← 返回 Avalaches

資安公司 A Security 的研究人員在 6 月初利用公開的 AI 模型,僅用了不到 20 次的提示,就在 Zoom 的視訊會議軟體中發現了嚴重的漏洞,並成功開發出攻擊手法。

這些漏洞存在於 Zoom 螢幕分享時的即時註記功能協定中。只要參與含有螢幕分享的視訊通話,無論是主辦人還是與會者,都可能在毫無察覺且無需任何互動的情況下遭到攻擊,甚至導致設備被完全控制。

Zoom 已在週二發布了安全公告,並開始針對所有支援的作業系統(包括 Windows、macOS、Linux、iOS 和 Android)推出伺服器端和客戶端修補程式以解決此問題。

Researchers from the cybersecurity firm A Security discovered severe vulnerabilities in the Zoom video conferencing software in early June by using publicly available AI models, developing a successful attack with fewer than 20 prompts.

The vulnerabilities were located in the protocol used for real-time annotation during screen sharing. Anyone participating in a call involving screen sharing, whether host or participant, could be attacked silently without any indication or interaction, potentially leading to complete device takeover.

Zoom issued a security advisory on Tuesday and has begun rolling out server-side and client-side patches for all supported operating systems, including Windows, macOS, Linux, iOS, and Android, to address the flaws.

2026-08-17 (Monday) · 8d817bf419bd8625cefe7533e114625a5cacbc56