A critical vulnerability in Zoom’s annotation system allowed attackers to remotely compromise devices across all major platforms without requiring any user interaction, prompting an urgent security update.
Key Points
- The flaw, tracked as CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415, enabled remote code execution via the app's screen-sharing annotation engine.
- Researchers utilized publicly available AI models to identify and exploit the memory corruption vulnerability in fewer than 20 prompts.
- Affected platforms include Windows, macOS, Linux, Android, and iOS, with no user action required for an attacker to gain control.
- Zoom has released patches for all impacted versions, including Zoom Workplace, VDI Client, Zoom Rooms, and the Meeting SDK.
- Users are advised to update their Zoom software immediately to versions 7.1.5 or 7.0.6 to mitigate the risk of silent device takeover.