A Zoom Screen-Sharing Bug Let Anyone Take Over Other Devices on a Call
A critical zero-click vulnerability in Zoom's screen-sharing feature allowed attackers to take remote control of participant devices.
Velocity
How fast coverage is spreading — measured hourly from article rate × source diversity. How this works →
The brief
A severe security vulnerability has been identified in Zoom's screen-sharing functionality, enabling attackers to take over devices belonging to other participants on a call. According to reports from WIRED and 9to5Mac, the flaw allowed for the takeover of various hardware, specifically including Macs and iPhones. This vulnerability is categorized as a zero-click flaw, meaning it could be exploited without requiring any specific action or interaction from the victim during a meeting. The flaw facilitated remote code execution, or RCE, which granted attackers a high level of control over the targeted devices while they were active in a Zoom call. Coverage of the incident is widespread across multiple technology and security publications. SecurityWeek reports that Zoom has already issued patches to address the zero-click code execution vulnerability.
Meanwhile, CyberInsider emphasizes the nature of the flaw as an RCE attack vector that occurred during active meetings. The Verge has highlighted a specific aspect of the discovery, noting that the hack—which they refer to as the 'Zoomsday' hack—was uncovered using fewer than 20 AI prompts. These outlets collectively present the bug as a significant failure in the software's security architecture regarding how screen-sharing is handled. This incident is particularly noteworthy due to the 'zero-click' nature of the attack, which represents a higher tier of security risk than traditional phishing or social engineering. By allowing remote code execution, the bug bypassed typical user warnings or consent screens that usually accompany screen-sharing requests. The fact that iPhones and Macs were specifically mentioned by 9to5Mac indicates that the vulnerability crossed platform boundaries, affecting both desktop and mobile operating systems.
The context provided by The Verge regarding the use of AI prompts suggests that automated tools are becoming more efficient at discovering critical vulnerabilities in enterprise software. Moving forward, the primary focus for users is the deployment of the patches mentioned by SecurityWeek. Because the flaw allowed for the complete takeover of devices, organizations using Zoom for secure communications must ensure all client versions are updated. While the vulnerability has been patched, the details surrounding the 'Zoomsday' hack and the role of AI in its discovery remain key points of interest. Further updates will likely center on whether other similar zero-click flaws exist within the screen-sharing protocols of other video conferencing platforms, though current coverage is focused solely on the Zoom resolution.
Synthesized by PULSE from the headlines below under a strict no-invention contract. ✓ fact-checked: all claims supported by sources Updated 1h ago.
Quick answers
Which devices were affected by the Zoom bug?
According to 9to5Mac, the flaw allowed attackers to take over devices including iPhones and Macs.
What is a zero-click flaw?
As reported by CyberInsider and SecurityWeek, it is a vulnerability that allows for remote code execution without requiring the victim to interact with the attack.
How was the 'Zoomsday' hack discovered?
The Verge reports that the hack was uncovered using fewer than 20 AI prompts.
Coverage (5)
- Zoom zero-click flaw allowed RCE attacks during meetings CyberInsider · 7h ago
- Zoom Patches Zero-Click Code Execution Vulnerability SecurityWeek · 7h ago
- Zoom flaw let an attacker take over your device, including iPhone and Mac 9to5Mac · 7h ago
- ‘Zoomsday’ hack uncovered using fewer than 20 AI prompts The Verge · 7h ago
- A Zoom Screen-Sharing Bug Let Anyone Take Over Other Devices on a Call WIRED · 7h ago
Topics
Related trends
Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days
Microsoft has released its August 2026 Patch Tuesday updates, addressing 400 vulnerabilities including three actively exploited zero-day flaws.
New Pass-ta-key attack reveals all the things we didn’t know about passkeys
Hackers have identified vulnerabilities in passkeys synced to Google, challenging the premise that they represent a safer future for security.
OpenAI launches GPT-5.6-Cyber with reduced refusals, 95% completion on advanced cybersecurity tasks
OpenAI launches GPT-5.6-Cyber, achieving 95% completion on advanced cybersecurity tasks with reduced refusal rates.
A cybersecurity researcher covered a Toyota in an AI-generated pattern to confuse Flock cameras
A cybersecurity researcher cloaks a Toyota in AI‑generated camouflage to outwit Flock cameras, sparking tech‑media focus.
New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA
New vulnerabilities in passkey implementations across Windows and Google Chrome may allow attackers to recover private keys or bypass MFA protections.
OpenAI introduces a new cyber model amid fears of AI cyberattacks
OpenAI has launched a new cyber model to bolster defenses as concerns grow over the potential for AI-driven cyberattacks.