
Zoom has patched a critical security flaw that could let an attacker remotely take control of another user's device during a live meeting. Researchers discovered a memory-corruption bug in Zoom's annotation feature…
Zoom has patched a critical security flaw that could let an attacker remotely take control of another user's device during a live meeting. Researchers discovered a memory-corruption bug in Zoom's annotation feature affecting all Zoom Workplace clients on supported platforms before versions 7.1.5 and 7.0.6. Three vulnerabilities, tracked as CVE-2026-53413, CVE-2026-53414 and CVE-2026-53415 and collectively dubbed 'Zoomsday', have been identified. Zoom states user interaction is necessary for an attack. Researchers rate the flaws as critical while Zoom rates them high severity. Users should update to the latest version and enable passcodes and waiting rooms.

The 'Zoomsday' label feels like the security industry's instinct to dramatise flaws. While the bug can give an attacker remote control, the attacker must already be in the same meeting and the victim must interact. Zoom downgraded its severity to 'High' instead of 'Critical'. That distinction matters. Users should update to version 7.1.5 or 7.0.6 immediately. The real test will be how many organisations enforce that update this week.
Sources (2): gadgets360.com, timesnownews.com
This story was synthesised by AI from the 2 sources linked above.
Updated: this story now draws on 2 sources.