On August 11, 2026, security firm A Security publicly disclosed three critical memory-corruption vulnerabilities in Zoom's screen-sharing annotation feature — the tool that lets meeting participants draw, highlight, or type on a shared screen. The vulnerabilities, tracked as CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415 and collectively named "Zoomsday," were each scored 9.0 out of 10 on the CVSS severity scale. They affected every version of the Zoom Workplace app up to and including 7.0.5, on every supported platform: Windows, macOS, iOS, Android, and Linux.

The most severe of the three, CVE-2026-53413, is a zero-click remote code execution vulnerability. An attacker who joins or hosts a Zoom meeting can exploit a missing bounds check in the annotation function's text-rendering path to overwrite memory on every other participant's device. No action is required from the victim. No notification appears. No dialogue box asks for permission. The attacker simply joins the call, triggers the annotation tool during screen sharing, and sends a malformed annotation packet. Every device in the meeting that processes it is compromised.

A Security reported the vulnerabilities to Zoom on June 10, 2026. Zoom shipped client-side patches beginning June 22 and deployed a server-side mitigation on July 15. But for every organization that was using Zoom for sensitive meetings between when this bug was introduced and when it was patched, the security property they believed they had — that participants in a call could not attack each other's devices — did not exist.

How the Exploit Works

Zoom's annotation feature uses a proprietary protocol to synchronize drawing and text annotations across all participants in a screen-sharing session. When a participant adds a text annotation, the client sends a format block containing character data in four fixed 128-byte buffers. The parser on each receiving client copies twice the wire-supplied character count into each buffer without checking it against the buffer size.

An oversized fourth count runs past the end of the containing object and, on the stack path, overwrites saved registers and the return address. This is a textbook buffer overflow — a class of vulnerability that has been understood and documented since the 1990s. The attacker controls the overflow content. The overflow overwrites the instruction pointer. The attacker's code executes with the privileges of the Zoom process on the victim's device.

CVE-2026-53414 is a related buffer over-read in the same annotation function, enabling denial-of-service attacks. CVE-2026-53415 is a use-after-free in the annotation memory management path, independently exploitable for remote code execution. Three separate memory safety errors in the same feature, all reachable from the same attack surface, all exploitable by any participant in a meeting.

"The victim does not click a link. The victim does not open a file. The victim does not accept a prompt. The victim joins a meeting. That is the entire attack surface."

AI Built the Exploit in 20 Prompts

The research team that discovered and weaponized the Zoomsday vulnerabilities reported that the full exploit chain was developed using publicly available AI models in fewer than 20 prompts, in under 24 hours. The AI models were used to analyze the annotation protocol, identify the memory corruption paths, and generate working exploit code.

This detail matters more than the vulnerability itself. Zero-click remote code execution vulnerabilities in widely deployed software have existed before. What has not existed before is the ability to discover and weaponize them in under a day using tools available to anyone. The barrier between vulnerability discovery and working exploit — historically measured in weeks or months of specialized reverse engineering — has collapsed to hours.

The implications for organizations that depend on commercial communications platforms are direct. Every platform with proprietary protocol code — every video conferencing tool, every messaging client, every collaboration suite — contains memory management logic that AI-assisted analysis can now probe at a speed that outpaces the vendor's ability to find and fix it first. The Zoomsday disclosure was responsible. The next one may not be.

If an AI can build a zero-click exploit against one of the most widely deployed communications platforms in the world in a single day's work, the security model that depends on trusting the vendor to find its own bugs before adversaries do is no longer a viable model.

What Zero-Click Means for Institutional Communications

The Zoomsday vulnerability is not a phishing attack that targets careless users. It is not a social engineering campaign that relies on human error. It is a flaw in the platform itself that turns participation into exposure. The victim's only action is being in the meeting. The attacker's only requirement is being in the same meeting.

For organizations that conduct sensitive business over Zoom — and there are very many of them — this means that every meeting with an external participant, every webinar with open registration, every all-hands call with a contractor, and every client briefing with a guest link was a potential attack surface for the entire duration this vulnerability existed. A nation-state actor with access to this exploit could join a meeting under any pretence and silently compromise the device of every participant: their laptop, their phone, their tablet. The devices those participants then carry into their next meeting, their office, their classified facility.

This is not a theoretical scenario. This is the operational capability that existed in the gap between when the vulnerability was introduced and when it was patched — a window during which Zoom was used for hundreds of millions of meetings by organizations that believed their participation in a video call did not constitute an attack surface.

"When participation is the attack surface, the only defence is controlling who participates — and that requires infrastructure where identity is verified and access is governed, not a meeting link that anyone can join."

The Vendor Dependency Problem

Zoom's response was, by commercial software standards, competent. The vulnerability was reported on June 10. Client patches shipped twelve days later. A server-side mitigation followed three weeks after that. Zoom communicated the issue and urged users to update. This is what a reasonable vendor response looks like.

It is also a response that happened entirely outside the control of the organizations whose devices were vulnerable. No enterprise security team could have detected this vulnerability in Zoom's proprietary annotation protocol. No IT department could have mitigated it before Zoom shipped the patch. No CISO could have made a risk-informed decision about whether to continue using Zoom during the exposure window, because the exposure window was invisible to them until the public disclosure.

This is the vendor dependency problem. When your organization's communications run on software you did not build, cannot audit, and cannot patch, your communications security is exactly as strong as the vendor's code quality — and you have no visibility into what that code quality actually is until a researcher publishes an advisory or an attacker exploits the flaw.

The Zoomsday vulnerabilities were buffer overflows — a class of bug that has been understood for three decades, that memory-safe languages eliminate entirely, and that static analysis tools routinely detect. They persisted in a platform used by hundreds of millions of people because the code was proprietary, the protocol was undocumented, and external auditors did not have access to it. The AI-assisted researchers who found the bugs in 24 hours did so by analysing the binary. The organizations whose devices were at risk could not have done the same.

What This Means for the Communications Security Decision

The Zoomsday disclosure arrives in the same year that EU officials were ordered to stop using Signal group chats after state-backed spearphishing campaigns, that France's sovereign messaging platform Tchap was breached through a single socially engineered account, and that unsecured Elasticsearch clusters exposed billions of identity records because nobody checked whether authentication was enabled.

The common thread across all of these incidents is not that the technology failed in an exotic or unforeseeable way. The common thread is that the organizations affected had delegated a critical security property — the integrity of their communications — to infrastructure they did not control, could not audit, and could not defend when the failure occurred.

Zoom's annotation protocol had a buffer overflow. Signal's linked devices feature can be exploited through social engineering. Tchap's LDAP layer contained hardcoded credentials. Elasticsearch ships without authentication enabled by default. Every one of these is a known class of failure. Every one persisted because the organization whose data was at risk was not the organization responsible for the code.

The Zoomsday vulnerability is patched. The next zero-click flaw in the next commercial communications platform is not. The question for organizations whose meetings carry genuine consequence is not whether to trust this vendor or that vendor. It is whether the model of delegating communications security to any vendor whose code you cannot see, whose protocols you cannot audit, and whose patches you cannot control is a model that your threat environment still permits.

If your organization conducts meetings where a zero-click compromise of every participant's device would constitute a serious incident, the conversation about communications infrastructure is overdue.

Get in Touch