The security breach centered on Zoom’s screen-sharing annotation feature. By manipulating this function, an attacker could silently gain control of a victim's device, enabling unauthorized access to cameras, microphones, or sensitive data. The compromise occurred without alerting the user, leaving no visual trace of the intrusion.
Idan Levcovich, a researcher at A Security, noted that creating such an exploit previously demanded the resources of nation-state actors and months of intensive development. His team condensed that timeline into a single day using an AI agent. Zoom deployed a patch on Tuesday to address the flaw across Windows, macOS, Linux, Android, and iOS, effectively neutralizing the threat to the platform's global user base.

Comments (0)
No comments yet. Be the first!