Written by
Peter Prieto, Cybersecurity Expert

Zoom flaws let a meeting participant hijack another attendee's computer just by using the annotation feature. Anyone sharing their screen on a call could have had their machine taken over by another attendee abusing the annotation tools, no separate exploit needed, according to The Hacker News.
Read that again. No malware. No phishing link. No suspicious attachment. Just a built-in feature that almost everyone has used at some point, the little pen and highlighter tool that lets meeting participants draw on a shared screen, turned into a way to take control of someone else's device.
Why This One Is So Easy to Overlook
Video calls occupy a strange blind spot in most people's mental model of security risk. Email gets scrutinized. Links get hovered over. Attachments get treated with suspicion. A video call, by comparison, feels inherently safe, you can see who is on it, you know their names, maybe you even recognize their voice. That sense of visibility creates a false sense of control.
Screen sharing compounds this. The moment someone shares their screen, they have already extended a certain amount of trust to everyone else in the call. The annotation feature exists specifically to make that collaboration easier, so a colleague can circle something on a shared spreadsheet or point out a typo on a slide. It is a genuinely useful feature, which is exactly what made it a viable attack path. Nobody thinks twice about a tool designed for pointing and highlighting, which is precisely why a flaw in how it handles permissions could let it be abused for something much more serious, taking control of the presenter's device entirely.
What Makes This Different From a Typical Exploit
Most of the vulnerabilities that make security news involve some technical sophistication, a crafted payload, a memory corruption bug, a chain of exploits strung together. This one is notable for how little sophistication it required. The attack surface here was a feature working exactly as designed, just without adequate boundaries on what a meeting participant could do with it during someone else's screen share.
That is a useful distinction to sit with. A flaw in a built-in collaboration feature does not require the attacker to write anything malicious at all. It just requires the software to have insufficiently guarded what a normal feature is allowed to do, and a participant willing to use that feature the way it was never intended to be used.
What This Means for Your Business
Confirm your video conferencing software is fully updated before your next screen-share-heavy meeting. Patches for flaws like this one are only protective once they are actually installed, and update reminders are easy to dismiss on a busy day.
Treat screen sharing as an active trust decision, not a passive one. Before sharing a screen, especially in meetings with participants outside your organization, it is worth knowing exactly what permissions your video platform grants to other attendees by default.
Review your video conferencing platform's default permission settings. Many platforms allow meeting hosts to restrict who can use annotation tools, request remote control, or interact with a shared screen. Locking these down by default, rather than leaving them open, closes off an entire category of risk.
Use this story in security awareness conversations about video calls specifically. Most training focuses on email and phishing. A concrete example involving something as ordinary as a video call annotation tool broadens the conversation in a way that sticks.
The Bigger Picture
This flaw is a useful reminder that security risk does not only live in obviously suspicious places. It can live inside a feature everyone has used dozens of times without a second thought. The businesses that take this seriously are the ones extending the same scrutiny to their everyday collaboration tools that they already apply to email and file downloads, and confirming the basics, like whether their video conferencing software is actually up to date, before the next big screen-share meeting.
Stay inside the line.