Zoom Fixes Critical Security Flaw That Could Let Attackers Remotely Control Users' Devices

The vulnerabilities in Zoom are tracked as CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415 with critical 9.0 CVSS:4.0 scores.

Advertisement
Written by Nithya P Nair, Edited by Rohan Pal | Updated: 12 August 2026 15:42 IST
Highlights
  • Cybersecurity researchers discovered a critical vulnerability in Zoom
  • The flaw was found in Zoom’s annotation feature
  • The researchers said they developed a working exploit in under 24 hours

The bug affects Zoom clients across Windows, macOS, iOS, Android and Linux

Photo Credit: Zoom

Cybersecurity researchers have discovered a critical vulnerability in Zoom that could allow attackers to control another user's device during a live call. The flaw is said to be linked to Zoom's screen-sharing feature. This latest bug seems to have affected the Zoom app across all operating systems. The vulnerability exists in all versions up to and including 7.0.5. The researchers confirmed that Zoom was informed about the bug and has deployed various fixes to mitigate the threat. The researchers claimed that they developed a working exploit using fewer than 20 prompts with publicly available AI models.

Zoom Security Flaw Puts Users at Risk

Security researchers at A Security discovered a critical flaw in Zoom that could allow an attacker to take full control of another user's device during a live meeting without any action from the victim. The latest blog post shared on the company website states that the vulnerability is a memory-corruption bug that exploits Zoom's annotation feature.

Advertisement

Researchers at A Security claim that the bug affects Zoom clients on Windows, macOS, iOS, Android, and Linux with versions before 7.1.5. Zoom clients using end-to-end encryption settings in version 7.0.6 also remain affected. Once exploited, attackers can either join or host a meeting, target any participant, and take over their machine with no required action from the victim and no visual cue indicating the compromise.

The threat actor can steal personal data, switch on the microphone or camera to spy on the target, or install other malicious software once the nefarious code is running on the victim's device.

Advertisement

The researchers said the entire operation, including finding the flaw and building a working exploit, "was carried out using fewer than 20 prompts on publicly available AI models in under 24 hours".

The platform states that it has collaborated with Zoom to address the issue and reported the vulnerability to Zoom in June THIS year. The vulnerabilities are listed as CVE-2026-53413, CVE-2026-53414 and CVE-2026-53415, and Zoom has acknowledged receipt and released fixes. The cloud-based video conferencing and communication platform says, "Users can help keep themselves secure by applying the latest updates."

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Zoom, A Security
Advertisement

Related Stories

Popular Mobile Brands
  1. Lava Virat Curve vs Poco M8 Power vs Vivo T5 Lite:
  1. Magic Eden Investigates Possible Exploit After NFTs Move for 0 ETH
  2. Amazon Great Indian Festival 2026: Early Deals Are Now Live on OnePlus N6x, iQOO Z10 Lite 5G, and More
  3. Marking 12 Years of Make in India, Gov't Targets the Brains Inside Our Smartphones
  4. Google Photos Update Brings Redact Tool, Moods and AI Wardrobe
  5. Halo Studios Reportedly Has Around 30 Employees Left After Layoffs as Activision Takes Charge of Franchise
  6. KelpDAO Sues LayerZero Over $292 Million rsETH Exploit, Claims Bridge Risks Were Not Disclosed
  7. OpenAI Plans to Launch a New Cybersecurity-Focused GPT-6 Series AI Model: Report
  8. Vivo V80 Price in India Leaked Ahead of October 6 Launch: What You Need to Know
  9. Infinix GT NX Controller With Pixel-Level FPS Touchpad, GT NX Station Cooling Dock Unveiled
  10. Bitget Suffers $351.6 Million Security Breach, Exchange Says No Private Keys Were Leaked
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.