Overview
- A Security discovered three memory‑safety bugs in Zoom’s proprietary annotation protocol and disclosed them to Zoom after finding a working exploit in early June.
- Researchers say the most severe defect, CVE‑2026‑53413, allowed an attacker in a meeting to run code on other participants’ machines with no action or visible cue from victims.
- Zoom assigned CVEs for the flaws and began deploying server‑side mitigations and patched clients in June and July, and it is urging users to update to the fixed versions.
- A Security reports it built the exploit in under 24 hours using fewer than 20 prompts on publicly available AI models, a development researchers warn lowers the bar for high‑impact attacks.
- Experts note unresolved issues: Zoom and the researchers disagree on severity and whether user interaction is required, server filters may not cover end‑to‑end encrypted meetings, and no active exploitation has been confirmed.