Zoom の画面共有バグ、通話参加者全員の端末乗っ取り可能
本文の状態
日本語全文を表示中
詳細モードで約4分の本文を読めます。
同じ出来事の情報源
この情報源を基点に整理
WIRED AI
セキュリティ調査会社 A Security は、AI モデルを活用して Zoom の画面共有機能に存在する深刻な脆弱性を発見し、攻撃者が被害者の操作や反応なしにデバイスを乗っ取れることを明らかにした。
Continue in AI NEW LAB
このニュースを、実務の判断につなげる
AI NEW LABで、試したことや先に確認したい条件を共有できます。まずはログインなしで読めます。
AI NEW LABで論点を見るAI深層分析を開く2026年8月11日 22:48
AI深層分析
キーポイント
AI を活用した脆弱性発見の効率化
A Security の研究チームは、公開されている AI モデルを用いてわずか 20 回ほどのプロンプトで、従来の手法では数ヶ月とチームが必要だった複雑な脆弱性を特定し、攻撃コードを生成した。
画面共有時の無痕でのデバイス乗っ取り
このバグは画面共有中のリアルタイム注釈機能のプロトコルに存在し、参加者やホストが被害に気づくことなく、かつ何らかの操作を要求されることなくデバイスを完全に制御可能にする。
全プラットフォームへの広範な影響
Zoom は Windows、macOS、Linux、iOS、Android など、サポートするすべてのオペレーティングシステムでこの脆弱性が存在すると発表し、修正パッチの展開を既に開始している。
セキュリティ参入障壁の低下とリスク
A Security の共同創設者オマー・ガール氏は、AI による攻撃能力の民主化により参入障壁が急速に下がっており、信頼されやすい Zoom が標的となりやすい状況を懸念している。
AIによる複雑な機能の脆弱性発見
研究者らは、AIバグハンティングシステムが人間同様に複雑で不明瞭な機能を重点的に調査し、クローズドソースのソフトウェアで見落とされやすい欠陥を特定した。
重要な引用
Before it would have taken a team of five people maybe six months with a lot of refining and iteration to find this. Now people can reach the same results with under 20 prompts.
What is interesting for us and what we believe is dangerous is the democratization of these capabilities—the barrier to entry is dropping rapidly.
"If you just get on a Zoom with us, we can take over your device."
"The worst case scenario is that we can take over an enterprise just by having this vulnerability in our hands."
編集コメントを表示
編集コメント
AI がセキュリティ研究のツールとして機能するだけでなく、攻撃者にとっても同等に強力な武器となり得る現実が示された事例である。技術的なパラダイムシフトを踏まえ、企業は AI を活用した脅威への対応策を即座に強化する必要がある。
Source Article
元記事を日本語で読む
本文に関係しない購読案内、埋め込み通知、サイト内プロモーションは除いています。
AI モデルがソフトウェアの脆弱性を発見し、それを悪用する手法を開発し、さらには自律的なハッキング活動を実行する能力を高度化させる中、研究者たちは火に油を注ぐような新たな事例を 2 月 13 日に提示しました。それは、ビデオ会議プラットフォーム「Zoom」に見つかった脆弱性で、これを利用すればターゲットの端末を乗っ取ることが可能だったのです。
画面共有が行われている通話に参加している誰しもが、ホストであれ参加者であれ、被害者が気づくことも、何らかの操作を行う必要もなく、静かに実行される攻撃にさらされていました。
デジタル防衛企業「A Security」の研究チームによると、このバグは 6 月初旬に公開されている AI モデルを用いて発見されました。脆弱性を特定し、実際に動作する攻撃コードを作成するために必要なプロンプト数は 20 回未満でした。これを受け、Zoom は火曜日にセキュリティアドバイザリーを発表しました。同社はすでに修正プログラムの展開を開始しており、Windows、macOS、Linux、iOS、Android など、Zoom がサポートするすべての OS で動作する端末が影響を受けていたことが明かされています。
「私たちにとって興味深く、かつ危険なのは、これらの機能の民主化です。参入障壁が急速に低下しています」と、A Security の共同創設者であるオマー・ガール氏は WIRED に対して、今回の不具合の公表前にこう語りました。「以前なら、この脆弱性を発見するには、5〜6 人のチームが数ヶ月をかけて何度も改良と反復を重ねる必要がありました。しかし今は、20 個以下のプロンプトで同じ結果を達成できます。Zoom は重要なターゲットの一つです。なぜなら、ユーザーは利用時に信頼を置いているからです。脅威とは認識していないのです。」
今回の脆弱性は、画面共有中にリアルタイム注釈機能を可能にするプロトコルに存在していました。研究チームによれば、彼らの AI によるバグハンティングシステムは、人間と同様に「複雑で分かりにくい機能には見落とされやすい脆弱性が潜んでいる」という学習に基づき、このコンポーネントを重点的に調査したそうです。特に、独自開発のクローズドソースソフトウェアではその傾向が顕著です。Zoom のような確立された企業であれば、すべてのコンポーネントや機能に対して徹底的なコードレビューと審査を行っているはずですが、公開されたオープンなレビューという恩恵がないため、注釈のような特殊で複雑な機能にはミスが含まれる可能性が高まります。
WIRED からの複数の取材依頼に対し、Zoom は A Security の発見についてコメントを返していません。
これらの脆弱性は現在、パッチが適用されています。Zoom はサーバー側とクライアント側の両方に対する修正プログラム(パッチ)を公開しました。
しかし研究チームは、単に Zoom の通話に参加するだけで標的のデバイスを乗っ取れる可能性のあるバグが存在したという事実自体が非常に驚くべきことだと強調しています。通話に参加することはそれ自体が信頼を示す行為ですが、個人間やビジネスの場においてビデオ通話があまりにも一般的になっていること、特に Zoom がウェビナーなどのイベントや準公開活動でも広く使われていることを考えると、参加者は警戒心が緩みがちです。
「Zoom への参加さえすれば、我々はあなたのデバイスを乗っ取ることができます」と、セキュリティ企業 A Security の共同創業者であるヨッシ・トラティ氏は WIRED の取材にこう語りました(なお、このインタビュー自体は Microsoft Teams で開催されました)。「最悪のシナリオとしては、この脆弱性を握るだけで企業のシステム全体を乗っ取れることです。攻撃者であれば、ある企業の担当者と通話に参加し、そのコンピューターと認証情報をコントロールした上で、企業内での横方向への移動に利用できます」。
セキュリティ業界では長年、「猫とネズミのゲーム」と表現されてきましたが、AI を活用したバグハンティングが普及するにつれ、この微妙な駆け引きはもはや全面戦争のような競争へと変貌を遂げつつあります。
原文を表示
As AI models gain advanced capabilities to find vulnerabilities in software, develop ways to exploit them, and even carry out autonomous hacking sprees, researchers offered a sobering new example on Tuesday, disclosing vulnerabilities in the video conferencing platform Zoom that could have been exploited to take over targets’ devices. Anyone on a call that involved screen sharing, whether participants or the host, would have been vulnerable to a silent attack that could be carried out with no indication and no interaction from the victim.
Researchers from the digital defense firm A Security say the bug was discovered in early June using publicly available AI models, and that it took fewer than 20 prompts to uncover the vulnerabilities and create a working attack. Zoom issued a security advisory on Tuesday, including details about fixes the company has already begun rolling out to address the flaws, which affected devices running all operating systems that Zoom supports—Windows, macOS, Linux, iOS, and Android.
“What is interesting for us and what we believe is dangerous is the democratization of these capabilities—the barrier to entry is dropping rapidly,” A Security cofounder Omer Gull told WIRED ahead of the disclosure. “Before it would have taken a team of five people maybe six months with a lot of refining and iteration to find this. Now people can reach the same results with under 20 prompts. And Zoom is an important type of target because people assume trust when using it. They don’t see it as a threat.”
The vulnerabilities were specifically in the protocol used to facilitate real-time annotation during screen sharing. The researchers say that their AI bug hunting systems specifically delved into this component because, like human bug hunters, they have been trained that convoluted and obscure functions often contain overlooked vulnerabilities. This is particularly true with proprietary, closed source software. An established company like Zoom presumably does extensive code review and vetting on all components and functions, but without the benefit of public, open review, esoteric yet complex features like annotation are more likely to contain mistakes.
Zoom did not respond to multiple requests for comment from WIRED about the A Security findings.
The bugs are now patched, with Zoom issuing both server and client-side fixes—or patches for both Zoom’s own servers and the applications that run on customer devices. But the researchers emphasize that it was alarming to contemplate bugs that could have been exploited to take over a target device simply by getting someone onto a Zoom call. Joining a call is in itself a gesture of trust, but given how ubiquitous video calling is in both personal and professional contexts—and given that Zoom in particular is also widely used for events and semi-public activities like webinars—people typically have their guard down when joining a Zoom.
“If you just get on a Zoom with us, we can take over your device,” A Security cofounder Yossi Torati told WIRED on a call. (It was, incidentally, hosted on Microsoft Teams.) “The worst case scenario is that we can take over an enterprise just by having this vulnerability in our hands. If I’m an attacker I can be on a call with someone from a company, take control of their computer and their credentials, and then use them to move laterally in the enterprise.”
Practitioners often call security a “cat and mouse game,” but as AI bug hunting proliferates, this delicate dance has become an all out race.
今日のまとめ
AIデイリーブリーフで今日の重要ニュースをまとめ読み