
Security researchers have found a critical zero-click remote code execution vulnerability in Zoom’s annotation feature that enabled meeting participants to silently take over other attendees’ devices.
The vulnerability affects Zoom’s screen-sharing annotation protocol across all supported platforms, including Windows, macOS, Linux, iOS, and Android.
The corporation states that it took less than 20 AI queries to identify the vulnerability and create an exploit.
CVE-2026-53413 (CVSS 8.3) is the most critical vulnerability, which relates to memory corruption. It would enable attackers to use the proprietary protocol of the application, connecting the meeting participants directly, sending crafted messages, and corrupting the memory of the receiving client, running arbitrary code without user intervention.
Moreover, Zoom fixed CVE-2026-53414, which is a buffer overread, and CVE-2026-53415, which is use-after-free. The third vulnerability was internally identified by Zoom, and server-side mitigations were implemented.
Zoom released patches in June and July with fixes available in Workplace versions 7.1.5 and 7.0.6, Rooms version 7.1.5, and Meeting SDK version 7.1.5. No active exploitation has been reported.
2026-08-12 18:19:00








