A major security vulnerability in Zoom’s screen-sharing annotation feature allowed attackers to execute code remotely and take over participants’ devices silently, without requiring any action or showing signs of compromise, researchers said [1, 2, 3].
Cybersecurity firm A Security discovered the flaw in early June 2026. Using fewer than 20 prompts on publicly available AI models, the team was able to create a working exploit in under a day—a task they said once required elite state-level teams months of effort and substantial budgets [1, 2, 3]. Idan Levcovich, an A Security researcher, explained, "Producing a working exploit has always been nation-state work: elite teams, months of effort, budgets that governments regulate as weapons. A Security did it in a single day, with an AI agent and models anyone can access today" [1].
The vulnerability affected all Zoom Workspace versions on Windows, macOS, Linux, iOS, and Android prior to the fixes [1, 2, 3]. It targeted the annotation feature, which lets users draw on shared screens during meetings, enabling silent remote code execution and device control [1, 2].
Zoom released security patches addressing both server-side and client-side components of this vulnerability on August 11, 2026, providing fixes for all supported platforms [1, 2, 3]. Omer Gull, cofounder of A Security, noted the shifting risk landscape: "Before it would have taken a team of five people maybe six months with a lot of refining and iteration to find this. Now people can reach the same results with under 20 prompts. And Zoom is an important type of target because people assume trust when using it. They don’t see it as a threat" [2].
The extent of any exploitation in the wild before disclosure and patching remains unknown [3]. The discovery also highlights rising risks from AI-enabled automated bug hunting and the democratization of exploit development, which previously required resources limited to nation-state actors [2, 3].
Users and organizations are urged to update Zoom to the August 11 patched versions to prevent potential attacks exploiting this critical vulnerability.