Israeli cybersecurity firm A Security has disclosed that researchers used publicly available AI models to uncover vulnerabilities in Zoom's annotation tool and build a working exploit in under 24 hours, using fewer than 20 prompts. The three flaws—tracked as CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415—allow an attacker to join or host a meeting without any victim interaction or visible warning, then target any participant and take over their device. Tests covered Zoom's Windows, macOS, Linux, Android, and iOS apps. Once a device is compromised, an attacker can steal personal data, turn on the microphone or camera, or install additional malware. A Security first reported a vulnerability to Zoom on June 10; Zoom shipped fixes between June 22 and July 20. Because server-side protections can't filter malicious messages in end-to-end encrypted meetings, users are still advised to update to the latest version. Decrypt reported the research.
Israeli security firm A Security says researchers used publicly available AI models to find bugs in Zoom's annotation tool and build a working exploit in under 24 hours, using fewer than 20 prompts.
Three flaws, no victim action required
The vulnerabilities are tracked as CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415. An attacker can join or host a meeting, target any participant, and take over their device. No victim interaction or visible warning is needed.
Tests covered Zoom's Windows, macOS, Linux, Android, and iOS apps. Once a device is compromised, an attacker can steal personal data, turn on the microphone or camera, or install additional malware.
Patch timeline and update warning
A Security reported the first vulnerability to Zoom on June 10. Zoom issued fixes between June 22 and July 20.
Server-side protections in end-to-end encrypted meetings cannot filter malicious messages, A Security noted, so users still need to update to the latest version. Decrypt reported the research.
This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan. Disclaimer:
The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.
Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.