Zoom Fixes Bug That Let Call Participants Take Control of Other Devices
Zoom has fixed issues in its annotation system that allowed malicious meeting participants to run code on other attendees’ devices without their consent.
Researchers at the AI-equipped cybersecurity research firm (A)Security discovered issues in the data shared by Zoom clients during screen sharing and annotation. Crucially, the bug did not allow random internet users to directly take over devices just by knowing a meeting link or a Zoom account; the attacker first needed to join the target meeting.
The researchers said an attacker could send annotation data to a participant’s Zoom client, after which the client would process that data automatically, even if the recipient did not click an annotation, approve remote control, or open a file. These bugs could let an attacker run code with the same permissions as the Zoom app.
The team responsible for finding the flaws reported them to Zoom back in June. Zoom released fixes in June and July and published these updates on August 11:
-
CVE-2026-53413: Buffer-overwrite vulnerability
-
CVE-2026-53415: Use-after-free vulnerability
-
CVE-2026-53414: Could lead to denial of service
-
CVE-2026-53416: Path-traversal issue in VDI products
Zoom clients on desktop and mobile, as well as Zoom Rooms, Zoom’s SDK, and its virtual desktop infrastructure (VDI), were vulnerable. If you use Zoom at all, it’d be wise to update to the latest version as soon as possible.