Zoom Fixed a Security Hole That Let Hackers Take Over Your Device During a Meeting

Zoom has fixed a security flaw in its screen-sharing annotation feature that let an attacker take control of a participant's device during an active meeting. The victim did not need to click anything or do anything wrong, and there was no visible sign that the device had been compromised. The fix covers Zoom on Windows, macOS, Linux, Android, and iOS, and is documented in Zoom's security bulletin ZSB-26015 (Zoom Security Bulletin).
Security researchers at the firm A Security discovered the flaw using fewer than 20 prompts sent to publicly available AI models. Idan Levcovich, a vulnerability researcher at A Security, described the findings in a blog post. According to Levcovich, finding and building a working attack for this type of flaw had previously required the resources of a nation-state. A Security completed it in a single day using an AI agent and publicly accessible models (The Verge).
The exploit targeted Zoom's annotation feature, which lets users draw on their screen while sharing it with other meeting participants. By joining or hosting a meeting, an attacker could use the flaw to run malicious code on victims' devices. The consequences were broad: stealing data, secretly turning on the camera or microphone, and installing malware were all possible. A Security reported that the attack required no action from victims and produced no visual cue signaling the compromise (A Security).
Wired reported A Security's findings earlier, before The Verge's coverage on August 11, 2026 (The Verge).
The reach of this flaw is worth noting. Because it affected all five major desktop and mobile operating systems, essentially every Zoom device in use was exposed. The annotation feature is turned on by default in many meeting setups, especially in education and collaborative work, which widens the window of risk between when the flaw was discovered and when people actually install the fix.
Levcovich's claim about how much easier this has become deserves scrutiny on its own terms. If building this kind of attack previously required nation-state resources and AI compressed that to a single day, the fair comparison is not to security research in general but to this specific type of flaw. The annotation feature handles graphical input shared between meeting participants who may not trust each other; finding a weakness there would typically require deep, specialized knowledge of how Zoom's software processes and displays that input internally. An AI agent completing that work with under 20 prompts suggests the models did something meaningful — not just blindly testing random inputs to see what breaks, but actually helping with the discovery and exploitation process.
The broader context here is not that AI has suddenly made finding security flaws easy. It is that the cost of finding certain types of flaws has dropped measurably, and the barrier has shifted from needing highly specialized expertise to knowing how to effectively direct an AI agent. For a platform with Zoom's enormous user base, that cost reduction matters even for a single flaw, because the number of people capable of finding the next one has grown. Security teams that have historically judged how urgently to apply patches based on how likely someone else might independently find the same flaw may need to rethink that calculus. The gap between when a vulnerability exists and when it gets exploited has always been the critical metric, and AI-assisted discovery shortens that gap.
Zoom acted to patch the flaw, and the bulletin is now public. The practical question for organizations is how fast they can install the update across all their devices, particularly mobile phones where updates are often slower and less controlled. The annotation feature can also be turned off by administrators as a temporary safeguard for organizations that cannot deploy the patch immediately.
What this incident makes possible, in the most constructive sense, is a clearer empirical baseline. A Security has provided a concrete data point: under 20 prompts, one day, publicly available models, a working attack on a real vulnerability in widely used software. That is a more useful input for security planning than abstract worries about AI and cybersecurity. Security teams can work with numbers, even preliminary ones. Vague alarm cannot.

