Search
Find merged stories by title or summary.
Zoom Patches “Zoomsday” Zero-Click Flaw Enabling Remote Code Execution
Zoom patches a zero-click flaw that could let a meeting participant execute code on another user’s computer through the annotation feature. Zoom has patched four vulnerabilities, including a critical zero-click flaw, tracked as CVE-2026-53413, in its annotation feature. CVE-2026-53413 is a memory corruption issue found by A Security that could allow a meeting participant to execute code on another participant’s computer. Due to its impact, the researchers dubbed the flaw “Zoomsday,” it affects Zoom clients on all supported platforms and is linked to the proprietary protocol used by the annotation function. Zoom has now begun rolling out security updates to address the issue. “Ⓐ Security, the Autonomous Offensive Security and Remediation Platform, discovered a critical flaw in Zoom that let an attacker take complete control of another user’s device during a live call.
Zoom Zero-Click Vulnerabilities Allow Meeting Participants to Hijack Other Users’ Devices
Zoom has rolled out patches for four newly disclosed security flaws that could let a malicious meeting participant remotely execute code on another attendee’s computer, with no clicks, downloads, or warning signs required. The most severe of the bugs, tracked as CVE-2026-53413 , has been dubbed “Zoomsday” by A Security, the research team credited with discovering it, and carries a “high” severity rating from Zoom’s own Trust and Security team. The flaw lives inside Zoom’s annotation feature, the tool that lets meeting participants draw, highlight, or add text while a screen is being shared. That feature relies on a proprietary protocol that opens a direct communication channel between whoever is sharing their screen and whoever is viewing it.
Zoom zero-click flaw allowed RCE attacks during meetings
Multiple vulnerabilities in Zoom’s annotation engine could allow a malicious meeting participant to compromise another attendee’s device by sending specially crafted meeting data. The most serious issue, tracked as CVE-2026-53413, is a buffer overwrite that Zoom says could lead to remote code execution. A second flaw, CVE-2026-53414, involves a buffer over-read and can be abused … The post Zoom zero-click flaw allowed RCE attacks during meetings appeared first on CyberInsider .
You've reached the end of current stories for this search.
