Three Zoom flaws let a meeting participant take over another attendee's device
Researcher Idan Levcovich of Israeli offensive-security firm A Security disclosed three Zoom vulnerabilities on August 11, 2026, tracked as CVE-2026-53413, CVE-2026-53414 and CVE-2026-53415, that let any meeting participant take over another attendee's device via malformed drawing objects sent through screen-share annotation, with no click or download on the victim's side. Zoom rates two of the flaws 8.3 while A Security rates all three 9.0; patches shipped in June and July for Zoom Workplace, the Workplace VDI client, Zoom Rooms and the Meeting SDK, and no exploitation has been reported. A Security says it built a working exploit using publicly available AI models, fewer than 20 prompts and under 24 hours, though its automated pass over 3,762 functions missed the vulnerable code and a human found it.