< BACK TO NEWS
importantSYS.SOURCE: The Hacker News2026-08-12T00:38:47+05:30

Zoom Annotation Vulnerability Allows Zero-Click Client Hijacking in Video Meetings

A zero-click vulnerability in Zoom's annotation tool could allow meeting participants to hijack another attendee's client without interaction, with exploit development achieved in under a day using AI models. Patches were released two months prior to disclosure, though discrepancies exist between the researcher's and vendor's severity assessments.

Anyone sharing their screen on a Zoom call could have taken over the computers of everyone watching, and anyone watching could have taken over the presenter's.

The flaw sat in the annotation tool, the feature that lets participants draw and type on a shared screen, and it asked nothing of the victim beyond being in the meeting. No click, no download, no prompt, and nothing on screen to show it

Read original article

*** END OF TRANSMISSION ***