Security researchers have found a vulnerability in Zoom’s screen sharing feature. This flaw could let attackers gain control of a victim’s device. A publicly available AI tool detected this issue in fewer than 20 prompts.
The discovery, reported by Ars Technica, underscores two key concerns in today’s cybersecurity landscape: the persistent weaknesses in widely used software and AI’s growing capability to identify these weaknesses much faster than humans can.
What the Attack Actually Does
When you share your screen on Zoom, you broadcast a live feed of your display to other participants. But many don’t consider the data pipeline behind that feed. Researchers discovered that this pipeline can be exploited.
The attack takes advantage of how Zoom processes the shared screen data during a session. By sending specially crafted inputs through the screen sharing channel, an attacker could execute arbitrary code on the target’s device. In simple terms, someone in your Zoom call could run harmful programs on your computer without you needing to click anything.
Think of it this way: screen sharing is meant to be a one-way window — you show, and others watch. This vulnerability turns that window into a door.
How AI Found the Flaw So Fast
The most striking aspect of this discovery isn’t the vulnerability itself but how quickly it was found. Researchers used a publicly available AI tool that anyone can access, identifying the dangerous flaw in under 20 prompts. A “prompt” is just a text instruction given to an AI system.
This speed is crucial. Typically, security researchers spend days or even weeks manually reviewing code to find vulnerabilities. An AI that can uncover a critical flaw through a brief conversation changes the game for both security research and, more concerningly, malicious hacking. The same tool that helps defenders is also available to attackers.
This isn’t the first time we’ve seen AI assist in finding vulnerabilities. However, the combination of a high-profile target like Zoom and such a rapid discovery time shows us the direction things are heading.
Who Is at Risk
Zoom is one of the most widely used applications globally, serving businesses, schools, healthcare providers, and government agencies. Any user involved in screen sharing sessions — whether sharing or viewing — could be at risk, depending on how quickly Zoom addresses the issue and how fast users update their software.
Corporate environments face particular danger, as employees often share screens with sensitive documents, login portals, and internal tools during meetings with external participants.
| By The Numbers | |
|---|---|
| AI prompts needed to find the flaw | Fewer than 20 |
| Zoom monthly active users (as of recent reports) | ~300 million meeting participants/day (peak) |
| Attack vector | Screen sharing session |
| Type of access gained | Arbitrary code execution on target device |
What This Means for Everyday Users
If you use Zoom for work, school, or personal calls, here’s what you need to do right away:
- Update Zoom immediately. Open the app, click your profile picture, and select “Check for Updates.” Zoom usually releases patches quickly after a vulnerability is disclosed.
- Be cautious about who you screen share with. Avoid sharing screens with people you don’t trust completely, especially in meetings accessed through public links.
- Watch for a security advisory from Zoom. The company will likely issue a bulletin detailing which versions are affected and when the fix will roll out.
This type of vulnerability — triggered by screen sharing instead of clicking a malicious link — is tough for average users to guard against through their usual habits. Your best defense here is to keep your software updated.
Community Reactions
“The AI finding this in under 20 prompts is the real headline. Imagine what a well-resourced threat actor is doing with these tools right now.”
“Every company that uses Zoom for client calls needs to be reading this. Screen sharing was supposed to be the safe alternative to sending files.”
The Bigger Picture: AI and Security Research
This discovery comes at a time when AI is rapidly transforming possibilities in cybersecurity — both positively and negatively. Tools that help defenders find and fix vulnerabilities faster are incredibly valuable. But they also lower the entry barrier for attackers who might lack the deep technical skills needed to discover exploits in complex software.
Security teams at major software companies are increasingly racing against AI-powered adversaries. Incidents like this one indicate that this race is already in motion.
For more detailed information about the vulnerability, check out the full Ars Technica report.
What To Watch
- Zoom’s official response: Expect a security advisory and patched update soon. Keep an eye on Zoom’s security bulletin page for details on affected and fixed versions.
- Proof-of-concept disclosure: Researchers often wait around 90 days before revealing full technical details. Once that window closes, the risk to unpatched users increases sharply.
- AI vulnerability discovery becoming standard: This case might speed up discussions within major tech companies about using AI for internal security audits — before outside researchers or attackers find issues first.
- Regulatory attention: Given Zoom’s use in government and healthcare, agencies overseeing those sectors may weigh in on disclosure timelines and patching requirements.
Maya Torres
Maya Torres is the Consumer Tech Editor at Explosion.com with 7 years covering product launches for major technology publications. She has reviewed over 300 devices across smartphones, laptops, wearables, and smart home products. Maya specializes in translating spec sheets into real-world buying advice and attends CES, MWC, and Apple keynotes as press. Her reviews focus on helping readers decide what to buy, not just what specs look good on paper.
