Zoom has patched a serious security flaw that could allow another participant in a meeting to remotely execute malicious code on a victim’s device without requiring them to click anything or respond to a warning.
Cybersecurity firm A Security discovered the vulnerability in Zoom’s annotation system, which powers the tools used to draw and write over shared screens. The researchers confirmed that the attack worked across Windows, macOS, iOS, and Android. Zoom’s affected-product list also covers all supported Zoom Workplace platforms.
No Action Required From the Victim
The vulnerability involved memory-corruption flaws in the annotation engine. A malicious meeting participant could send specially crafted annotation data that another Zoom client would automatically process.
A security researcher said the attack required no click or download from the target and displayed no visible indication that the device had been compromised. Successful exploitation could allow an attacker to run code on the victim’s machine.
Zoom has assigned the related flaws CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415. Two can contribute to remote code execution, while another involves a buffer over-read that can cause denial of service.
There is currently no public indication in Zoom’s or A Security’s disclosures that attackers exploited the vulnerabilities in the wild before they were fixed.
AI-Made Exploit
The researchers also highlighted how quickly they developed the attack.
A-Security said its team confirmed a working zero-click remote code execution exploit less than a day after discovering the problem, using publicly available AI models during the research process. The company said this type of exploit would previously have required significantly more time and specialized resources.
The original vulnerability was discovered on June 8 and reported to Zoom on June 10. Zoom released client-side fixes beginning later that month, followed by server-side mitigations and additional patches in July. The vulnerabilities were publicly disclosed on August 11.
Zoom Users Should Update
Zoom recommends installing the latest available updates.
Zoom Workplace users should be on at least version 7.1.5 or 7.0.6 in their respective branches. Updated versions are also available for Zoom Rooms, the Meeting SDK, and the Windows VDI client.
Apple recently addressed a separate Screen Sharing security issue in macOS as well. Apple released macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9 on August 6, while the Tahoe update specifically fixes a flaw that could allow a network attacker to authenticate to Screen Sharing without valid credentials.
The post Zoom Bug Was Letting Hackers Take Over Anyone’s PC or Phone appeared first on ProPakistani.
