Unmasking ‘Zoomsday’: A Zero-Click Vulnerability in Zoom That Lets Hackers Control Your Device

Cybersecurity researchers have recently discovered a severe zero-click vulnerability in Zoom, ominously named “Zoomsday”. This flaw enables a malicious meeting participant to silently seize control of another attendee’s device — without any action required from the unsuspecting victim. No clicks, no downloads, no warning prompts.

The most critical bug, identified as CVE-2026-53413, is a memory corruption flaw nestled within Zoom’s annotation feature — a tool that allows participants to draw or highlight content during screen sharing. The flaw was discovered and named by researchers at A Security. They found that an attacker could send a specially crafted message to corrupt a receiving client’s memory and execute arbitrary code on the target device. Zoom has classified this vulnerability as high severity, and released security bulletins (ZSB-26015 through ZSB-26018) on August 11, 2026.

The annotation-related bugs affect Zoom clients across all supported platforms — Windows, Mac, iOS, Android, and Linux. Zoom has since released patches and strongly encourages all users to promptly update to Zoom Workplace version 7.1.5 or 7.0.6. Zoom Rooms and Meeting SDK users should also update to version 7.1.5. Despite no evidence of active exploitation in the wild, security experts are treating this as an urgent patching priority given the flaw requires zero interaction from the victim.

Source: SecurityWeek – Zoom Patches Zero-Click Code Execution Vulnerability

Move to the category:

Leave a Reply

Your email address will not be published. Required fields are marked *