Zoom Patches Zero-Click Code Execution Flaw
TL;DR. Zoom patched a severe vulnerability allowing zero-click remote code execution via its annotator function. - The flaw, named Zoomsday by A Security, exploited a missing bound check in the proprietary annotator protocol. - Attackers could execute arbitrary code on participants' machines without user interaction or visual cues. - The patch addresses CVE-2026-53413, a memory corruption issue impacting all supported Zoom platforms.
- Zoom released patches for four vulnerabilities, including a critical zero-click RCE flaw.
- The most severe bug, CVE-2026-53413, affected Zoom's annotator function across all platforms.
- A Security discovered the vulnerability, which allowed attackers to execute code on participants' systems.
- The flaw exploited a direct channel between viewers and sharers in the annotator protocol.
- The patch was rolled out in coordination with the discovering security firm.
Sources
- Zoom Patches Zero-Click Code Execution Vulnerability — securityweek.com