Executive Summary
A Security identified a series of critical vulnerabilities, collectively termed 'ZOOMSDAY,' affecting Zoom Workplace clients across Windows, macOS, iOS, Android, and Linux. These flaws allow a meeting participant to achieve remote code execution (RCE) on other participants' devices without any user interaction. The attack leverages Zoom's proprietary annotation protocol, which was found to be 'always on' and vulnerable to malformed messages that corrupt memory.
The technical analysis reveals that these nation-state-level exploits were developed in less than 24 hours using publicly available AI models. The vulnerabilities stem from missing bounds checks when deserializing annotation objects, such as text frames and auto-shapes. Zoom has released client-side and server-side mitigations to address these flaws, which are tracked as CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415.
This discovery highlights a significant shift in threat tradecraft, as AI agents have drastically lowered the barrier for developing complex, cross-platform exploits for closed-source software. Organizations are urged to update Zoom clients to version 7.1.5 or later and consider disabling end-to-end encryption (E2EE) if legacy clients cannot be immediately patched, as E2EE bypasses server-side filtering.
Key Details
Threat Name
ZOOMSDAY
Affects
Zoom Workplace (all supported platforms) before 7.1.5, Zoom Workplace VDI Client for Windows before 7.0.11, Zoom Rooms before 7.1.0, Zoom Meeting SDK before 7.1.0, Zoom Workplace (before 7.1.5 and 7.0.6), Zoom Workplace VDI Client for Windows (before 7.0.11 and 6.6.16), Zoom Rooms (before 7.1.0), Zoom Meeting SDK (before 7.1.0)
Adversary
—
Malware/Tools
None identified
