Zoom resolved three vulnerabilities that allowed any participant on a call to gain control of your device.

Zoom resolved three vulnerabilities that allowed any participant on a call to gain control of your device.

      Zoom has addressed three memory corruption vulnerabilities in its annotation feature, permitting any participant in a meeting to execute code on another attendee’s device without any interaction. The patches were released in June and July 2026, approximately two months prior to the public disclosure of the research.

      These vulnerabilities in the annotation tools utilized during screen sharing allowed any participant to run code on another user’s device without requiring a click or any visible indication. These fixes were implemented in June and July.

      It is important to highlight this timing, as the incident has been characterized as an urgent matter. Zoom rectified the issues about two months before the research became public, ensuring that any users on an updated client are already protected.

      The corrected versions include Zoom Workplace 7.1.5 and 7.0.6, Rooms and the Meeting SDK at 7.1.5, and the Windows VDI client at versions 7.0.11 and 6.6.16. Versions older than these remain vulnerable.

      The reported severity level is also somewhat overstated. A Security, the firm that identified the vulnerabilities, rated all three issues at 9.0 out of 10. In contrast, Zoom assessed CVE-2026-53413 and CVE-2026-53415 at 8.3 and CVE-2026-53414 at 6.5.

      The underlying issues are typical memory-safety failures. Annotations are transmitted over the network as a sequence of counts followed by data, with the receiving client erroneously trusting those counts, allowing one value to overflow a 128-byte buffer and corrupt a return address. Another flaw permitted the dispatcher to accept annotation messages without verifying the sender’s identity.

      An attacker participating in the call, whether a host or guest, could send a specially crafted message that would execute on other devices without prompting the user or showing any signs. The potential outcomes include file theft, unauthorized access to the camera and microphone, credential and wallet theft, and the deployment of secondary payloads.

      The primary assertion is that AI was responsible for the rapid development of the exploit. A Security claims it transitioned from discovering the flaws to creating a working exploit in less than a day, using under 20 prompts on publicly available models, and contends that such capabilities were previously limited to nation-states. Meanwhile, OpenAI has released a cyber model designed to reject less.

      However, its own report complicates this narrative. An automated assessment across 3,762 functions overlooked the vulnerable library, positioning it 45th, and the bug was only identified when a researcher manually traced a live call. While AI expedited the weaponization process, it was human intervention that initially discovered it.

      Nonetheless, the broader trend remains significant. Anthropic’s Mythos has identified 10,000 critical vulnerabilities within a month, outpacing the ability for anyone to patch them.

Другие статьи

Nvidia is developing an open model with a trillion parameters, which would still be less extensive than China's model. Nvidia is developing an open model with a trillion parameters, which would still be less extensive than China's model. Nvidia's Nemotron 3.5 Lightning is both free and quick. The upcoming trillion-parameter Nemotron 4 would still lag behind the top Chinese open models. Why brief moments of acknowledgment are increasingly essential to workplace culture Why brief moments of acknowledgment are increasingly essential to workplace culture Gallup indicates that employee engagement dropped to 20% in 2025. Julie Tylman, co-founder of GroupTogether, contends that peer recognition through small, consistent rituals fosters a culture that formal programs and algorithms cannot achieve. Megadeals accounted for 87.5% of venture capital in the US, with the remainder of the market priced according to vintage. Megadeals accounted for 87.5% of venture capital in the US, with the remainder of the market priced according to vintage. In the first half of 2026, deals of $100 million or more accounted for 87.5% of venture capital investment in the US. Firms that last secured funding in 2021 are valued at a 59.1% discount in secondary markets. The Pixel 11 finally includes the video enhancements I've been looking forward to, but not all Pixels receive these updates. The Pixel 11 finally includes the video enhancements I've been looking forward to, but not all Pixels receive these updates. This year, Google equipped the Pixel 11 lineup with authentic video enhancements, including 8K recording and an integrated teleprompter. Jaguar presents a sneak peek of its fully electric Type 01. Jaguar presents a sneak peek of its fully electric Type 01. Jaguar has unveiled the initial interior photos of the Type 01 electric GT, the vehicle on which it is banking for its relaunch after halting sales in the UK in November 2024. Google's latest Pixel 11 Pro and Pro XL feature brighter screens, extended zoom capabilities, and an innovative method to capture your interest. Google's latest Pixel 11 Pro and Pro XL feature brighter screens, extended zoom capabilities, and an innovative method to capture your interest. Google's Pixel 11 Pro and Pro XL feature a new Tensor G6 chip, an upgraded display with a brightness of 3,600 nits, and HiLight; however, the base RAM and battery capacity have seen a slight decrease compared to last year's versions.

Zoom resolved three vulnerabilities that allowed any participant on a call to gain control of your device.

Three bugs in Zoom's annotation feature allow any participant on a call to execute code on other devices. Fixes were released in June and July, two months prior to the announcement.