Zoom annotation tool flaws (multiple vulnerabilities)
Vulnerability
Summary
Hide ▲
Show ▼
Zoom's annotation tool flaws could let one meeting participant compromise another attendee's client across supported Zoom Workplace, Zoom Workplace VDI Client for Windows, Zoom Rooms, and Zoom Meeting SDK builds. The issues are tracked as CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415, covering a buffer over-write, a buffer over-read, and a use-after-free condition. Fixes shipped in June and July 2026 before the public disclosure, and the company says no exploitation has been reported. The affected flows rely on annotation messages in shared-screen meetings, where the receiver trusts the sender enough to rebuild the object in full.
Related Happenings
CISA expands KEV catalog and sets February 16 remediation deadline
Public Sector Action
H score34
First: 27.01.2026 12:37
Last: 27.01.2026 12:37
Sources 1
About this happening:
CISA expanded the KEV catalog with five flaws and told federal agencies to fix them by February 16, tightening remediation pressure for vulnerabilities already tie...
CISA expands KEV catalog and sets February 16 remediation deadline
Public Sector ActionAbout this happening: CISA expanded the KEV catalog with five flaws and told federal agencies to fix them by February 16, tightening remediation pressure for vulnerabilities already tie...
Timeline
-
11.08.2026 22:08 2 articles · 2h ago
Zoom annotation tool flaws could hijack meeting participants' clients
Initial DisclosureZoom Workplace, Zoom Workplace VDI Client for Windows, Zoom Rooms, and Zoom Meeting SDK were affected by three annotation tool vulnerabilities tracked as CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415; the flaws could let one meeting participant take over another attendee's client during a shared-screen call, with the vulnerable builds fixed before 7.1.5 and 7.0.6 in their branches, before 7.0.11 and 6.6.16, and before 7.1.0 or 7.1.5 depending on the product line. Client fixes had already shipped in June and July 2026, and none of the identifiers appear in CISA's Known Exploited Vulnerabilities catalog.
Show sources
- Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee's Client — thehackernews.com — 11.08.2026 22:08
- Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee's Client — thehackernews.com — 11.08.2026 22:08