Flaws in a video conferencing tool’s shared-screen annotation feature could have let anyone on a call take over the devices of everyone else watching, silently and without any interaction.
Researchers at A Security, an Israeli-founded offensive-security startup, found the bugs with help from an AI tool, according to reporting from Wired picked up by 9to5Mac. The disclosure landed August 11 as three vulnerabilities in Zoom Workplace, a cluster Malwarebytes dubbed Zoomsday.
Anyone sharing a screen could have been taken over by a viewer, and a viewer could have been taken over by the presenter. The attack needed nothing beyond being in the meeting: no click, no download, no prompt, and nothing on screen to reveal it. The apps run on iPhone, Mac, and other platforms.
The fixes were already in the wild before the research went public. Zoom updated its client software in June and July, roughly two months ahead of the disclosure, covering Zoom Workplace before 7.1.5 and 7.0.6, the VDI client before 7.0.11 and 6.6.16, and Zoom Rooms plus the Meeting SDK before 7.1.0.
No real-world abuse of any of the three has surfaced, and CISA’s registry of flaws already under attack lists none of them. The quiet stretch between Zoom shipping fixes and the public report is prime hunting ground for attackers who watch update logs, so stragglers on old builds should upgrade before their next meeting.