Particle.news

Zoom Patches “Zoomsday” Zero-Click Flaw

Researchers say publicly available AI tools sped discovery of a memory‑corruption bug that could let an attacker run code on meeting participants’ devices.

Overview

  • A Security reported that it used public AI models in early June to find a zero-click memory corruption bug in Zoom’s annotator feature and developed a working exploit in under a day.
  • The root defects were buffer over‑writes, buffer over‑reads and a use‑after‑free in Zoom’s proprietary annotation protocol that let a malformed annotation message corrupt memory and reach remote code execution.
  • Zoom assigned CVEs including CVE-2026-53413, and rolled out client and server patches for Workplace, Rooms, Meeting SDK and VDI builds before the public writeup appeared on Tuesday, August 11.
  • No confirmed in‑the‑wild exploitation has been reported as of publication, but the flaw could have allowed a meeting participant to silently take control of other attendees’ devices with no user action or visible cue.
  • A Security and Zoom disagree on severity scoring and credit for some fixes, a split that highlights tensions over disclosure practices and the broader debate about how AI lowers the technical barrier to creating high‑impact exploits.