Zoom has patched a screen-sharing vulnerability that researchers said could have allowed an attacker on a call to take over another participant’s device without a warning or further action from the victim, according to Wired and Engadget. Wired reports that researchers at the digital defense firm A Security disclosed the flaws Tuesday after finding them in early June. The issue sat in the protocol Zoom uses for real-time annotation during screen sharing, a feature that lets users mark up shared content during a call. Engadget similarly reports that exploitation was tied to Zoom’s screen-sharing function and the annotation tool. The reported impact was broad. Wired says devices running every operating system Zoom supports were affected: Windows, macOS, Linux, iOS, and Android. Engadget describes the affected software as Zoom Workspace apps for Windows, Mac, iOS, Android, and Linux, and says the vulnerability existed in versions before the latest updates. The mechanics matter because the attack did not depend on the target clicking a link, opening a file, or approving a prompt. Wired reports that anyone on a call involving screen sharing — host or participant — could have been vulnerable to a silent attack. Engadget reports the same essential behavior: no victim interaction and no visible warning. Zoom has issued fixes. Wired says the company published a security advisory Tuesday and began rolling out both server-side and client-side patches, meaning fixes on Zoom’s infrastructure as well as updates to the applications running on customer devices. Engadget reports that Zoom was notified and deployed mitigations, and says users can help protect themselves by installing the latest updates. A second part of the story is how the vulnerability was found. Wired reports that A Security used publicly available AI models and needed fewer than 20 prompts to uncover the bugs and produce a working attack. Engadget reports that the researchers used AI prompts to develop the exploit in under 24 hours. The researchers framed the episode as evidence that AI systems are lowering the skill and time required for vulnerability discovery and exploit development. There is no public confirmation in the provided reports that the flaw was exploited in the wild. Engadget says it remains unclear whether attackers ever used the vulnerability against real targets. Wired says Zoom did not respond to multiple requests for comment about A Security’s findings, while Engadget says Zoom advised users to apply the latest updates. The practical takeaway is narrower than the headline risk, but still serious: the issue is fixed, yet unpatched clients remain the exposure point. For organizations that use Zoom for internal meetings, webinars, sales calls, and semi-public events, the trust model around simply joining a call becomes part of the security surface when screen sharing is active. Who benefits: Zoom users who install the latest updates benefit from the fixes already issued. Security teams also gain a concrete case study for treating conferencing clients as high-priority software in patch programs. Who's exposed: Users and organizations running Zoom versions prior to the latest updates remain the clearest exposed group, according to Engadget’s description of affected versions. The provided reports do not establish exploitation in the wild.