Zoom Annotation Flaws Enabled Hijacking, Exploited via AI in Under a Day
Thionne_WTZ · x · 2026-08-12
Security researchers discovered three flaws in Zoom's screen annotation feature that allowed an attacker to hijack other attendees' computer clients during a meeting without requiring any clicks or downloads from the victim.
The uncovering firm, "A Security," revealed they developed a working exploit in under a day using fewer than 20 prompts directed at publicly available AI models, though the specific model was not named. Zoom shipped patches in June and July, and no active exploitation has been reported thus far.
Related event: AI Cracks Zoom Zero-Click Vulnerability in Under 20 Prompts(2 posts)→
More from Safety
- New Approach for Open Weights: Embedding Fingerprints Directly into Model Weights — 0xsachi · 2026-08-13
- Realtek IoT SDK Buffer Overflow Vulnerability Disclosed with PoC — evilsocket · 2026-08-13
- AI Paper Trail Reads Your AI Chats to Build Detailed Privacy Profile — RSync25 · 2026-08-13
- How to Safely Isolate AI Coding Agents Locally — aj_kt · 2026-08-13
- AI Labs and Data Providers Go to New Lengths for Training Data — steph_palazzolo · 2026-08-13
- Preventing Silent MCP Drift: Open-Source Local Security Tool HOL Guard — kantorcodes1 · 2026-08-13