Skip to content

Zoom Bug Could Let Attackers Take Full Control of Your Device During a Call

Zoom Bug Could Let Attackers Take Full Control of Your Device During a Call

Cybersecurity researchers have uncovered a serious vulnerability (CVE-2026-53413) in Zoom’s screen-sharing feature that could allow attackers to take full control of a victim’s device during a call. The attack required no action from the user and reportedly provided no visible warning. The flaw affected the Zoom Workspace app on Windows, macOS, iOS, Android, and Linux. Zoom has since released a fix, although there is no indication yet that the vulnerability was exploited in real-world attacks.

The problem sits inside Zoom’s annotation tool, which people can use during a screen-sharing session. An attacker could abuse the flaw to run malicious code on someone else’s computer and gain full access to the device. The worrying part is that the victim doesn’t have to click anything, and Zoom doesn’t show a warning when it happens.

Zoomsday Infection

The cybersecurity company that discovered the flaw said attacks of this level were once largely limited to nation-state groups. According to the company, developing such exploits previously required highly skilled teams, months of work, and enormous budgets. That barrier appears to be shrinking, with one researcher reportedly able to create an exploit with nation-state-level capabilities in less than a day.

The company said AI prompts helped its researchers build the screen-sharing exploit in just a day. The example shows how generative AI can make it much faster to develop attacks that would normally take far more time and expertise.

Zoom was informed about the vulnerability and has since rolled out fixes for its applications. A company spokesperson urged users to install the latest updates to stay protected. The flaw affects Zoom Workspace versions released before the latest security patches, and researchers recommend updating as soon as possible to prevent potential attacks.

There is currently no evidence that the zero-interaction exploit has been used in real-world attacks. Still, the findings highlight how AI is making sophisticated exploits easier to develop, putting more pressure on software companies to respond quickly and users to keep their devices updated.

Maybe you would like other interesting articles?

Leave a Reply

Your email address will not be published. Required fields are marked *