A set of critical vulnerabilities discovered in Zoom’s annotation feature could have enabled malicious participants to remotely execute code on another attendee’s device, without any interaction from the victim.
Critical flaws allow silent device takeover
Israeli cybersecurity company A Security identified the flaws, naming the exploit method “Zoomsday.” Their researcher managed to construct a working exploit in less than a day by leveraging fewer than 20 prompts with commonly available AI models.
The vulnerabilities targeted Zoom’s annotation system, which is used for drawing, adding text, and sharing collaborative elements during meetings. Manipulating the annotation data allowed attackers to trigger dangerous memory-corruption issues on another participant’s computer.
Zoom classified two of the vulnerabilities, CVE-2026-53413 and CVE-2026-53415, as high severity with CVSS scores of 8.3. Both theoretically enabled one user to run malicious code on another participant’s system. A third vulnerability, CVE-2026-53414, received a medium severity rating.
For cryptocurrency holders, such an attack could provide unauthorized access to sensitive resources, including exchange sessions, wallet applications, and confidential data, significantly increasing the risk to digital assets if a device is compromised.
Mini dictionary: CVSS (Common Vulnerability Scoring System) is a standardized method for rating the severity of cybersecurity vulnerabilities, with scores ranging from 0 (low) to 10 (critical).
Zoom’s annotation flaws could let an attacker in the same meeting execute code on another participant’s device with no user action and no link-click required.
Zoom responds, but E2EE poses ongoing risk
A Security first alerted Zoom to the vulnerabilities in June. In response, Zoom issued client-side security updates and implemented a server-side filter to block malicious annotation traffic from reaching vulnerable devices.
However, the researchers cautioned that the server-side defense does not work in end-to-end encrypted meetings because Zoom lacks the ability to inspect encrypted content. As a result, users with outdated clients in encrypted meetings may still be at risk.
Zoom recommended that affected Workplace customers update to at least version 7.1.5 or 7.0.6, according to their update channel. Earlier versions of Zoom Rooms and Meeting SDK are also vulnerable to attack.
| Vulnerability | Severity | Affected Feature |
|---|---|---|
| CVE-2026-53413 | High (8.3) | Annotation system |
| CVE-2026-53415 | High (8.3) | Annotation system |
| CVE-2026-53414 | Medium | Annotation system |
Compromising a computer through Zoom may expose access to cryptocurrency wallets, private keys, or other sensitive digital-asset data stored locally.
Recent crypto sector attack highlights threat
In September 2025, JP Thor, co-founder of decentralized exchange protocol THORChain, reportedly lost approximately $1.3 million after his computer was compromised during a seemingly legitimate Zoom meeting.
With the recently uncovered Zoomsday vulnerabilities, attackers no longer need to convince users to download malicious files or install fake updates. A vulnerable client is enough for unauthorized code execution as soon as an attacker joins the meeting.
Zoom advised all users, especially those handling digital assets or operating in sensitive environments, to update their software to the recommended versions without delay.





USDT
AAPL
