← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 11, 2026 · 17:48via Security Affairs

Zoom Patches “Zoomsday” Zero-Click Flaw Enabling Remote Code Execution

Brief

Zoom patches a zero-click flaw that could let a meeting participant execute code on another user’s computer through the annotation feature.

Zoom has patched four vulnerabilities, including a critical zero-click flaw, tracked as CVE-2026-53413, in its annotation feature. CVE-2026-53413 is a memory corruption issue found by A Security that could allow a meeting participant to execute code on another participant’s computer.

Due to its impact, the researchers dubbed the flaw “Zoomsday,” it affects Zoom clients on all supported platforms and is linked to the proprietary protocol used by the annotation function. Zoom has now begun rolling out security updates to address the issue.

“Ⓐ Security, the Autonomous Offensive Security and Remediation Platform, discovered a critical flaw in Zoom that let an attacker take complete control of another user’s device during a live call.

Read more on Security Affairs