Summary
A Security reverse engineered Zoom’s closed annotation protocol, found a remotely reachable overwrite and information-leak primitive, and demonstrated zero-click code execution from one meeting participant to another. The company says the end-to-end process took under 24 hours and fewer than twenty prompts using publicly available frontier models.
Zoom shipped client fixes and a server-side mitigation before public disclosure. CVE-2026-53415 appears in the same research page but does not count toward A Security: the primary source explicitly says Zoom had already found and fixed it before the report.
References
Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.