Zoom has shipped emergency patches for a cluster of vulnerabilities that could have let a single participant on a video call silently seize control of every other device in the meeting — no click, no download and no warning required. Researchers who found the flaws nicknamed the bug "Zoomsday."
The core issue, tracked as CVE-2026-53413, sits in the code Zoom uses to process annotations, the drawing and highlighting marks participants can add during screen sharing. Zoom rated it high severity and paired the fix with patches for three related bugs, CVE-2026-53414 through CVE-2026-53416, covering a denial-of-service flaw, a separate use-after-free bug and a path-traversal issue in Zoom's VDI client. The vulnerable code shipped across every platform Zoom supports — Windows, macOS, Linux, iOS and Android — in Zoom Workplace, Zoom Rooms, the Meeting SDK and the VDI Client. Fixed versions include Workplace 7.1.5 and 7.0.6, Rooms 7.1.5 and Meeting SDK 7.1.5, according to Zoom's security bulletins.
The bug itself was mundane in the way many serious ones are. The function that reads annotation data allocates a fixed 128-byte buffer but trusts a 32-bit length value sent over the network, so a participant could send a crafted string of drawing coordinates that overflows the buffer and corrupts adjacent memory. That corruption can be steered into running code the attacker controls, all while the target sees nothing more than a normal meeting on screen. In a proof-of-concept, researchers used the flaw to silently launch the Safari browser on a target's Mac mid-meeting.
Found with fewer than 20 prompts
The firm that found the bug, a.security, says it stumbled on the flaw in early June while reviewing Zoom's Android client, then turned to publicly available AI models to build a working exploit. Cofounder Omer Gull has said that finding and weaponizing a bug of this kind would ordinarily take a team of five researchers as long as six months of manual work; his team did it in under a day, using fewer than 20 prompts. The claim, reported by TechRepublic and other outlets covering the disclosure, has become as much a talking point in security circles as the bug itself, evidence that generative AI is compressing the time it takes to both find and exploit software flaws.
That compression cuts in more than one direction. Security teams can find and fix bugs faster, but the same tools narrow the head start defenders once had over attackers. The disclosure lands little more than a day after CloudSEK researchers detailed a separate software supply-chain breach that touched thousands of companies through a popular AI developer tool, underscoring how much of the industry's exposure now runs through a small number of widely shared components.
Zoom says it found no evidence of exploitation
Zoom said it has seen no evidence the flaws were exploited before the patch shipped. The company and the researchers have not fully agreed on how severe the bug should be rated: a.security argued for a critical rating given that no user interaction was required to trigger it, while Zoom classified the primary flaw as high severity, a dispute Malwarebytes noted turns on how CVSS scoring treats a victim's passive presence in a call as a form of interaction.
Security researchers are urging IT administrators to push the update across managed device fleets immediately rather than wait for users to update on their own, given how widely Zoom is used for government, healthcare and financial-services meetings. Recommended interim steps include enforcing meeting passcodes and waiting rooms, disabling annotation features where they aren't needed, and watching endpoint logs for unexplained Zoom process crashes.
Zoom has not said whether it will change how annotation data is validated more broadly, and further bulletins in the same numbering series, ZSB-26015 through ZSB-26018, suggest the company's internal review of the feature is continuing. Other collaboration-software vendors are likely to face similar scrutiny of their own screen-sharing and annotation code in the weeks ahead, as researchers apply the same AI-assisted techniques that surfaced Zoomsday to competing platforms.