Recent findings have uncovered vulnerabilities in Zoom's annotation tool that could allow meeting participants to gain control over other attendees' devices without their knowledge. This flaw, within the tool that permits users to draw and type on shared screens, required no action from victims other than being present in the meeting. The vulnerabilities were patched in June and July, preceding their public disclosure, and there have been no reports of exploitation as of now.

The vulnerabilities were identified by A Security, an Israeli-founded cybersecurity startup. They discovered the flaws and developed a working exploit within a day, utilizing publicly available AI models. However, the company has not disclosed the specific models used. The vulnerabilities are tracked under CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415, with varying CVSS scores assigned by Zoom and the researchers, leading to some discrepancies in severity assessments.

The core issue stems from how the annotation data is processed and transmitted between clients. The system lacks adequate checks to validate the source of messages, allowing malformed data to exploit buffer vulnerabilities. While Zoom has addressed these issues in its client, the details of these technical fixes remain undisclosed.

The discovery highlights the potential for AI models to rapidly uncover security flaws, raising concerns about the accessibility of such capabilities. The incident follows OpenAI's release of a restricted version of its AI model to vetted partners, emphasizing the need for controlled access to advanced security tools. Despite the patches, security teams should remain vigilant and ensure their Zoom clients are updated to prevent potential exploitation.