devices, enabling data theft, unauthorized camera or microphone access, or malware installation. Zoom has since released a patch to address the vulnerability.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.



Discussion (0)
Log in to join the discussion and vote.
Log in