Zoomsday: Zero-click RCE in Zoom, from any meeting participant to any other (CVE-2026-53413)
Zoom's annotation parser read a count off the wire and copied twice that many bytes into a fixed 128-byte buffer with no bounds check, letting any participant corrupt memory on every other client in the call, with no action from the victim.
Fixed in Zoom Workplace 7.1.5 and 7.0.6, VDI 7.0.11 and 6.6.16, Rooms and Meeting SDK 7.1.5.
Disclosure: our team's (A Security) research, reported to Zoom and fixed with them.
u/Key_Emu2269 — 8 days ago