A dangerous Zoom screen-sharing bug could have let hackers hijack other devices on a call
Patch Zoom now or possibly pay a big price
by https://www.techradar.com/uk/author/sead-fadilpai · TechRadarNews By Sead Fadilpašić Published 12 August 2026
Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter
- AI‑found Zoom flaws enabled device takeover through malicious annotation messages
- Exploits worked across all platforms and required only joining a video call
- Researchers warn AI now enables rapid, nation‑state‑level exploit development
Experts have warned that Zoom, one of the most popular collaboration tools in the world, carried multiple vulnerabilities that allowed malicious actors to take over people’s devices, entirely.
What makes these vulnerabilities particularly dangerous is that the victims need not do much to be compromised - participating in a video call with the attacker is enough.
The bugs were said to be present in every version of Zoom, on every device and operating system - Windows, Mac, iPhone, Android, and Linux, in all versions up to and including 7.0.5 - with patches available now, so be sure to update immediately.
Latest Videos FromTechRadarWatch full video here:
AI-powered security
The flaws were discovered by security researchers A Security, which focuses on “autonomous offensive security”, using AI agents to simulate real-work attacks, identify vulnerabilities, and chain them into exploitable attack paths.
The company “simply” used publicly available frontier models and within 24 hours and fewer than 20 prompts, went from finding the flaws to building a working exploit.
The flaws are described as memory corruption bugs exploiting Zoom’s annotation feature. That feature, built on a proprietary protocol (meaning it has no public documentation or specifications, as opposed to being open source), meant that the Zoom client parsed everything it received, including specially crafted, malicious messages.
During the call, a malicious actor could send a message to each visitor that would corrupt their device’s memory and execute weaponized code, all without the victim knowing, being prompted to do anything, or clicking anything at all.
Are you a pro? Subscribe to our newsletter
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
Contact me with news and offers from other Future brandsReceive email from us on behalf of our trusted partners or sponsors