Particle.news
Download on the App Store

Zoom 'Zoomsday' Flaw Allowed Zero‑Click Device Takeover, Researchers Say

Publicly available AI models sharply reduced the time to weaponize a memory‑corruption bug, prompting Zoom to roll out server and client fixes.

Overview

  • A Security discovered three memory‑safety bugs in Zoom’s proprietary annotation protocol and disclosed them to Zoom after finding a working exploit in early June.
  • Researchers say the most severe defect, CVE‑2026‑53413, allowed an attacker in a meeting to run code on other participants’ machines with no action or visible cue from victims.
  • Zoom assigned CVEs for the flaws and began deploying server‑side mitigations and patched clients in June and July, and it is urging users to update to the fixed versions.
  • A Security reports it built the exploit in under 24 hours using fewer than 20 prompts on publicly available AI models, a development researchers warn lowers the bar for high‑impact attacks.
  • Experts note unresolved issues: Zoom and the researchers disagree on severity and whether user interaction is required, server filters may not cover end‑to‑end encrypted meetings, and no active exploitation has been confirmed.