AI tool hijacks Zoom devices in seconds, threatening 1.5 billion users
Researchers used an AI tool to exploit a Zoom screen-sharing flaw, hijacking devices in seconds without user interaction. This vulnerability threatens over 1.5 billion users, prompting Zoom to develoโฆ
A public AI tool discovered a critical flaw in Zoomโs screenโsharing feature that could let attackers hijack a device in under 20 prompts, researchers said on Tuesday. The flaw was uncovered by an openโsource language model that rapidly tested Zoomโs chat and screenโshare functions. The discovery was announced by a security research group that monitors AIโgenerated threats.
Zoom has faced security scrutiny after earlier bugs exposed data leaks and remote code execution vulnerabilities. The new flaw comes as the platform remains the most widely used videoโconferencing service for remote work, education, and virtual events. With more than 1.5โฏbillion users worldwide, any weakness that can be triggered from a simple chat message raises concerns about the safety of virtual meetings.
The vulnerability works by injecting malicious commands through Zoomโs chat interface, allowing an attacker to run code on the hostโs machine without the userโs knowledge. The AI model was able to craft a sequence of prompts that caused Zoom to execute an unauthorized script, effectively taking control of the device. The researchers noted that the exploit requires only a few seconds of interaction, and it does not rely on any userโinitiated file downloads or external links.
Zoom has acknowledged the issue and is working on a patch that will be rolled out in the coming weeks. Security experts advise users to keep their Zoom client updated, use twoโfactor authentication, and be cautious about accepting screenโshare requests from unknown participants. The incident highlights the growing intersection of AI and cybersecurity, where machine learning tools can both uncover and potentially create new attack vectors.
Read Full Story at Ars Technica โ


