AI has turned vulnerability discovery from a craft into a prompt. The new unit of work is the conversation, and the new clock is days, not quarters. Tools that once took a five-person team half a year to find now surface to a single researcher in a single session, which means the next flaw in the next closed-source collaboration tool is no longer a question of if, only of when.
A Security's researchers found the chain inside Zoom's screen-sharing annotation protocol, a side channel in the call rather than the main video pipeline, exploitable without the victim clicking anything, using fewer than 20 AI prompts. The annotation layer is a trust surface most users did not know to vet, because it sits beneath the meeting's visible function. The exploit is interesting; the mechanism is what changes an operator's day. Collaboration tools that ship in closed builds may all carry similar hidden trust surfaces, a pattern visible wherever the cost of probing closed annotation layers has collapsed, and the cost of probing it has collapsed.
The reader's lever is concrete. Install Zoom's patches, then ask which side protocol in the next screen-share, whiteboard, or remote-control feature inherits the same trust. When the cost of finding a flaw falls by two orders of magnitude, which some security researchers argue could shift the audit calculus from the vendor to the user.
Reported by Sky for Type0, from Researchers found a way to hijack devices through Zoom screen sharing. Read the original: arstechnica.com