{"id":52933,"date":"2026-08-17T13:41:40","date_gmt":"2026-08-17T17:41:40","guid":{"rendered":"https:\/\/mjtsai.com\/blog\/?p=52933"},"modified":"2026-08-17T13:41:40","modified_gmt":"2026-08-17T17:41:40","slug":"zoom-screen-sharing-attack","status":"publish","type":"post","link":"https:\/\/mjtsai.com\/blog\/2026\/08\/17\/zoom-screen-sharing-attack\/","title":{"rendered":"Zoom Screen Sharing Attack"},"content":{"rendered":"<p><a href=\"https:\/\/www.wired.com\/story\/a-zoom-screen-sharing-bug-let-anyone-take-over-other-devices-on-a-call\/\">Lily Hay Newman<\/a> (via <a href=\"https:\/\/9to5mac.com\/2026\/08\/11\/zoom-flaw-let-an-attacker-take-over-your-device-including-iphone-and-mac\/\">Ben Lovejoy<\/a>):<\/p>\n<blockquote cite=\"https:\/\/www.wired.com\/story\/a-zoom-screen-sharing-bug-let-anyone-take-over-other-devices-on-a-call\/\">\n<p>As AI models gain advanced <a href=\"https:\/\/www.wired.com\/story\/anthropics-mythos-will-force-a-cybersecurity-reckoning-just-not-the-one-you-think\/\">capabilities<\/a> to find vulnerabilities in software, develop <a href=\"https:\/\/www.wired.com\/story\/openai-didnt-notice-its-ai-agents-using-a-message-board-to-plan-their-hacking-spree\/\">ways to exploit them<\/a>, and even carry out autonomous <a href=\"https:\/\/www.wired.com\/story\/openai-anthropic-ai-hacking-sprees-illegal\/\">hacking sprees<\/a>, researchers offered a sobering new example on Tuesday, <a href=\"https:\/\/a.security\/blog\/asecurity-zoomsday\">disclosing vulnerabilities<\/a> in the video conferencing platform Zoom that could have been exploited to take over targets&rsquo; devices. Anyone on a call that involved screen sharing, whether participants or the host, would have been vulnerable to a silent attack that could be carried out with no indication and no interaction from the victim.<\/p>\n<p>Researchers from the digital defense firm A Security say the <a href=\"https:\/\/www.zoom.com\/en\/trust\/security-bulletin\/zsb-26015\/\">bug<\/a> was discovered in early June using publicly available AI models, and that it took fewer than 20 prompts to uncover the vulnerabilities and create a working attack. Zoom issued a security advisory on Tuesday, including details about fixes the company has already begun rolling out to address the flaws, which affected devices running all operating systems that Zoom supports&mdash;Windows, macOS, Linux, iOS, and Android.<\/p>\n<p>[&#8230;]<\/p>\n<p>The vulnerabilities were specifically in the protocol used to facilitate real-time annotation during screen sharing.<\/p>\n<\/blockquote>\n\n<p>I don&rsquo;t understand how it could take over an iOS device when Zoom&rsquo;s iOS screen sharing feature only allows observation, not control.<\/p>\n\n<p>Previously:<\/p>\n<ul>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2026\/08\/07\/macos-tahoe-26-6-1\/\">macOS 26.6.1<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2020\/05\/07\/zoom-security-improvements\/\">Zoom Security Improvements<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2020\/04\/10\/every-zoom-security-and-privacy-flaw-so-far\/\">Every Zoom Security and Privacy Flaw So Far<\/a><\/li>\n<\/ul>","protected":false},"excerpt":{"rendered":"<p>Lily Hay Newman (via Ben Lovejoy): As AI models gain advanced capabilities to find vulnerabilities in software, develop ways to exploit them, and even carry out autonomous hacking sprees, researchers offered a sobering new example on Tuesday, disclosing vulnerabilities in the video conferencing platform Zoom that could have been exploited to take over targets&rsquo; devices. [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"apple_news_api_created_at":"2026-08-17T17:41:46Z","apple_news_api_id":"7302db6a-463e-47b8-8d4d-16bca0c862f3","apple_news_api_modified_at":"2026-08-17T17:41:46Z","apple_news_api_revision":"AAAAAAAAAAD\/\/\/\/\/\/\/\/\/\/w==","apple_news_api_share_url":"https:\/\/apple.news\/AcwLbakY-R7iNTRa8oMhi8w","apple_news_coverimage":0,"apple_news_coverimage_caption":"","apple_news_is_hidden":false,"apple_news_is_paid":false,"apple_news_is_preview":false,"apple_news_is_sponsored":false,"apple_news_maturity_rating":"","apple_news_metadata":"\"\"","apple_news_pullquote":"","apple_news_pullquote_position":"","apple_news_slug":"","apple_news_sections":"\"\"","apple_news_suppress_video_url":false,"apple_news_use_image_component":false,"footnotes":""},"categories":[2],"tags":[1351,131,2095,31,2741,26,30,32,2742,1601,1608,1839],"class_list":["post-52933","post","type-post","status-publish","format-standard","hentry","category-technology","tag-artificial-intelligence","tag-bug","tag-exploit","tag-ios","tag-ios-26","tag-iosapp","tag-mac","tag-macapp","tag-macos-tahoe-26","tag-screen-sharing","tag-secure-boot","tag-zoom"],"apple_news_notices":[],"_links":{"self":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/52933","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/comments?post=52933"}],"version-history":[{"count":1,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/52933\/revisions"}],"predecessor-version":[{"id":52934,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/52933\/revisions\/52934"}],"wp:attachment":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/media?parent=52933"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/categories?post=52933"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/tags?post=52933"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}