Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Šefčovič: Verhandlung mit China noch ohne Ergebnisse – POLITICO

    October 2, 2026

    Welsh first minister calls on Burnham to deliver ‘new deal’ on devolution | Rhun ap Iorwerth

    October 2, 2026

    Conservatives aim to be election-ready ahead of party conference

    October 2, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Šefčovič: Verhandlung mit China noch ohne Ergebnisse – POLITICO
    • Welsh first minister calls on Burnham to deliver ‘new deal’ on devolution | Rhun ap Iorwerth
    • Conservatives aim to be election-ready ahead of party conference
    • Decisions taken by the Governing Council of the ECB (in addition to decisions setting interest rates)
    • Laytr’s new app lets you save anything you find online, not just articles to read
    • Datalab Introduces OmniExtractBench to Fix Bias and Opacity in Extraction Benchmarks
    • US sanctions Tren de Aragua gang members in ATM hacks crackdown
    • EU Issuers Explain Why Europe Needs US Dollar Stablecoins
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Friday, October 2
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee’s Client

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 13, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Swati KhandelwalAug 11, 2026Vulnerability / Software Security

    Anyone sharing their screen on a Zoom call could have taken over the computers of everyone watching, and anyone watching could have taken over the presenter’s.

    The flaw sat in the annotation tool, the feature that lets participants draw and type on a shared screen, and it asked nothing of the victim beyond being in the meeting. No click, no download, no prompt, and nothing on screen to show it had happened.

    The patches are not new. Client fixes shipped in June and July, roughly two months before the flaws were made public, and no exploitation has been reported as of publication. None of the three identifiers appear in CISA’s Known Exploited Vulnerabilities catalog.

    The versions that close them:

    • Zoom Workplace, all supported platforms, before 7.1.5 and 7.0.6 in their respective branches
    • Zoom Workplace VDI Client for Windows, before 7.0.11 and 6.6.16
    • Zoom Rooms and Zoom Meeting SDK, all platforms, before 7.1.0, and before 7.1.5 for the third flaw

    The research came from “A Security,” an Israeli-founded offensive-security startup that left stealth in June with $37 million in funding. It says it went from finding the flaw to a working exploit in under a day, using fewer than 20 prompts on publicly available AI models.

    Nobody outside the company can check that claim: the writeup names no model. The vendor also rates the bugs lower than the firm does, and credits one of the three to its own internal team.

    Cybersecurity

    Zoom has published no technical detail, so the internals come from the firm’s own reverse engineering. A drawing does not cross the network as a picture. The client turns it into a structured object and sends it as a run of counts followed by data, and the receiver trusts those counts to decide how much to read.

    One of them fills a fixed 128-byte buffer with no check that the data fits, and because it is the object’s last field, an oversized count runs past the end and over the return address.

    What makes one malformed drawing reach the whole room is a missing check on where a message came from. Every viewer holds a channel to whoever is sharing, and the sharer holds one back that is meant to carry acknowledgements.

    On the paths the researchers traced, the dispatcher reads a message’s type number off the wire and hands it to the matching parser without asking which seat the sender occupied. 0x10001 means here is an object; 0x10002 means I received yours. Send the first where the second belongs, and the victim’s client rebuilds the object in full.

    Zoom tracks the flaws as CVE-2026-53413 (CVSS score: 8.3), a buffer over-write, and CVE-2026-53414 (CVSS score: 6.5), a buffer over-read, both covered by ZSB-26015 and ZSB-26016, plus CVE-2026-53415 (CVSS score: 8.3), a use-after-free, in ZSB-26017.

    The firm puts all three at 9.0 under CVSS 4.0, a score that appears in none of the bulletins. Zoom issues its own CVE records, and NIST no longer routinely re-scores them, so the lower figures will likely stand. All three vendor vectors also mark user interaction as required, which sits badly beside the zero-click framing.

    The two accounts diverge furthest on the over-read. The firm says it recovered uninitialized heap memory from a victim’s client holding live code and vtable pointers, the material an address-randomization bypass needs.

    Cybersecurity

    The advisory says the same bug may let a participant “conduct a denial of service,” and scores its confidentiality impact at none. Credit splits as well: two bulletins name Idan Levcovich of A Security, while the one covering the use-after-free credits Zoom Offensive Security, the in-house team behind the 9.8-rated account takeover flaw the company patched in July.

    The startup’s post lists all three as its own, while acknowledging that Zoom already knew about the third and had filtered it server-side before the report arrived. Its account of the AI work is also messier than its own summary.

    The first pass, an automated ranking of functions reachable from the Java layer, produced a queue of 3,762 functions across 70 libraries and missed the vulnerable library completely, ranking it 45th. It surfaced only when they traced the running client through a live call, feature by feature. Levcovich writes that the barrier to building this class of exploit “has collapsed, and it will not come back.”

    The disclosure follows OpenAI splitting its Daybreak program a day earlier and releasing GPT-5.6-Cyber to vetted partners only, on the argument that this capability needs gating. The startup says it got its result from models anyone can use. By OpenAI’s own measure, its guardrailed public model answers 1.5% of advanced offensive-security prompts, against 95% for the restricted one.

    Annotation attendees client flaws hijack meeting Participant Zoom
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    US sanctions Tren de Aragua gang members in ATM hacks crackdown

    Vulnerability Backlogs Are an Ownership Problem

    macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor

    OpenAI Parts Ways With Three Safety Researchers Over Sensitive Information Mishandling

    Android 17 Advanced Protection Locks Accessibility Services to Verified Accessibility Tools

    Microsoft’s X account hacked in crypto pump-and-dump scheme

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Šefčovič: Verhandlung mit China noch ohne Ergebnisse – POLITICO

    October 2, 2026

    Welsh first minister calls on Burnham to deliver ‘new deal’ on devolution | Rhun ap Iorwerth

    October 2, 2026

    Conservatives aim to be election-ready ahead of party conference

    October 2, 2026

    Decisions taken by the Governing Council of the ECB (in addition to decisions setting interest rates)

    October 2, 2026
    Latest Posts

    Lime bikes hurtling around the city: is this the revenge of a priced-out generation? | Andy Beckett

    August 8, 2026

    Clarity Act Delayed Until September, Trump Praises Bitcoin

    August 8, 2026

    North Carolina Ports confirms cyberattack disrupting operations

    August 8, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Šefčovič: Verhandlung mit China noch ohne Ergebnisse – POLITICO

    October 2, 2026

    Welsh first minister calls on Burnham to deliver ‘new deal’ on devolution | Rhun ap Iorwerth

    October 2, 2026

    Conservatives aim to be election-ready ahead of party conference

    October 2, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.