# Session lifetime is a security control, not a UX setting

DevFeed: [Session lifetime is a security control, not a UX setting](<https://devfeed.tech/articles/session-lifetime-is-a-security-control-not-a-ux-setting-16060.md>)

Original publisher: [Read original article](<https://workos.com/blog/session-lifetime-security-control>)

Author: WorkOS

Published: 2026-08-18T00:00:00Z

Content type: opinion

Language: en

Sources: [WorkOS Blog](<https://devfeed.tech/sources/workos-blog.md>)

Topics: [zoom](<https://devfeed.tech/topics/zoom.md>), [Security](<https://devfeed.tech/topics/security.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [bug](<https://devfeed.tech/topics/bug.md>), [configuration](<https://devfeed.tech/topics/configuration.md>)

Tags: [bug](<https://devfeed.tech/tags/bug.md>), [configuration](<https://devfeed.tech/tags/configuration.md>), [env-file-security](<https://devfeed.tech/tags/env-file-security.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [rce](<https://devfeed.tech/tags/rce.md>), [security](<https://devfeed.tech/tags/security.md>), [zoom](<https://devfeed.tech/tags/zoom.md>)

## AI overview

This commentary argues that session lifetime should be treated as a security control rather than a user-experience setting. It uses a reported Zoom annotation vulnerability, which allegedly progressed from discovery to a zero-click remote code execution exploit in under 24 hours with fewer than 20 prompts to publicly available AI models, to emphasize the risk of long-lived stolen sessions. It also notes Zoom's fixes, server-side filtering, and the stated limitation involving end-to-end encrypted meetings.

## Source excerpt

A Zoom zero-click RCE went from discovery to working exploit in a day. The exploit took one day; your sessions last longer than that.