SAN FRANCISCO, Aug. 12 -- For roughly three months, anyone sharing their screen in a Zoom meeting was participating in something they had not agreed to: a quiet security experiment in which their device could have been taken over by anyone else in the room.

A critical vulnerability in Zoom's screen-sharing feature, assigned the designation ZSB-26015 and already nicknamed "Zoomsday," allowed attackers to execute arbitrary code on any device participating in a meeting where screen sharing was active. Windows, macOS, Linux, iOS, and Android users were all exposed, silently, without requiring the target to click, download, or do anything beyond joining a call. Zoom has since patched the flaw. But what the disclosure has put into sharp relief...