No links to click, no files to download, not even a warning popup on screen — that's how quietly this Zoom Workspace vulnerability could operate, according to the security researchers who found it. All it took was someone activating the "annotation" tool during a screen-share call, and an attacker could remotely execute malicious code on their device — essentially handing over full control of the computer. The flaw affects Zoom Workspace across Windows, Mac, iOS, Android, and Linux, meaning users on virtually every platform were exposed.
What's even more alarming than the vulnerability itself is how it came to exist. The security team that discovered it says they built an exploit of this caliber using AI prompts in under 24 hours. As the team put it in their blog post: "Capabilities that once required elite teams, months of effort, and immense budgets — the kind of resources typically reserved for nation-state hacking groups — have now collapsed. Today, one person can develop a nation-state-level exploit in a single day." There's currently no evidence the vulnerability has been exploited in real-world attacks.






