All findings

CVE-2026-53413, CVE-2026-53414 critical

A Security uses frontier models to build Zoomsday in under a day

A Security reports that fewer than twenty prompts to public frontier models uncovered and weaponized two Zoom annotation memory-safety flaws.

Bug class
Remotely reachable stack overwrite and heap over-read chained into zero-click code execution
Affected codebase
Zoom annotation protocol and native clients
Credited system
A Security
Disclosed
August 11, 2026
Attribution
Self-reported attribution
Severity
critical
Source status: A Security's primary report documents the AI-assisted workflow, exact CVEs, exploitation, disclosure, and fixes. Zoom's bulletins independently corroborate the affected products and remediation. CVE-2026-53415 is excluded because A Security says Zoom found it first.

Summary

A Security reverse engineered Zoom’s closed annotation protocol, found a remotely reachable overwrite and information-leak primitive, and demonstrated zero-click code execution from one meeting participant to another. The company says the end-to-end process took under 24 hours and fewer than twenty prompts using publicly available frontier models.

Zoom shipped client fixes and a server-side mitigation before public disclosure. CVE-2026-53415 appears in the same research page but does not count toward A Security: the primary source explicitly says Zoom had already found and fixed it before the report.


References


Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.