A Zoom Bug Let Callers Take Over Your Computer. Here's What to Do

Security researchers found a flaw in Zoom's screen-sharing feature that could let someone on a call with you take full control of your computer or phone. Zoom has fixed the problem and posted details in a security bulletin numbered ZSB-26015. The advice is simple: update Zoom now (Engadget, Zoom Security Bulletin ZSB-26015).
The problem was in the annotation tool, the set of drawing and marking tools that appears when someone shares their screen during a meeting. If a caller turned on that tool while sharing their screen, they could run hidden code on your device. You would not see a warning, get a prompt, or have to click anything. The attack would just happen, and the other person would have full access to your machine (Engadget).
The flaw affected the Zoom app on Windows, Mac, iPhone, Android, and Linux. Any version of Zoom that has not been updated is potentially at risk (Engadget, Zoom Security Bulletin ZSB-26015).
Most security flaws of this kind in collaboration software need the victim to do something, click a link, accept a file, approve a request. This one did not. The only condition was being on a call with someone who started screen sharing and opened the annotation tool. That is what makes this finding unusual: a standard, default feature became a way in with no action required from the person being attacked (Engadget).
The researchers also used AI tools to build a working version of the attack in under 24 hours. The annotation tool they targeted is a common feature that many people have turned on by default in their Zoom settings, which means the potential exposure was wide.
Zoom was notified and has released fixes. The company's security bulletin, ZSB-26015, is available on Zoom's trust and security portal and directs users to install the latest version of the Zoom app (Zoom Security Bulletin ZSB-26015).
For anyone managing Zoom for an organization, the task is to make sure every device on every platform is running the updated version. That includes Windows and Mac computers, but also iPhones, Android phones, and Linux machines. Phones are often the last to get updates in workplace settings, so it is worth checking rather than assuming they are covered.
The use of AI to build the exploit in under a day is worth pausing on. It means the gap between finding a bug and turning it into a working attack is getting shorter. This does not change what you need to do about this particular Zoom flaw, which is to patch immediately. But it does suggest that future security flaws in widely used software may become active threats faster than they used to.
There is also a broader question about how these features are set up. Screen sharing and annotation are core parts of Zoom, not optional extras. When a feature that is turned on by default becomes a way for someone to take over a device with no warning, it may be worth turning off annotation for people who do not need it. That reduces risk whether or not everyone has updated.
The fix is available now and the risk only applies to versions that have not been updated. If you can confirm that all your devices are running the latest Zoom app, you can consider this resolved.
There is a positive angle here too. The researchers found the flaw, told Zoom about it, and Zoom released a patch and made the details public. That process, responsible disclosure, is how security is supposed to work. The AI tools that helped build the exploit quickly also helped the researchers understand the problem faster. In this case, the people working to protect users moved first, and the fix is in place.


