Security
Zoom flaw exposed devices across every major platform
A Zoom flaw enabled silent code execution across iPhone, Mac, Windows, Linux and Android. Researchers found it with fewer than 20 AI prompts.
A Zoom vulnerability could have let an attacker remotely execute code on a meeting participant’s device—including an iPhone, Mac, Windows PC, Linux machine or Android device—without the victim clicking anything.
According to 9to5Mac, the flaw affected calls involving screen sharing. Both hosts and participants could be targeted through a silent attack with no visible indication or interaction. Cybersecurity firm A Security disclosed the vulnerability to Zoom, which has patched it.
The more unusual part of the disclosure is how the flaw was found. A Security researchers used publicly available AI models in early June 2026 and needed fewer than 20 prompts to uncover the vulnerabilities and produce a working attack.
“Before it would have taken a team of five people maybe six months with a lot of refining and iteration to find this. Now people can reach the same results with under 20 prompts. And Zoom is an important type of target because people assume trust when using it. They don’t see it as a threat.”
— Omer Gull, cofounder of A Security
The report does not identify a CVE number, affected Zoom version, or details about when the patch was distributed. It does establish the scope: every operating system supported by Zoom was potentially exposed when screen sharing was involved.