CyberIntel ⬡ News
★ Saved ◆ Cyber Reads
← Back ◇ Industry News & Leadership Aug 12, 2026

Zoom Flaws Facilitate Zero-Click Remote Code Execution

Data Breach Today Archived Aug 12, 2026 ✓ Full text saved

Patch Now: Outdated Zoom Clients Still Vulnerable to Malicious Meeting Participants Security experts are urging all Zoom users to patch their client, after the video communications giant fixed flaws that a malicious participant could exploit to infect everyone else on the call with malware, without targets having to click or download any code.

Full text archived locally
✦ AI Summary · Claude Sonnet


    Endpoint Security , Governance & Risk Management , Remote Workforce Zoom Flaws Facilitate Zero-Click Remote Code Execution Patch Now: Outdated Zoom Clients Still Vulnerable to Malicious Meeting Participants Mathew J. Schwartz (euroinfosec) • August 12, 2026     Credit Eligible Get Permission Image: Shutterstock/ISMG Participants in Zoom calls until recently could reach out and touch someone in the worst way possible by remotely running malicious code on other caller systems. See Also: A Legal Services Firm Needed a Modern Remote Work Strategy. Choosing Venn over a Virtual Desktop Changed Everything. The ubiquitous live video meeting provider disclosed it patched memory corruption flaws in the annotation feature included in the Zoom client. The flaw existed across platforms, including mobile devices. Publicly traded Zoom is the world's most-used videoconferencing platform, ahead of Microsoft Teams, GoTo Meeting and WebEx. The vulnerabilities are present in all versions of Zoom Workplace prior to July 20. Security experts said the only foolproof defense is to install the patch. Endpoint security software cannot be relied on to spot and block these types of attacks. "For managed environments, enforce minimum client versions rather than relying on users to update themselves," said Douglas McKee, director of vulnerability intelligence at Rapid7. The vulnerabilities exist in the annotator functionality built into the Zoom client, and include a use-after-free flaw, CVE-2026-53415, and a missing bounds check vulnerability, CVE-2026-53413 each of which can be abused to remotely execute code. The company also patched a denial of service vulnerability tracked as CVE-2026-53414. Israeli cybersecurity firm A Security said it reported these "Zoomsday" flaws to Zoom in June, after discovering using just 20 prompts to an offensive AI security harness it built. The researchers said the flaws let an attacker "take complete control of another user's device during a live call" without a user having to click on anything or download any code. A single malicious presenter or participant on a meeting could infect every other participant, and the attack would trigger "no visual cue" indicating their system was hacked. "Once the nefarious code is running on the victim's device, the threat actor can quietly steal personal data, switch on the microphone or camera to spy on the target or install other malicious software," they said. Zoom didn't immediately respond to a request for comment about how to better mitigate these types of vulnerabilities in its clients. The A Security researchers said Zoom was already running server-side mitigations to block malicious messages, and it's added fresh blocks to arrest any attempted exploit of these new flaws. This will protect users running prior, vulnerable versions of the client, with a big caveat: if users have enabled Zoom's end-to-end encryption setting, the server-side protections won't work, because end-to-end prevents Zoom from inspecting the traffic. As a result, attackers could still exploit the flaws in unpatched clients. Rapid7's McKee said that short of updating to patched software, there's no sure-fire safeguard, including by using endpoint security tools. But reducing the attack surface can help. "The interesting part of this attack is that the victim didn't need to click anything. The attacker only needed to be in the meeting, so meeting access controls matter too. Waiting rooms, authenticated-user requirements, passcodes and restricting unused features such as annotation all reduce who can reach that attack surface," he said. Also, how this attack unfolded is a good reason for defenders to now "validate endpoint controls rather than assume they're working," he said. The A Security researchers detailed numerous controls that can be set, and said their proof-of-concept attack generated multiple clues something bad was unfolding. "A meeting client has no reason to launch a browser, a shell or a script interpreter, so block it where you can and alert on it everywhere; our exploit made zoom.us open Safari. Collect client crash reports centrally too, because failed attempts crash long before a working one lands," they said. McKee likewise emphasized the importance of "centralizing application crash data," because "failed memory-corruption attempts often produce crashes before an attacker gets reliable code execution." Using more isolated versions of Zoom or a different device entirely is another potential defensive strategy, said Yossi Torati, CEO of A Security, in a post to LinkedIn. "For calls with untrusted parties, a browser client or a dedicated VM meaningfully reduces exposure," he said.
    💬 Team Notes
    Article Info
    Source
    Data Breach Today
    Category
    ◇ Industry News & Leadership
    Published
    Aug 12, 2026
    Archived
    Aug 12, 2026
    Full Text
    ✓ Saved locally
    Open Original ↗