# "Zoomsday" Flaws (CVE-2026-53413, CVE-2026-53414, CVE-2026-53415) Let One Zoom Meeting Participant Attack Another

> Three memory-safety bugs in the annotation parser shared by Zoom Workplace, Zoom Rooms, the Zoom Meeting SDK, and the Zoom Workplace VDI Client for Windows let one meeting participant send crafted annotation protocol data to crash another participant's client, leak process memory, or achieve zero-click remote code execution. Israeli research firm A Security ("Zoomsday") built working exploits in under a day using AI-assisted reverse engineering; Zoom shipped client and server-side fixes between June and August 2026 and there is no evidence of in-the-wild exploitation.

- **Published:** 2026-08-12T00:00:00Z
- **Last reviewed:** 2026-08-12T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2001
- **ID:** TL-2026-2001
- **Severity:** CRITICAL (CVSS 8.3)
- **Category:** VULNERABILITY
- **Status:** PATCHED
- **Detections:** 9 · **IOCs:** 15 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-53413, CVE-2026-53414, CVE-2026-53415

## Description

On 2026-08-11 Zoom published three coordinated security bulletins — ZSB-26015, ZSB-26016, and ZSB-26017 — for a cluster of annotation-feature vulnerabilities that Israeli offensive-security firm A Security named "Zoomsday." All three flaws live in the code that deserializes annotation/whiteboard objects Zoom's proprietary protocol passes directly between meeting participants, meaning one attendee can attack another attendee's client without going through any server-side content filter that would normally apply to shared files or chat.

CVE-2026-53413 (CVSS 3.1: 8.3, CWE-787 Out-of-bounds Write) is a stack buffer overflow in the `CAnnoFormatBlock::Deserialize` routine (found in the Android client's `libannotate.so` and its cross-platform equivalents): the function contains four fixed 128-byte buffers but trusts a wire-supplied 32-bit character count when copying into them, so an oversized count overwrites adjacent stack memory including saved registers and the return address. A Security's proof-of-concept sent a 745-byte AddObj protocol data unit (opcode 0x10001, object flags bit 3 for TextFrame) with an oversized fourth channel count (0x100, eight times the 128-byte buffer capacity) to overflow a 704-byte `CAnnoTextFrame` stack variable; on macOS arm64 they hijacked the function epilogue to control registers X19-X30 and pivoted through a single shared-cache gadget (`MOV X0,X19; MOV X1,X21; BL execvp`) to launch Safari with no PAC or stack-canary protection engaged. Register planting placed the gadget address in the link register (X30), the path `/Applications/Safari.app/Contents/MacOS/Safari` in X19, and an argv pointer `{path, NULL}` in X21; one leaked pointer was enough to rebase the entire shared-cache block as a unit and defeat ASLR. On Android, the team sprayed `ExtChild` objects (592-byte heap size class) to place a controlled neighbor object adjacent to the overflow source, then corrupted only the low, ASLR-invariant byte of that neighbor's C++ vtable pointer so a subsequent virtual-call dispatch redirected within the vulnerable module without needing a separate information leak; the corruption was triggered via the un-gated teardown path reachable from RemoveObj/ModifyObj wire operations, which invoke a destructor virtual call on the sprayed object.

CVE-2026-53414 (CVSS 3.1: 6.5, CWE-126 Buffer Over-read) is a companion flaw in the same annotator: Zoom allocates a glyph buffer sized `2 × count + 2` bytes from an attacker-declared character count but fills it from however many bytes actually arrived on the wire (a short body), exposing the uninitialized/adjacent heap tail back to the sender. That leaked memory can contain live code pointers, vtable addresses, and resource strings useful for defeating ASLR in a follow-on exploit chain, and at minimum reliably crashes the receiving client (denial of service).

CVE-2026-53415 (CVSS 3.1: 8.3, CWE-416 Use After Free) involves annotation message type 75 (`CAnnoObjAutoMetaShape`), which deserializes linked-list pointers from network data and unlinks them without validation, producing a write-what-where primitive that can also be driven to remote code execution. Unlike the other two, this bug was found independently by Zoom's own internal Offensive Security team (credited on ZSB-26017) before A Security's report; A Security's own researcher Lidor Elias is credited for its triage.

Underlying all three is a dispatcher validation gap in `CAnnoPduFactory::create`: Zoom's annotation message handler fails to check sender role or message origin, so it accepts AddObj annotation objects (0x10001) from any participant even in contexts meant to be restricted to acknowledgement-only messages (0x10002, differing from AddObj by a single opcode value) — letting an attacker's malformed drawing reach every other attendee in the meeting rather than being filtered. The protocol also routes annotation traffic over a direct, individually addressed channel per participant pair, letting an attacker target one specific victim from the sharer seat rather than broadcasting to the whole meeting.

A Security says it produced working exploits for the RCE-class bugs "in under a day, using fewer than 20 prompts" against publicly available frontier AI models. The workflow began with static analysis: researchers used IDA to disassemble the Android client (build v7.0.4, 121 native libraries) and built an AI-assisted static pre-ranker that scored every function reachable from a JNI entry point against dangerous-sink calls (memcpy/strcpy/sprintf-style copies, computed-size allocators), weighted by CWE severity, function size, and call depth — producing a ranked queue of 3,762 functions across 70 libraries. `libannotate.so` ranked only 45th on that static list; the team pivoted to dynamic tracing with Frida (referred to in A Security's writeup as "Frida MCP") once static ranking alone proved unproductive, exercising each meeting feature live while monitoring library loads and function invocations, which surfaced the annotation feature as the highest-value, protocol-reachable target despite its low static rank. Subsequent AI prompts reverse-engineered the proprietary annotation opcode set by mapping serialize/deserialize function pairs, audited the deserialization routines for memory-safety bugs, helped construct PDU payloads that traversed normal parsing paths, and identified the control-flow-hijack gadgets used on each target architecture. The firm frames the result as evidence that a capability class "previously only available to nation-state threat actors" now has a same-day production barrier; lead researcher Idan Levcovich (credited for CVE-2026-53413/53414) is quoted stating "the barrier to building this class of exploit has collapsed, and it will not come back."

A Security's writeup is explicit about what an attacker inherits once code is running inside the vulnerable process: "Code running inside these applications inherits their permissions, which in a conferencing client means camera, microphone and screen recording," and separately, "Once the nefarious code is running on the victim's device, the threat actor can quietly steal personal data, switch on the microphone or camera to spy on the target, or install other malicious software." The researchers also stress the one-to-many exposure of a single crafted message inside a call: "In a large call, that's a room full of targets from a single message, with no safe seat in it." On the detection side, A Security recommends alerting on a meeting client spawning an unrelated interpreter or browser process — "A meeting client has no reason to launch a browser, a shell or a script interpreter, so block it where you can and alert on it everywhere; our exploit made zoom.us open Safari." None of this — data theft, live audio/video capture, or additional malware installation — was demonstrated beyond the Safari-launch proof-of-concept; A Security frames it as the capability class the RCE unlocks given the OS-level permissions Zoom clients typically hold, not an observed payload.

Zoom rates the bugs High (CVSS 8.3 max) rather than Critical, a gap Zoom and reporters attribute to CVSS requiring User Interaction (UI:R) in the vector for the RCE-class CVEs — i.e., the victim must be in a meeting state where their client is set to receive/render annotation data — while A Security markets the class as "zero-click" because no explicit click or approval is needed beyond that meeting state, and there is no visible cue to the victim that an attack occurred. Zoom's disclosed remediation timeline shows the client-side fix for the CVE-2026-53413/53414 exploit path landing in Zoom Workplace v7.1.0 on 2026-06-22 (about two weeks after the 2026-06-10 report), a server-side mitigation for endpoints that had not yet updated on 2026-07-15, and the CVE-2026-53415 client fix in v7.1.5 on 2026-07-20 — all roughly three weeks to two months ahead of the coordinated public disclosure on 2026-08-11/12. A Security's own remediation notes flag that the 2026-07-15 server-side mitigation depends on Zoom's servers being able to inspect meeting content to filter malformed annotation objects, so meetings running with end-to-end encryption enabled do not benefit from that interim server-side filter and remain exposed until every participant's client is patched. As of publication neither CISA's KEV catalog nor any reviewed source shows in-the-wild exploitation or public weaponized exploit code; A Security's writeup gives exploit construction detail (opcode, buffer sizes, gadget, register planting, heap-spray object sizing) but not a drop-in tool.

## MITRE ATT&CK

- T1587.004 Develop Capabilities: Exploits
- T1588.002 Obtain Capabilities: Tool
- T1588.007 Obtain Capabilities: Artificial Intelligence
- T1203 Exploitation for Client Execution
- T1106 Native API
- T1113 Screen Capture
- T1123 Audio Capture
- T1125 Video Capture
- T1005 Data from Local System
- T1499.004 Endpoint Denial of Service: Application or System Exploitation

## Sources

- ["Zoomsday" flaws could let one Zoom participant attack another](https://www.malwarebytes.com/blog/bugs/2026/08/zoomsday-flaws-could-let-one-zoom-participant-attack-another)
- [Zoom Security Bulletin ZSB-26015 (CVE-2026-53413)](https://www.zoom.com/en/trust/security-bulletin/zsb-26015/)
- [Zoom Security Bulletin ZSB-26016 (CVE-2026-53414)](https://www.zoom.com/en/trust/security-bulletin/zsb-26016/)
- [Zoom Security Bulletin ZSB-26017 (CVE-2026-53415)](https://www.zoom.com/en/trust/security-bulletin/zsb-26017/)
- [ZOOMSDAY](https://a.security/blog/asecurity-zoomsday)
- [Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee's Client](https://thehackernews.com/2026/08/zoom-annotation-flaws-could-let-meeting.html)
- [Zoom Patches Zero-Click Code Execution Vulnerability](https://www.securityweek.com/zoom-patches-zero-click-code-execution-vulnerability/)
- [Zoom Patches "Zoomsday" Zero-Click Flaw Enabling Remote Code Execution](https://securityaffairs.com/197042/hacking/zoom-patches-zoomsday-zero-click-flaw-enabling-remote-code-execution.html)
- [NVD - CVE-2026-53413](https://nvd.nist.gov/vuln/detail/CVE-2026-53413)
- [NVD - CVE-2026-53414](https://nvd.nist.gov/vuln/detail/CVE-2026-53414)
- [NVD - CVE-2026-53415](https://nvd.nist.gov/vuln/detail/CVE-2026-53415)
- [Zoom Zero-Click 'Zoomsday' Flaw Lets Meeting Participants Execute Code on Other Users' Devices](https://gbhackers.com/zoom-zero-click-zoomsday-flaw/)
- [Zoom zero-click flaw allowed RCE attacks during meetings](https://cyberinsider.com/zoom-zero-click-flaw-allowed-rce-attacks-during-meetings/)
- [Zoom Products Multiple Vulnerabilities](https://www.hkcert.org/security-bulletin/zoom-products-multiple-vulnerabilities_20260812)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2001
