Zoom Patches Zero-Click Zoomsday Flaws Discovered via AI
Zoom patched three critical vulnerabilities that allowed attackers to remotely control user devices without interaction, discovered by A Security using AI models.
Researchers at the Israeli cybersecurity firm A Security discovered three critical vulnerabilities in Zoom's real-time annotation and screen-sharing protocols, collectively dubbed Zoomsday. The flaws—CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415—enabled zero-click remote code execution, allowing a malicious participant to gain full control of other users' devices during a call without any interaction or warning. The vulnerabilities affected all supported platforms, including Windows, macOS, Linux, iOS, and Android.
A Security reported that they used a publicly available AI security harness to uncover the bugs and develop a working exploit in under 24 hours using fewer than 20 prompts. The firm noted that this process previously would have required months of effort and significant budgets from elite teams, signaling a democratization of nation-state-level hacking capabilities.
Zoom was notified of the flaws on June 10 and acknowledged them the following day. The company deployed client-side fixes in June and server-side mitigations in July, before publicly disclosing the vulnerabilities on August 11. While server-side mitigations are in place, they are ineffective for users with end-to-end encryption enabled. Zoom has urged all users to update to versions 7.1.5 and 7.0.6 or later. Security experts advise that managed environments should enforce minimum client versions and that users should consider browser clients or dedicated virtual machines when calling untrusted parties to reduce exposure.