Skip to content
Zoom Patches Three Screen

Zoom Patches Three Screen

Mlq.Ai • August 11, 2026

Zoom has patched three vulnerabilities in the annotation protocol used during screen sharing that could let a meeting participant execute code on another participant’s device without visible interaction from the victim. Zoom published the related security bulletins on Tuesday, August 11, assigning CVE-2026-53413 and CVE-2026-53415 CVSS scores of 8.3 and CVE-2026-53414 a score of 6.5. [1] [2] [3]

The affected software includes Zoom Workplace on supported operating systems, the Windows VDI Client, Zoom Rooms and Zoom Meeting SDK. Zoom’s bulletins direct customers to install the latest releases; the listed fixed-version boundaries include Workplace 7.1.5 or 7.0.6, depending on the branch, VDI Client 7.0.11 or 6.6.16, and product-specific 7.1.0 or 7.1.5 releases. [1] [2] [3]

Zoom’s advisory for CVE-2026-53413 describes a missing bounds check in the annotator function. The company says the flaw could allow a meeting participant to achieve remote code execution on another participant’s device through network access. Zoom rates the vulnerability high severity at 8.3. [1]

CVE-2026-53414 involves a separate buffer over-read in the same annotation function. Zoom rates it medium severity at 6.5 and says it could enable a denial-of-service attack against another participant. CVE-2026-53415 is a use-after-free issue that Zoom rates high severity at 8.3, with potential for remote code execution. [2] [3]

A Security’s technical account says the annotation feature serializes drawings, text and other objects into messages that receiving clients rebuild. The researchers said they found memory-corruption paths in that parser and demonstrated code execution on test devices. They said the issue could work from a viewer to a presenter or from a presenter to participants, depending on the meeting role and communication path. [4]

A Security said it began with Zoom Android client version 7.0.4, which contained 121 native libraries. Its initial static analysis ranked 3,762 functions across 70 libraries, but the researchers then shifted to tracing which code remote meeting participants could actually reach. They used dynamic instrumentation during live calls and focused on the proprietary annotation library, libannotate. [4]

The researchers said publicly available AI models helped map the attack surface, reverse-engineer the annotation protocol and identify memory-safety problems. A Security said the process from initial discovery to a working exploit took fewer than 20 prompts and less than 24 hours. WIRED separately reported the same claim and quoted A Security cofounder Omer Gull. [4] [5]

The AI-assisted discovery claim comes from A Security’s own account of its research, rather than an independent reproduction. Zoom’s advisories confirm the CVE identifiers, vulnerability classes, severity scores and affected products, but do not independently describe the AI methodology. [1] [2] [3]

A Security said it identified the initial vulnerability on June 8, confirmed a working exploit on June 9 and reported it to Zoom on June 10. According to the researchers, Zoom shipped a client-side fix for the first two issues in version 7.1.0 on June 22, deployed a server-side mitigation for older clients on July 15 and shipped a further client fix in version 7.1.5 on July 20. [4]

The public bulletins list the affected-version boundaries. Organizations using Zoom Workplace should move to at least 7.1.5 or 7.0.6 on the applicable branch. VDI Client administrators should use at least 7.0.11 or 6.6.16. Zoom Rooms and Meeting SDK customers should check the separate product-specific minimums in Zoom’s advisories. [1] [2] [3]

A Security said its server-side filtering did not protect end-to-end encrypted meetings because Zoom’s servers cannot inspect encrypted annotation messages. The researchers recommended temporarily disabling end-to-end encryption for older, unpatched clients while completing updates. They also advised restricting meeting access, using waiting rooms and authenticated-user controls, limiting screen sharing and reviewing whether annotation and related collaboration features are necessary. Those are researcher recommendations; Zoom’s bulletins specifically direct users to apply the latest updates. [1] [4]

The materials reviewed for this report do not provide evidence that the vulnerabilities were exploited in attacks before disclosure. The exposure was narrower than an internet-wide attack because the attacker had to join the meeting, but the victim did not need to interact with the malicious traffic after the attacker was present. [4] [5]

Extracted Entities