Zoom Fixes Four Annotation Flaws After Disclosure

Dutch NCSC said Zoom has patched four annotation-related flaws in Zoom Client and Zoom VDI Client, including CVE-2026-53413, after the bugs were already public. The advisory moves the story from discovery to deployment: the question now is which fleets have actually picked up the fixes. The bug sits in Zoom's annotator protocol, where one participant's drawing or text messages are parsed by another client's app as normal collaboration data. That trust boundary matters because malformed annotation traffic can crash the receiving client or overwrite memory, so one meeting participant can reach another attendee's device through the meeting itself. For organizations that rely on screen sharing and live annotation, the exposed surface is the collaboration channel, not just the host machine or meeting room device. Until the patched clients are widely in place, any meeting with an unpatched participant keeps that peer-to-peer trust path in play.

Part of the PlainSec briefing for 2026-08-13

Every edition of this story: Zoom Fixes Four Annotation Flaws After Disclosure

Sources