A concerning vulnerability has been discovered in the popular video conferencing platform Zoom, allowing hackers to gain access to user accounts by exploiting a secret "no record" feature. According to reports, this exploit relies on understanding how the platform handles transcription and summary functions. Essentially, when users press the "record" button during meetings or chats, the software temporarily stores the conversation in a database, effectively creating a transcript.
However, the "no record" feature seems to prevent Zoom from actually saving any of these transcribed conversations. Instead, hackers can use this glitch to steal sensitive information and even read through entire meeting recordings, including private conversations. This vulnerability is particularly concerning given the increasing reliance on video conferencing in everyday life.
Experts warn that users should take immediate action to address this issue. To mitigate the risk, Zoom should update its software to remove the "no record" feature altogether, allowing legitimate users to save and control their own recorded conversations. Until then, users are advised to exercise caution when sharing sensitive information during meetings or online discussions.