CVE-2026-53415
Zoom Clients - Use After Free
Description
Use after Free in the annotator function of Zoom Clients may allow a meeting participant to achieve remote code execution of another participant via network access.
In plain language
AI Act nowCVE-2026-53415 is a serious Zoom Clients bug that could let a meeting participant take control of another user’s computer through Zoom’s meeting annotation feature; if you use Zoom in meetings, you should act quickly even though no patch details are available yet.
CVE-2026-53415 is a Use After Free in Zoom Clients’ annotator/drawing feature that can be triggered during an active meeting by sending crafted annotation data, allowing one participant to run code on another participant’s machine without needing prior authentication.
What to do now
- Check whether your organization uses “Zoom Clients” for meetings (desktop app on Windows/macOS/Linux, not just the web browser).
- Confirm whether meeting annotations/drawing/whiteboard tools are enabled for participants in your typical meeting setup.
- Update Zoom Clients as soon as a vendor fix is released; no fixed version details are available from the information provided for CVE-2026-53415.
- As an immediate risk reduction, restrict annotation/drawing permissions so only the host (or approved presenters) can use annotations during meetings.
- If you cannot restrict annotations, limit who can share/participate in meetings with external parties until you can apply the fix.
CVSS Vector Breakdown
AV:NAttack VectorAC:HAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:CScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
- В Zoom исправили уязвимость, позволявшую выполнять произвольный кодru-ru·Хакер (xakep.ru)·
- ⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and Moreen·The Hacker News· Exploited Lazarus Group ransomware
- Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee's Clienten·The Hacker News· PoC Zoom Workplace rce
- Zoom Patches Zero-Click Code Execution Vulnerabilityen-us·SecurityWeek· PoC Zoom Workplace rce
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-53415 and every CVE in our database. Create a free account — no credit card required.
Create Free Account