If you use the Zoom video conferencing software, you should update it to the latest version soon. The vendor has closed several dangerous security flaws. One of them lets attackers execute malicious code on other participants' devices from within a running meeting, and apparently without any user interaction.
No click required
The flaw is registered as CVE-2026-53413, and its discoverers call it Zoomsday. With a CVSS score of 8.3, it's rated a high risk. The cause is out-of-bounds writes to a buffer. The bug is described as a zero-click flaw, was discovered with the help of artificial intelligence, and was reported to Zoom back on June 10. According to the security researchers at A Security, the vulnerability could be found in under 24 hours using fewer than 20 prompts on publicly available AI models.
The flaw sits in Zoom's annotation feature, which is based on a proprietary protocol. Apart from joining the meeting, a victim doesn't have to do anything. The attacker can compromise the target device on their own by sending specially crafted messages to the targeted participant's Zoom client. The protocol opens a direct channel between a viewer and a participant sharing content, so each participant can be targeted individually. There are no visible signs of the attack, meaning a compromise can go unnoticed.
What attackers can do with it
Once the malicious code runs on the victim's device, the researchers say an attacker can quietly steal personal data, turn on the microphone or camera to spy on the target, or install additional malware. In a large conference call, that means, in the worst case, many targets from a single message.
Patches for all Zoom variants
All common Zoom clients for Windows, macOS, iOS, Android, and Linux up to and including version 7.0.5 are vulnerable. A full patch for Zoom Workplace has been available since July with versions 7.1.5 and 7.0.6. The Zoom Workplace VDI Client for Windows is protected from versions 7.0.11 and 6.6.16, and for Zoom Rooms and the Zoom Meeting SDK the flaw was closed with version 7.1.0. The same releases fix two more flaws discovered by A Security (CVE-2026-53414 and CVE-2026-53415). One is based on a use-after-free bug and also allows remote code execution, while the other lets attackers crash the software on other devices.