Zoom fixed three bugs that let anyone on a call take over your machine
Zoom has patched three memory corruption flaws in its annotation feature that allowed any meeting participant to run code on another attendee’s device with no interaction. The fixes shipped in June and July 2026, roughly two months before the research was made public.
Zoom has patched three flaws in the annotation tools used during screen sharing that let anyone on a call run code on another participant’s device. No click was needed and nothing visible happened. The fixes shipped in June and July.
That timing is worth stating plainly, because the story has been written up as an emergency. Zoom closed the holes roughly two months before the research went public, so anyone on a current client is already covered.
The fixed builds are Zoom Workplace 7.1.5 and 7.0.6, Rooms and the Meeting SDK at 7.1.5, and the Windows VDI client at 7.0.11 and 6.6.16. Anything older remains exposed.
The...
Copyright of this story solely belongs to thenextweb.com. To see the full text click HERE