A series of severe vulnerabilities found in Zoom’s annotation tool could have allowed attackers in meetings to remotely hijack the devices of unsuspecting participants without any intervention required from them. Disclosed by Israeli cybersecurity experts, this security flaw, dubbed “Zoomsday,” could have led to unauthorized system breaches.
What are the significant risks?
The critical vulnerabilities discovered by A Security primarily affected the annotation system within Zoom. This feature, used for collaborative purposes during meetings, was susceptible to manipulation. Exploiting this flaw enabled attackers to execute dangerous memory-corruption actions on the targeted participant’s device, posing significant security risks.
Designated as CVE-2026-53413 and CVE-2026-53415, Zoom rated these vulnerabilities with high severity scores of 8.3, indicating their potential to permit the execution of malicious code on another user’s system. Another flaw, CVE-2026-53414, received a medium severity classification.
How has Zoom addressed these issues?
Zoom, informed of the threats by A Security in June, responded by upgrading client-side security protocols and architecting a server-side filter to obstruct malicious annotation activity. However, the server-side protection does not extend to end-to-end encrypted sessions, as encryption prevents Zoom from inspecting the transmitted content, leaving certain users susceptible.
- Users on outdated Zoom clients in encrypted meetings remain at potential risk for exploitation.
- Updating to Zoom version 7.1.5 or 7.0.6 is strongly recommended for increased protection.
- The vulnerabilities could compromise access to sensitive cryptocurrency information and digital assets.
The risks became highlighted when THORChain’s co-founder, JP Thor, endured a financial loss of approximately $1.3 million after a compromised Zoom session. In light of this, updating security protocols for Zoom users, particularly those handling cryptocurrencies or delicate data, remains imperative. The discovery underlines the importance of implementing the latest updates promptly to prevent unauthorized access during virtual meetings.



