From PC Mag: Researchers at A Security have discovered a critical bug in Zoom that allows attackers to assume full control of a participant’s device by exploiting a flawed screen-sharing function.
The vulnerability exists in the Zoom Workspace app for Windows, Mac, iOS, Android, and Linux. When a user launches the annotation tool while sharing their screen, the bug allows attackers to remotely execute malicious code and access participants’ devices. The attack requires no action from a victim’s end and leaves no visible warning, A Security says in its blog post.
The firm discovered the bug and developed a working exploit for it in just 24 hours. They did it using just 20 prompts on a publicly available AI model, highlighting how AI can make cyberattacks easier to carry out.
View: Full Article