Researchers at A Security have discovered a critical bug in Zoom that allows attackers to assume full control of a participant’s device by exploiting a flawed screen-sharing function.
The vulnerability exists in the Zoom Workspace app for Windows, Mac, iOS, Android, and Linux. When a user launches the annotation tool while sharing their screen, the bug allows attackers to remotely execute malicious code and access participants’ devices. The attack requires no action from a victim’s end and leaves no visible warning, A Security says in its blog post.
The firm discovered the bug and developed a working exploit for it in just 24 hours. They did it using just 20 prompts on a publicly available AI model, highlighting how AI can make cyberattacks easier to carry out.
“This class of capability would previously have only been available to nation-state threat actors, but the model requiring elite teams, months of effort, and weapons-grade budgets has collapsed,” A Security says. “Today, a single researcher was able to develop a nation-state-level exploit in less than a day.”
A Security notified Zoom about the bug on June 10. Zoom acknowledged it the next day and deployed client-side and server-side fixes to mitigate the threat a few weeks later.
The video-conferencing service also published security bulletins noting that the vulnerability exists across all Zoom Workplace platforms prior to versions 7.1.5 and 7.0.6. “Users can help keep themselves secure by applying the latest updates,” Zoom adds.
This comes after Apple issued emergency macOS updates to fix a similar screen-sharing flaw that allowed attackers to view a user’s screen, open files, and launch apps.