Zoom resolved three vulnerabilities that allowed any participant on a call to gain control of your device.
Zoom has addressed three memory corruption vulnerabilities in its annotation feature, permitting any participant in a meeting to execute code on another attendee’s device without any interaction. The patches were released in June and July 2026, approximately two months prior to the public disclosure of the research.
These vulnerabilities in the annotation tools utilized during screen sharing allowed any participant to run code on another user’s device without requiring a click or any visible indication. These fixes were implemented in June and July.
It is important to highlight this timing, as the incident has been characterized as an urgent matter. Zoom rectified the issues about two months before the research became public, ensuring that any users on an updated client are already protected.
The corrected versions include Zoom Workplace 7.1.5 and 7.0.6, Rooms and the Meeting SDK at 7.1.5, and the Windows VDI client at versions 7.0.11 and 6.6.16. Versions older than these remain vulnerable.
The reported severity level is also somewhat overstated. A Security, the firm that identified the vulnerabilities, rated all three issues at 9.0 out of 10. In contrast, Zoom assessed CVE-2026-53413 and CVE-2026-53415 at 8.3 and CVE-2026-53414 at 6.5.
The underlying issues are typical memory-safety failures. Annotations are transmitted over the network as a sequence of counts followed by data, with the receiving client erroneously trusting those counts, allowing one value to overflow a 128-byte buffer and corrupt a return address. Another flaw permitted the dispatcher to accept annotation messages without verifying the sender’s identity.
An attacker participating in the call, whether a host or guest, could send a specially crafted message that would execute on other devices without prompting the user or showing any signs. The potential outcomes include file theft, unauthorized access to the camera and microphone, credential and wallet theft, and the deployment of secondary payloads.
The primary assertion is that AI was responsible for the rapid development of the exploit. A Security claims it transitioned from discovering the flaws to creating a working exploit in less than a day, using under 20 prompts on publicly available models, and contends that such capabilities were previously limited to nation-states. Meanwhile, OpenAI has released a cyber model designed to reject less.
However, its own report complicates this narrative. An automated assessment across 3,762 functions overlooked the vulnerable library, positioning it 45th, and the bug was only identified when a researcher manually traced a live call. While AI expedited the weaponization process, it was human intervention that initially discovered it.
Nonetheless, the broader trend remains significant. Anthropic’s Mythos has identified 10,000 critical vulnerabilities within a month, outpacing the ability for anyone to patch them.
Другие статьи
Zoom resolved three vulnerabilities that allowed any participant on a call to gain control of your device.
Three bugs in Zoom's annotation feature allow any participant on a call to execute code on other devices. Fixes were released in June and July, two months prior to the announcement.
