Zoom Fixes Critical Security Flaw That Could Let Attackers Remotely Control Users' Devices

The vulnerabilities in Zoom are tracked as CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415 with critical 9.0 CVSS:4.0 scores.

Advertisement
Written by Nithya P Nair, Edited by Rohan Pal | Updated: 12 August 2026 15:42 IST
Highlights
  • Cybersecurity researchers discovered a critical vulnerability in Zoom
  • The flaw was found in Zoom’s annotation feature
  • The researchers said they developed a working exploit in under 24 hours

The bug affects Zoom clients across Windows, macOS, iOS, Android and Linux

Photo Credit: Zoom

Cybersecurity researchers have discovered a critical vulnerability in Zoom that could allow attackers to control another user's device during a live call. The flaw is said to be linked to Zoom's screen-sharing feature. This latest bug seems to have affected the Zoom app across all operating systems. The vulnerability exists in all versions up to and including 7.0.5. The researchers confirmed that Zoom was informed about the bug and has deployed various fixes to mitigate the threat. The researchers claimed that they developed a working exploit using fewer than 20 prompts with publicly available AI models.

Zoom Security Flaw Puts Users at Risk

Security researchers at A Security discovered a critical flaw in Zoom that could allow an attacker to take full control of another user's device during a live meeting without any action from the victim. The latest blog post shared on the company website states that the vulnerability is a memory-corruption bug that exploits Zoom's annotation feature.

Advertisement

Researchers at A Security claim that the bug affects Zoom clients on Windows, macOS, iOS, Android, and Linux with versions before 7.1.5. Zoom clients using end-to-end encryption settings in version 7.0.6 also remain affected. Once exploited, attackers can either join or host a meeting, target any participant, and take over their machine with no required action from the victim and no visual cue indicating the compromise.

The threat actor can steal personal data, switch on the microphone or camera to spy on the target, or install other malicious software once the nefarious code is running on the victim's device.

The researchers said the entire operation, including finding the flaw and building a working exploit, "was carried out using fewer than 20 prompts on publicly available AI models in under 24 hours".

The platform states that it has collaborated with Zoom to address the issue and reported the vulnerability to Zoom in June THIS year. The vulnerabilities are listed as CVE-2026-53413, CVE-2026-53414 and CVE-2026-53415, and Zoom has acknowledged receipt and released fixes. The cloud-based video conferencing and communication platform says, "Users can help keep themselves secure by applying the latest updates."

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Zoom, A Security
Advertisement

Related Stories

Popular Mobile Brands
  1. Android 17 Update: These Motorola Phones Are Eligible
  2. iQOO Neo 11 Ultra Will Launch With This 2K Resolution Display
  3. Amazon Freedom Sale 2026: Check Best Last-Minute Smartphone Deals
  4. Amazon Great Freedom Sale 2026: Top Deals on Gaming Peripherals
  5. Realme 16x 5G Review: Aesthetics With a Big Battery Bet
  6. Amazon Great Freedom Sale 2026: Best Deals on Storage Devices
  7. Redmi Note 17 Now on Sale in India With Rs. 3,000 Bank Discount
  8. iPhone 18 Pro Launch Might Bring Price Hike to All iPhone Models
  9. Realme 16x 5G Debuts in India With MediaTek Dimensity 6300 SoC
  1. Bumble Changes Its Women-First Dating Model, Now Lets Anyone Send the First Message
  2. Amazon Great Freedom Sale 2026: Best Deals on Storage Devices
  3. Amazon Great Freedom Sale 2026: Best Deals on Smartphones Under Rs. 20,000
  4. BGMI Redeem Codes: How to Claim Mecha Ant Backpack, Free Rewards, Skins, UC, and More
  5. Vivo X500, iQOO 16 Reportedly Get 3C Certification Ahead of Expected Launch
  6. Vivo X300 FE Launches in New 8GB RAM, 256GB Storage Variant in India: Price, Specifications
  7. Zoom Fixes Critical Security Flaw That Could Let Attackers Remotely Control Users' Devices
  8. XRP Bridge Hit by $200,000 Loss as Software Accepts Fake Deposits
  9. Phantom Blade Zero Is Getting a Gameplay Deep Dive at Sony's Next State of Play Show Next Week
  10. Motorola Rolling Out Android 17 Update to Razr, Edge and Moto G Phones
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.