ZeroHour
Vendor

Zoom

2 mentions in 7 days · 2 in 30 days · 5 total · first seen · last

Timeline

Linux Zoom Client Proactively Reads X11 Clipboard

Simon Tatham reports that Zoom's Linux client proactively reads the X11 clipboard, potentially exposing copied passwords and other sensitive data.

A Mastodon post by Simon Tatham, shared via Lobsters, reports that the Linux Zoom client proactively reads the X11 system clipboard rather than accessing it only on explicit paste. Because X11 allows any running application to query clipboard contents, secrets such as copied passwords or tokens may be captured by the app. The observation highlights the broader privacy gap between X11's unrestricted clipboard access and more restricted display servers like Wayland.

Lobsters · security · 3d agoResearch1

New N0va Phishkit Targets North America and EU: A Growing Identity Risk for SOCs

ANY.RUN researchers uncovered the N0va phishkit targeting government, technology, consulting, and healthcare organizations across North America and the EU via device code phishing.

The N0va phishkit uses lures imitating Microsoft Teams, SharePoint, OneDrive, DocuSign, Google Drive, Dropbox, Zoom, and Adobe Sign to draw victims into a device code authentication flow. After the user completes legitimate authentication, N0va captures access and refresh tokens and abuses token-exchange and device-registration mechanisms to establish persistent SSO access to corporate resources. Because the flow relies on real Microsoft authentication, it can evade MFA-focused detections, and token access can outlive takedown of the phishing page. ANY.RUN says it observed the campaign in sandbox sessions, with targeting spanning government, technology, consulting, and healthcare sectors.

Cyber Security Newsupdated · 4d agofirst · 6d agoPhishing & fraud in the wild 13 sources

Researchers found a way to hijack devices through Zoom screen sharing

Researchers used a public AI tool to find a Zoom flaw enabling device hijacking via screen sharing in under 20 prompts.

Security researchers discovered a serious vulnerability in Zoom that can be used to hijack devices through the screen-sharing feature. The flaw was reportedly found by a publicly available AI tool in fewer than 20 prompts, highlighting the role of agentic AI in vulnerability discovery. The article does not report active exploitation or assign a CVE in the provided text.

Ars Technica · Security · Aug 12, 2026Vulnerability

Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee's Client

A Security researchers disclosed three Zoom annotation flaws enabling zero-click client hijacking; Zoom shipped fixes in June and July with no exploitation reported.

Researchers at A Security found three flaws in Zoom's annotation feature: CVE-2026-53413 (CVSS 8.3, buffer over-write), CVE-2026-53414 (CVSS 6.5, buffer over-read), and CVE-2026-53415 (CVSS 8.3, use-after-free). A crafted drawing object sent over the wrong message channel can overwrite adjacent memory and hijack another attendee's client with no user interaction. Fixes shipped in Zoom Workplace 7.1.5/7.0.6, VDI Client 7.0.11/6.6.16, and Zoom Rooms/Meeting SDK 7.1.0+ during June and July. No exploitation has been reported and the flaws are absent from CISA's Known Exploited Vulnerabilities catalog.

Zoom Patches “Zoomsday” Zero-Click Flaw Enabling Remote Code Execution

Zoom patched CVE-2026-53413, a zero-click annotation flaw dubbed "Zoomsday" allowing remote code execution on meeting participants' devices across all platforms.

Zoom patched four vulnerabilities, including CVE-2026-53413, a stack buffer overflow in CAnnoFormatBlock::Deserialize in the annotation protocol that allows zero-click remote code execution on another participant's device. A Security also found CVE-2026-53414, a buffer overread enabling denial-of-service crashes, and CVE-2026-53415, a use-after-free Zoom had already discovered internally. Updates shipped for Workplace 7.1.5 and 7.0.6, Rooms 7.1.5, and Meeting SDK 7.1.5 across all supported platforms.

Related CVEs

  • Out-of-Bounds Write in Zoom Clients Enables Participant-to-Participant RCE
    Zoom has fixed an out-of-bounds write (CWE-787) in the annotator function of its client applications, tracked as CVE-2026-53413. A meeting participant can trigger the missing bounds check remotely through the annotation feature, causing a buffer over-write in another attendee's client; per the CVSS vector, user interaction and high attack complexity are required. Successful exploitation may allow the attacker to execute code on the victim's machine with that user's privileges, effectively hijacking another participant's client from within the same meeting. Anyone running a vulnerable Zoom Client (the platform's desktop and mobile apps, used by an extremely large user base) is potentially affected until patched. There is no public proof-of-concept, the flaw is not yet in CISA's KEV catalog, and no exploitation in the wild is known, though an EPSS of 5.6% (92nd percentile) indicates meaningful exploitation potential.
    · Zoom Clients (client applications)mass
  • Use-After-Free in Zoom Client Annotator Enables Participant-to-Participant RCE
    CVE-2026-53415 is a use-after-free vulnerability (CWE-416) in the annotator function of Zoom Clients, scored 8.3 (High) with a network attack vector and changed scope. It is triggered when one meeting participant sends crafted annotation input that another participant's Zoom client processes, allowing an attacker in the meeting to corrupt memory in a fellow attendee's client; the CVSS vector marks user interaction as required and attack complexity as high, while press coverage describes the flaw as zero-click for the victim. A successful attack yields remote code execution on the other participant's client, with high impact to confidentiality, integrity, and availability. Anyone using Zoom Clients who joins meetings with untrusted participants where annotation is available is potentially affected. Exploitation status: not in CISA KEV, no public PoC, EPSS estimates only a 0.5% probability of exploitation in the next 30 days (44th percentile), and Zoom has already patched the flaw.
    · Zoom Clients (annotator function)mass
  • Missing bounds check in the annotator function of Zoom Clients allows buffer over-read, which may allow a meeting participant to conduct a denial of service on
    Missing bounds check in the annotator function of Zoom Clients allows buffer over-read, which may allow a meeting participant to conduct a denial of service on another participant via network access.

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.