Researchers found a way to hijack devices through Zoom screen sharing



As AI models gain advanced capabilities to find vulnerabilities in software, develop ways to exploit them, and even carry out autonomous hacking sprees, researchers offered a sobering new example on Tuesday, disclosing vulnerabilities in the video conferencing platform Zoom that could have been exploited to take over targets’ devices. Anyone on a call that involved screen sharing, whether participants or the host, would have been vulnerable to a silent attack that could be carried out with no indication and no interaction from the victim.

Researchers from the digital defense firm A Security say the bug was discovered in early June using publicly available AI models, and that it took fewer than 20 prompts to uncover the vulnerabilities and create a working attack. Zoom issued a security advisory on Tuesday, including details about fixes the company has already begun rolling out to address the flaws, which affected devices running all operating systems that Zoom supports—Windows, macOS, Linux, iOS, and Android.

“What is interesting for us and what we believe is dangerous is the democratization of these capabilities—the barrier to entry is dropping rapidly,” A Security cofounder Omer Gull told WIRED ahead of the disclosure. “Before it would have taken a team of five people maybe six months with a lot of refining and iteration to find this. Now people can reach the same results with under 20 prompts. And Zoom is an important type of target because people assume trust when using it. They don’t see it as a threat.”

The vulnerabilities were specifically in the protocol used to facilitate real-time annotation during screen sharing. The researchers say that their AI bug hunting systems specifically delved into this component because, like human bug hunters, they have been trained that convoluted and obscure functions often contain overlooked vulnerabilities. This is particularly true with proprietary, closed-source software. An established company like Zoom presumably does extensive code review and vetting on all components and functions, but without the benefit of public, open review, esoteric yet complex features like annotation are more likely to contain mistakes.



Source link

  • Related Posts

    Microsoft is combining its Copilot apps ahead of a ‘super app’

    Microsoft is finally beginning to combine its consumer and commercial Copilot AI assistants into a single “super app” interface, starting with the Copilot and Microsoft 365 Copilot apps. Both personal…

    Claude’s new Scarlet Letter watermark is invisible—for now

    “We’re adding marking to Claude’s output to comply with the EU AI Act, and other labs are taking similar steps,” Anthropic said. “It’s hard to identify AI-generated text, and this…

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    You Missed

    Chief calls for co-operation to prevent fires as world changes at a ‘rapid pace’

    Chief calls for co-operation to prevent fires as world changes at a ‘rapid pace’

    Microsoft is combining its Copilot apps ahead of a ‘super app’

    Microsoft is combining its Copilot apps ahead of a ‘super app’

    Did the eclipse damage your eyes? A surgeon explains

    Did the eclipse damage your eyes? A surgeon explains

    Halton police release new video of 3 men wanted in fatal 2025 shooting of Oakville business owner

    Halton police release new video of 3 men wanted in fatal 2025 shooting of Oakville business owner

    Apache Helicopter Crash Leaves 2 Soldiers Dead in Texas

    Apache Helicopter Crash Leaves 2 Soldiers Dead in Texas

    What Roma Can Expect From Nahuel Molina: An Atlético Perspective

    What Roma Can Expect From Nahuel Molina: An Atlético Perspective