
A recently discovered security flaw in online meeting platform Zoom could reportedly let attackers remotely take over devices. Digital criminals could use the security loophole to run code on devices used by people in a meeting, including iPhones and Macs. It reportedly affected calls and meetings where the screen-sharing feature was active. The worst part is that the flaw could be exploited without the victim clicking anything or seeing a warning.
Zoom patches a critical flaw that could let attackers take over devices
The security vulnerability was discovered by the cybersecurity firm A Security back in June. The flaw came to light when the researchers were examining Zoom using the publicly available AI models. The team needed fewer than 20 prompts to identify the vulnerabilities and develop a working attack. The company then shared the issue with Zoom, which has since released a patch to fix the problem.
What’s interesting in this particular case is the speed of discovery. In usual cases, finding a vulnerability of this kind previously could have required months of work by a larger security team. But thanks to AI, the critical security flaw was discovered in just a few minutes or hours of work.
The flaw worked across Android, iOS, macOS, and Windows
The most dangerous part of the flaw was that it could work across all the popular operating systems, such as macOS, Windows, iPhones, and even Android. Moreover, anyone on the call, be it a participant or the organizer, could have been exposed. The attack could be carried out without any interaction. Meaning, the user would remain unaware of the ongoing attack.
Omer Gull, co-founder of A Security, told Wired that similar work could previously have taken a team of five people around six months, including repeated testing and refinement. He said the finding shows how publicly available AI tools can reduce the time needed to identify weaknesses. Lastly, he added that Zoom was an important target because users generally trust the platform and do not expect a normal meeting to pose a security threat.
The post Researchers Uncover Zoom Flaw That Could Let Attackers Control Devices appeared first on Android Headlines.
​Â