Zoomsday Zoom vulnerability prompts urgent update after AI-assisted exploit research
Zoom patched three annotation-data flaws after researchers said publicly available AI helped build an exploit in a day.
By Theo Nakamura · Staff Writer
· 3 min read
The Zoomsday Zoom vulnerability is a set of flaws in Zoom’s meeting annotation system that researchers said could let one participant run code on another participant’s device. Zoom has issued patches, making an update the immediate priority for people and organizations using the affected apps.
The central issue, tracked as CVE-2026-53413, was a memory-corruption bug in the feature that processes shared annotations, according to SecurityWeek. A Security, the firm that found the flaws, said a specially formed annotation message could cause a vulnerable Zoom client to run attacker-controlled code.
For an investor or employee, the practical point is straightforward: this was a risk inside a meeting, not a claim that any stranger could remotely take over any Zoom user’s device. Malwarebytes reported that an attacker needed to be in the same meeting as the intended target, such as by entering an insufficiently restricted call or using a compromised account.
What was the Zoomsday Zoom vulnerability?
Zoom annotations let participants draw or add text while someone shares a screen. Instead of treating that activity as a picture, the software receives structured collaboration data and turns it into what appears on screen. Researchers said the affected Zoom client automatically processed that received data.
That created the opening: a meeting participant could send malformed annotation data to a vulnerable client. SecurityWeek reported that the underlying protocol allowed individual attendees to be targeted. Successful exploitation of CVE-2026-53413 could result in remote code execution, meaning an attacker could make the targeted device run their code. Other reported flaws could cause a crash or disclose information.
A Security called the victim-side attack “zero-click” because the targeted person did not need to approve a prompt, open a file, or take another action after the attacker had meeting access. Malwarebytes noted that Zoom nevertheless treated the step of getting a target into a malicious meeting as user interaction when rating the flaws. The researchers reportedly rated the issues Critical, while Zoom rated them High.
How did AI factor into the research?
A Security said its researchers produced a working exploit in less than 24 hours with fewer than 20 prompts to publicly available AI models, The Verge reported. Researcher Idan Levcovich characterized that pace as work that previously would have required elite teams and much longer effort. That comparison is the researchers’ assessment, rather than an independently measured benchmark.
There is no reported evidence in the available accounts that the flaw was exploited in the wild. The episode does show why the time between discovering a software bug and applying an update matters: AI may have helped accelerate the research workflow, while unpatched software and weak meeting-access controls determine exposure.
Which Zoom versions need updating?
SecurityWeek reported fixes in Zoom Workplace 7.1.5 and 7.0.6, depending on the release branch, Zoom Rooms 7.1.5, and Zoom Meeting SDK 7.1.5. Malwarebytes additionally listed patched Zoom Workplace VDI Client for Windows versions 7.0.11 and 6.6.16. Users should install the latest available Zoom update rather than rely only on version numbers.
- Use passcodes, waiting rooms, authenticated-user restrictions, and unique links for sensitive calls.
- Limit attendance, especially for meetings whose links are widely shared.
- Turn off annotation and other collaboration functions when they are not needed for open-invitation meetings.
- Organizations should confirm managed devices are receiving Zoom updates.
This story draws on original reporting from Decrypt.