Zoom patches memory corruption flaws enabling zero-click remote code execution
This digest was compiled by AI from multiple sources — links to the originals are below.

Zoom patches memory corruption flaws in its annotation feature that allowed malicious meeting participants to execute code remotely without clicks or downloads. The vulnerabilities affect all Zoom Workplace versions before July 20 across platforms, including mobile; security experts recommend installing the patch, warning endpoint software cannot reliably block these attacks. Zoom's server-side mitigations will not protect users who have enabled end-to-end encryption.
The Vulnerabilities
Zoom patched a use-after-free flaw tracked as CVE-2026-53415 and a missing bounds check tracked as CVE-2026-53413 in the annotator functionality built into the Zoom client. The company also patched a denial-of-service vulnerability tracked as CVE-2026-53414. The flaws exist in all versions of Zoom Workplace prior to July 20 and across platforms, including mobile devices. Israeli cybersecurity firm A Security said it reported the 'Zoomsday' flaws to Zoom in June after discovering them with just 20 prompts to an offensive AI security harness.
Attack Mechanism
A Security researchers said the flaws let an attacker take complete control of another user's device during a live call without requiring the victim to click anything or download code. A single malicious presenter or participant could infect every other participant, with no visual cue indicating the system had been compromised. Once the code runs, the threat actor could steal personal data, switch on the microphone or camera to spy on the target, or install additional malicious software. Zoom did not immediately respond to a request for comment about further mitigation of these client vulnerabilities.
Mitigation Limits
Security experts recommend installing the patch as the only foolproof defense for the three flaws; according to Douglas McKee, director of vulnerability intelligence at Rapid7, endpoint security software cannot be relied on to spot and block these attacks. For managed environments, McKee advised enforcing minimum client versions rather than relying on users to update themselves. Zoom was already running server-side mitigations to block malicious messages and added fresh blocks to thwart attempts to exploit the new flaws. That protects users on older, vulnerable clients—but if users have enabled Zoom's end-to-end encryption setting, the server-side protections do not work because Zoom cannot inspect the traffic. As a result, attackers could still exploit the flaws in unpatched clients with end-to-end encryption enabled.
What's Next
Zoom has not yet detailed additional mitigations, leaving IT administrators to enforce the July 20 patched client versions across their fleets. It remains unclear how many unpatched users with end-to-end encryption enabled remain exposed to the zero-click attack.
1 source
Zoom patches memory corruption flaws enabling zero-click remote code execution






