Zoom Zero-Click Vulnerabilities Allow Meeting Participants to Hijack Other Users’ Devices
Brief
Zoom has rolled out patches for four newly disclosed security flaws that could let a malicious meeting participant remotely execute code on another attendee’s computer, with no clicks, downloads, or warning signs required.
The most severe of the bugs, tracked as CVE-2026-53413 , has been dubbed “Zoomsday” by A Security, the research team credited with discovering it, and carries a “high” severity rating from Zoom’s own Trust and Security team.
The flaw lives inside Zoom’s annotation feature, the tool that lets meeting participants draw, highlight, or add text while a screen is being shared. That feature relies on a proprietary protocol that opens a direct communication channel between whoever is sharing their screen and whoever is viewing it.
