An AI tool cracked Zoom’s screen-sharing in under 20 prompts—and now anyone can hijack your device on a call

11 Min Read

A public artificial intelligence tool discovered a critical Zoom vulnerability in fewer than 20 prompts—a flaw that allowed any participant on a call to silently hijack another person’s device.

The finding exposes a chilling reality: the barriers between casual users and sophisticated hacking have collapsed. What once required specialized knowledge, custom code, and months of reverse-engineering now takes a few typed requests to a chatbot. Zoom has patched the vulnerability, but the incident reveals how AI is democratizing the discovery and weaponization of security flaws at a pace that outstrips corporate patch cycles and user awareness.

Key Findings:
  • Speed of Discovery: A publicly available AI model identified a critical Zoom vulnerability in fewer than 20 prompts—a process that previously required weeks of specialized manual analysis.
  • Scope of Exposure: The flaw required no special privileges or social engineering, meaning any malicious participant on an active call could silently gain full device control over another user.
  • Systemic Acceleration: Research confirms that large language models can now automate vulnerability detection at scale, compressing the window between a flaw’s existence and its discovery to hours rather than months.

Researchers discovered that the screen-sharing feature in Zoom contained a logic flaw that could be exploited to grant unauthorized control of a participant’s machine. The attack required no special privileges, no social engineering, and no prior access—only presence on an active call. An attacker could trigger the vulnerability through a sequence of screen-sharing interactions that would appear innocuous to other participants, then gain full device control without triggering alerts or requiring the victim’s consent.

The speed of discovery matters. Fewer than 20 prompts to a publicly available AI model was sufficient to identify the flaw. That’s not a theoretical exercise conducted by a well-funded security firm over weeks. That’s a proof-of-concept that any person with internet access and basic prompt-engineering skills could replicate in an afternoon. The researchers did not name the specific AI tool, but the implication is stark: commodity large language models trained on code repositories and security documentation can now function as automated vulnerability scanners. Research into LLMs in code vulnerability analysis has demonstrated that both code-specific and general-purpose language models can automate critical security tasks that once demanded expert human review.

How Does AI Turn a Video Call Into a Device Takeover?

Zoom released a patch addressing the issue, and the company has not made a detailed public statement about the scope of exploitation or whether the flaw was actively abused in the wild before the fix. What is confirmed: the vulnerability existed, it was discoverable by AI in near-real-time, and it could have allowed attackers to pivot from a video call into full device compromise—the kind of lateral movement that transforms a meeting into a beachhead for data theft, ransomware deployment, or surveillance.

For Zoom users, the practical implication is immediate. Your device was exposed not because you clicked a malicious link or downloaded infected software, but because you joined a video call with someone who may have harbored malicious intent. The screen-sharing feature—a staple of remote work, education, and healthcare—became a vector for silent takeover. Zoom’s patch closes this specific door, but the underlying pattern remains: features designed for convenience and transparency can be weaponized when security assumptions fail.

By the Numbers:
• Fewer than 20 AI prompts were sufficient to identify a critical, remotely exploitable vulnerability in a platform used by hundreds of millions of people
• The average enterprise organization takes weeks to deploy patches for critical flaws—a window that AI-assisted discovery compresses dramatically on the attacker’s side
• Security researchers have documented that defenders face a structural disadvantage: attackers need to find one flaw, while defenders must protect against all of them simultaneously

Why Does This Mirror the Cambridge Analytica Playbook?

This incident mirrors a structural vulnerability that defined the Cambridge Analytica scandal: the exploitation of a system designed for legitimate use to gain unauthorized access to private data and behavior. In Cambridge Analytica’s case, researchers used Facebook’s API—a tool meant for app developers—to harvest psychological profiles from millions of users without their knowledge. The mechanism was different, but the principle was identical: a feature intended for one purpose became a lever for mass surveillance. Here, screen-sharing becomes a device-hijacking tool. Understanding the legacy of Cambridge Analytica makes this pattern immediately recognizable: legitimate infrastructure, repurposed at scale, with users entirely unaware of the exposure.

The democratization vector is also parallel. Cambridge Analytica’s initial data harvesting relied on a single researcher and a relatively simple application of existing APIs—no sophisticated technical apparatus, just a creative misuse of available tools. Today, an AI model does the work of discovering the vulnerability itself, compressing the timeline from months to minutes. What Cambridge Analytica demonstrated about the weaponization of human data through platform features applies directly here: the most dangerous exploits are often the ones hiding inside tools people trust.

Is the Security Industry Moving Fast Enough to Respond?

The research team did not disclose the specific prompts or methodology used to discover the flaw, a responsible choice that prevents immediate copycat attacks while the patch propagates. However, the fact that the discovery was possible at all suggests that AI-assisted vulnerability research is now a viable attack surface. A comprehensive review of artificial intelligence in cybersecurity published in a peer-reviewed journal documents how researchers are already using AI-based techniques to discover vulnerabilities in software and hardware interfaces—a capability that is now accessible far beyond specialized research institutions.

Zoom’s response—patching the vulnerability—is standard practice. The company has not disclosed whether it conducted a full audit of screen-sharing logic or whether other similar flaws exist. The patch is available, and Zoom users should ensure their client is updated to the latest version. However, the incident raises a question that no single company can answer: if a public AI tool can discover a critical vulnerability in under 20 prompts, how many other flaws exist in widely used software that are waiting for the same treatment?

What Research Shows:
A 2025 study presented at the IEEE/ACM International Conference on Software Engineering examined the real-world usefulness of AI-assisted vulnerability detection, finding that automated tools are closing the gap between theoretical capability and practical deployment in security workflows
• Large language models have demonstrated the ability to identify statement-level vulnerabilities in code—the same granularity required to find logic flaws like the one exploited in Zoom’s screen-sharing feature
• The research consensus points toward a future where AI-assisted security testing is standard on both sides of the attacker-defender divide, with the advantage accruing to whichever side adopts the tools more aggressively

What Does This Mean for Every Platform You Use?

The timeline of vulnerability discovery is accelerating. In the era of manual code review and academic research, a flaw like this might have remained unknown for years, or until a sophisticated attacker stumbled upon it. Now, the discovery window has compressed to hours or days after deployment. Patch management, already a chronic weakness in enterprise and consumer security, faces a new pressure: vulnerabilities are being found faster than they can be fixed and deployed. The average organization takes weeks to patch critical flaws; the average AI model takes minutes to find them.

For security teams at Zoom and other communication platforms, this incident is a forcing function. It means that the assumption of gradual, researcher-led vulnerability disclosure is obsolete. Attackers with access to commodity AI tools can now conduct automated security testing at scale. The only defense is to adopt the same tools internally—to use AI to find flaws before attackers do—or to accept that the window of vulnerability will only shrink further. The same dynamic applies to encrypted communication tools, where encrypted communication vulnerabilities have repeatedly proven that security theater and genuine protection are not the same thing.

Zoom has not announced a formal AI-assisted security audit program, though the company’s engineering teams likely use automated testing tools already. What remains unclear is whether the company will adopt a more aggressive posture toward proactive vulnerability discovery, or whether it will continue to rely on patches released after flaws are reported.

For the broader ecosystem, the lesson is uncomfortable. The Zoom screen-sharing vulnerability is not an anomaly; it’s a preview. As AI models become more capable at code analysis and security testing, the population of discoverable flaws will expand, and the time to discovery will contract. The defenders—Zoom, Microsoft, Apple, and thousands of smaller software companies—are not moving faster. They are moving at the same pace they always have. The attackers, now augmented by AI, are accelerating. That gap will define the security landscape for the next five years.

The patch is available now. Your Zoom client should update automatically, but checking your settings to confirm the latest version is installed is prudent. More broadly, the incident is a reminder that no communication platform is a neutral tool—each one is a potential attack surface, and each one is being probed by both defenders and attackers with increasing sophistication and speed.

Share This Article
Miora Danielle Raveloarison is a journalist at CA Privacy Watch covering surveillance, data privacy and the human impact of technology. A graduate of the Catholic University of Madagascar with a background in the social sciences, she has spent over a decade turning complex subjects into clear, engaging reporting, and brings a humanistic lens to questions of privacy, AI and digital rights.