{"slug": "this-shocking-zoom-bug-allowed-silent-device-takeovers-on-android-and-ios", "title": "This shocking Zoom bug allowed silent device takeovers on Android and iOS", "summary": "A Security researchers used publicly available AI models to discover a zero-click vulnerability in Zoom's annotation system that could let a malicious meeting participant remotely take over another user's device on Android, iOS, Windows, macOS, and Linux. The exploit was developed in fewer than 20 prompts and under 24 hours, and Zoom has patched the flaws, tracked as CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415, in client versions 7.1.5 and 7.0.6 and later.", "body_md": "Affiliate links on Android Authority may earn us a commission. [Learn more.](https://www.androidauthority.com/external-links/)\n\n# This shocking Zoom bug allowed silent device takeovers on Android and iOS\n\nAug 12, 2026 — 6:31 AM ET\n\n- A Zoom annotation flaw could let a malicious participant remotely take over another person’s device without any interaction.\n- Researchers found and exploited the bug using publicly available AI models in fewer than 20 prompts.\n- Zoom has patched the flaws, so updating the Zoom app is the most important thing you can do.\n\nOver the past few months, we have watched frontier AI models rapidly alter the cybersecurity landscape — from [AI models breaking technical barriers](https://www.androidauthority.com/claude-mythos-5-3676051/) to [mounting regulatory scrutiny over weaponized AI capabilities](https://www.androidauthority.com/us-government-anthropic-fable-5-mythos-5-suspension-3677315/). Now, a newly disclosed Zoom flaw shows just how serious that can become.\n\nResearchers used undisclosed publicly available AI models to uncover a vulnerability that could have allowed someone on a Zoom call to take control of another participant’s device. The flaw affected Zoom clients on Windows, macOS, Linux, iOS, and Android. Worse, the attack required no click, download, or other action from the victim. Simply being in the same meeting could be enough.\n\nThe vulnerability was found in Zoom’s annotation system, which handles features such as drawing and adding text while sharing a screen. A Security [discovered](https://a.security/blog/asecurity-zoomsday) (via [ Wired](https://www.wired.com/story/a-zoom-screen-sharing-bug-let-anyone-take-over-other-devices-on-a-call/)) that specially crafted annotation data could trigger memory corruption in the receiving client and ultimately enable remote code execution. What’s even scarier is that it took fewer than 20 prompts to find the flaws and produce a working exploit in under 24 hours, something that previously took lots of time and resources.\n\nThat puts a real-world example behind growing concerns about AI-assisted security research. The same technology can help defenders find vulnerabilities faster, but it can also reduce the effort required to discover weaknesses in widely used software. Google, for example, is already [using AI agents to uncover and help address vulnerabilities in Chrome](https://www.androidauthority.com/google-chrome-ai-security-overhaul-3692872/).\n\nWhat makes this bug particularly dangerous for everyday users is its zero-click execution and cross-platform reach. The flaw existed inside Zoom’s proprietary screen-sharing annotation engine (libannotate.so), an always-on component that automatically parses incoming drawing and text data. Because the same binary source compiles across all native Zoom Workplace apps, devices running Android, iOS, Windows, macOS, and Linux were equally exposed.\n\nWithout requiring any clicks, downloads, or interactions from the victim, an attacker could silently corrupt system memory, extract personal data, activate the device’s camera or microphone, or install secondary malware, undetected.\n\nFor Zoom users, there’s a straightforward takeaway: update the app. A Security reported the vulnerabilities to Zoom in June, and the company subsequently deployed client-side and server-side fixes. The flaws are tracked as CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415.\n\nAffected products include Zoom Workplace on all supported platforms before versions 7.1.5 and 7.0.6 in their respective branches, Zoom Workplace VDI Client for Windows before versions 7.0.11 and 6.6.16, Zoom Rooms on all supported platforms before version 7.1.0, and Zoom Meeting SDK on all supported platforms before version 7.1.0.\n\nSo, while there’s no indication that ordinary Zoom users need to stop making calls, running an outdated client isn’t worth the risk. If your Zoom app hasn’t updated recently, check for an update before your next meeting.\n\nThank you for being part of our community. Read our [Comment Policy](https://www.androidauthority.com/android-authority-comment-policy/) before posting.", "url": "https://wpnews.pro/news/this-shocking-zoom-bug-allowed-silent-device-takeovers-on-android-and-ios", "canonical_source": "https://www.androidauthority.com/zoom-call-device-takeover-bug-3697629/", "published_at": "2026-08-12 10:31:41+00:00", "updated_at": "2026-08-12 10:48:08.069637+00:00", "lang": "en", "topics": ["ai-research", "ai-safety", "ai-policy"], "entities": ["A Security", "Zoom", "Zoom Workplace", "Zoom Rooms", "Zoom Meeting SDK", "CVE-2026-53413", "CVE-2026-53414", "CVE-2026-53415"], "alternates": {"html": "https://wpnews.pro/news/this-shocking-zoom-bug-allowed-silent-device-takeovers-on-android-and-ios", "markdown": "https://wpnews.pro/news/this-shocking-zoom-bug-allowed-silent-device-takeovers-on-android-and-ios.md", "text": "https://wpnews.pro/news/this-shocking-zoom-bug-allowed-silent-device-takeovers-on-android-and-ios.txt", "jsonld": "https://wpnews.pro/news/this-shocking-zoom-bug-allowed-silent-device-takeovers-on-android-and-ios.jsonld"}}