This shocking Zoom bug allowed silent device takeovers on Android and iOS
Aug 12, 2026 — 6:31 AM ET
- A Zoom annotation flaw could let a malicious participant remotely take over another person’s device without any interaction.
- Researchers found and exploited the bug using publicly available AI models in fewer than 20 prompts.
- Zoom has patched the flaws, so updating the Zoom app is the most important thing you can do.
Over the past few months, we have watched frontier AI models rapidly alter the cybersecurity landscape — from AI models breaking technical barriers to mounting regulatory scrutiny over weaponized AI capabilities. Now, a newly disclosed Zoom flaw shows just how serious that can become.
Researchers used undisclosed publicly available AI models to uncover a vulnerability that could have allowed someone on a Zoom call to take control of another participant’s device. The flaw affected Zoom clients on Windows, macOS, Linux, iOS, and Android. Worse, the attack required no click, download, or other action from the victim. Simply being in the same meeting could be enough.
The vulnerability was found in Zoom’s annotation system, which handles features such as drawing and adding text while sharing a screen. A Security discovered (via Wired) that specially crafted annotation data could trigger memory corruption in the receiving client and ultimately enable remote code execution. What’s even scarier is that it took fewer than 20 prompts to find the flaws and produce a working exploit in under 24 hours, something that previously took lots of time and resources.
That puts a real-world example behind growing concerns about AI-assisted security research. The same technology can help defenders find vulnerabilities faster, but it can also reduce the effort required to discover weaknesses in widely used software. Google, for example, is already using AI agents to uncover and help address vulnerabilities in Chrome.
What makes this bug particularly dangerous for everyday users is its zero-click execution and cross-platform reach. The flaw existed inside Zoom’s proprietary screen-sharing annotation engine (libannotate.so), an always-on component that automatically parses incoming drawing and text data. Because the same binary source compiles across all native Zoom Workplace apps, devices running Android, iOS, Windows, macOS, and Linux were equally exposed.
Without requiring any clicks, downloads, or interactions from the victim, an attacker could silently corrupt system memory, extract personal data, activate the device’s camera or microphone, or install secondary malware, undetected.
For Zoom users, there’s a straightforward takeaway: update the app. A Security reported the vulnerabilities to Zoom in June, and the company subsequently deployed client-side and server-side fixes. The flaws are tracked as CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415.
Affected products include Zoom Workplace on all supported platforms before versions 7.1.5 and 7.0.6 in their respective branches, Zoom Workplace VDI Client for Windows before versions 7.0.11 and 6.6.16, Zoom Rooms on all supported platforms before version 7.1.0, and Zoom Meeting SDK on all supported platforms before version 7.1.0.
So, while there’s no indication that ordinary Zoom users need to stop making calls, running an outdated client isn’t worth the risk. If your Zoom app hasn’t updated recently, check for an update before your next meeting.