Zoom Annotation Flaw Let Attendees Hijack Peers

Zoom patched four vulnerabilities in its annotation feature, including CVE-2026-53413, a zero-click remote code execution bug that could let one meeting participant run code on another attendee’s client. The fixes cover Zoom Workplace, Zoom Rooms, the Meeting SDK, and the Windows VDI client. The issue is in the annotator protocol that moves drawing and text messages between the screen sharer and viewers. Zoom clients trusted those messages enough to parse them automatically, so a crafted annotation packet could overflow memory on the receiving side with no click or visible prompt. That means compromise could happen one attendee at a time, inside an ordinary meeting. For organizations that use screen sharing and live annotation, the exposure sits in the collaboration channel itself, not just in the host or room device. Even after patching, the trust model changes: any app that auto-parses one user’s messages on another user’s client has to be treated as part of the attack surface.

Part of the PlainSec briefing for 2026-08-12

Every edition of this story: Zoom Annotation Flaw Let Attendees Hijack Peers

Sources