Three Zoom flaws let a meeting participant take over another attendee's device
Three flaws in Zoom’s annotation tool let any meeting participant take over another attendee’s device. The patches are already out, which makes updating the entire fix.
The vulnerability chain
Researcher Idan Levcovich of the Israeli offensive-security firm A Security disclosed the chain on August 11, 2026. Tracked as CVE-2026-53413, CVE-2026-53414 and CVE-2026-53415, the bugs are triggered by malformed drawing objects sent through screen-share annotation. No click, no download, no prompt on the victim’s side. Zoom rates two of the flaws 8.3; A Security rates all three 9.0.
The affected list covers most of the product line: Zoom Workplace before 7.1.5 and 7.0.6, the Workplace VDI client for Windows before 7.0.11 and 6.6.16, and Zoom Rooms and the Meeting SDK before 7.1.0 and 7.1.5. Zoom shipped patches in June and July, two months ahead of disclosure, and no exploitation has been reported.
The AI-assisted exploit, with an asterisk
The detail that matters beyond Zoom is how the exploit got built. A Security says it used publicly available AI models, fewer than 20 prompts and under 24 hours to produce a working exploit. The firm named no specific models.
The asterisk is just as instructive. A Security’s automated ranking pass over 3,762 functions missed the vulnerable code entirely. A human researcher found it by tracing live client calls. So the honest division of labor in this case: AI did not find the bug, but once a human found it, AI compressed exploit development from a specialist project into a day’s work with a chatbot.
What to take from it
Both halves of that finding should update assumptions. Defenders lose the comfortable lag between disclosure and weaponization if exploit development now takes hours, which raises the cost of slow patching. At the same time, the discovery step, the actual security judgment, still belonged to a human in this case, so claims of fully automated vulnerability research remain ahead of the evidence.
For users and IT teams the action item is unusually clean. The fixes have been shipping since June. Updating the client closes the whole chain.
Sources
ANOTHER News is published by ANOTHER, an AI-native content agency. Daily coverage also runs on Instagram.