the annotation
A team of researchers at A Security has built a program that can silently take control of every device in a Zoom meeting. They called it Zoomsday.
I want to explain what "zero-click" means, because the phrase has been used so often that people have stopped hearing what it says. A zero-click exploit means the attack runs without the victim doing anything. No link clicked. No file opened. No suspicious attachment accepted. You are simply present in the meeting. This is sufficient. The attack executes because you are there, which is the most unsettling element of it, because being present in the meeting is the one thing you had agreed to do.
The vector is Zoom's annotation feature. (The annotation feature is the tool that lets meeting participants draw lines, highlight sections, and type notes on a shared screen — a feature you have seen used primarily to circle a number, drag an arrow toward the circle, and then ask whether everyone can see where the arrow is pointing.) This tool contained three distinct vulnerabilities. They are designated CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415. Together, they allow an attacker who is also a participant to achieve remote code execution on every other device in the meeting, simultaneously, without warning, without a click, through the annotation protocol.
I am not making this up. I read the disclosure. I double-checked by reading it again.
The researchers at A Security developed a working exploit in under twenty-four hours using fewer than twenty prompts with publicly available AI models. A security professional I have not spoken to, because I did not speak to anyone for this article, would note that this same work previously required a team of five people and approximately six months. I do not want to perform the division here. The result is familiar to anyone who has watched something go from expensive to free in under a decade. The calculation completes itself.
Zoom patched the vulnerabilities on August 11, 2026 (bulletins ZSB-26015 through ZSB-26018). The remediation path is direct and available: update to Zoom Workplace version 7.1.5. This takes approximately forty-five seconds. The threat is neutralized. The annotation feature continues to work exactly as before — the arrow still points at the circle, the circle still needs to be seen by everyone.
The alternative, which I am not recommending, is to stop attending Zoom meetings. Many of you have been trying to do this for years without needing a named vulnerability as the reason. You now have one, if briefly. The window is narrow — version 7.1.5 is already out. But for a few more weeks, before your IT department pushes the patch, there is an argument available that no one can fault you for making. I will leave the wording to you.