someone could take over your Zoom call with zero clicks — Zoom already fixed it, but only if you update

a bug called 'Zoomsday' let any meeting participant silently run code on your Mac or iPhone. researchers built the working exploit using an AI model…

Aliteq
Priya Nair · Software & Systems Editor

What you need to know right now

CVE-2026-53413 ('Zoomsday') is a zero-click flaw in Zoom's annotation engine, rated high severity by Zoom's own security team — full code execution with no user interaction required.

What you need to know right now

Three related bugs were disclosed alongside it: CVE-2026-53414 (medium, memory leak), CVE-2026-53415 (high, use-after-free), CVE-2026-53416 (high, VDI path traversal).

What you need to know right now

All four are already fixed. Update to Zoom Workplace 7.1.5/7.0.6, Zoom Rooms 7.1.5, or Meeting SDK 7.1.5 to close the annotation bugs.

What you need to know right now

Security firm A Security says it found the flaw and built a working exploit using publicly available AI models with fewer than 20 prompts, in under 24 hours.

What you need to know right now

On macOS, researchers demonstrated the exploit by silently launching Safari on a victim's machine — proof of full, invisible code execution.

My honest take

The zero-click part is what makes headlines, but CVE-2026-53416 quietly worries me more for enterprise environments — path traversal bugs in VDI deployments tend to sit unpatched far longer than…

Aliteq

Read the full story

someone could take over your Zoom call with zero clicks — Zoom already fixed it, but only if you update

Read the full story on Aliteq