Zoom fixes screen-sharing flaw allowing device takeovers during calls
A security flaw in Zoom's screen-sharing feature allows malicious users to take control of another participant's device without their consent, affecting multiple operating systems. Zoom has issued upโฆ
Researchers uncovered a significant security vulnerability in Zoom's screen-sharing feature that allows malicious users to take control of another participant's device during a call. This flaw affects the Zoom Workspace app across multiple operating systems, including Windows, Mac, iOS, Android, and Linux. The bug can be exploited without any action needed from the victim, and there are no visible warnings to alert users of the threat.
The discovery comes at a time when cybersecurity concerns are heightened, as remote work and virtual meetings have become the norm. The researchers demonstrated how quickly this vulnerability could be exploited, using AI prompts to create the exploit in under 24 hours. They noted that such capabilities, which were once limited to state-sponsored hackers with extensive resources, are now accessible to individual researchers, raising alarms about potential increases in cyberattacks.
In response to the findings, Zoom has rolled out fixes to address the issue, urging users to update their apps to the latest versions to mitigate risks. The vulnerability existed in all Zoom Workspace versions prior to the updates. Apple has also taken action; the company released security updates for macOS to close similar vulnerabilities, specifically in versions Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9.
This incident underscores the evolving landscape of cybersecurity threats, where even widely-used platforms like Zoom can harbor significant risks. As more individuals and organizations rely on virtual communication tools, the importance of regular software updates and awareness of potential vulnerabilities cannot be overstated. The incident serves as a reminder that users must remain vigilant and proactive in safeguarding their digital environments.
Read Full Story at Engadget โ


