None
DE
Researchers found a way to hijack devices through Zoom screen sharing
[]
Ars Technica
Anyone on a call that involved screen sharing, whether participants or the host, would have been vulnerable to a silent attack that could be carried out with no indication and no interaction from the victim.
Zoom issued a security advisory on Tuesday, including details about fixes the company has already begun rolling out to address the flaws, which affected devices running all operating systems that Zoom supports—Windows, macOS, Linux, iOS, and Android.
And Zoom is an important type of target because people assume trust when using it.
The vulnerabilities were specifically in the protocol used to facilitate real-time annotation during screen sharing.
The researchers say that their AI bug hunting systems specifically delved into this component because, like human bug hunters, they have been trained that convoluted and obscure functions often contain overlooked vulnerabilities.