‘Zoomsday’ Bug Scanned By Akshay Sharma AVS
Zoomsday Security Vulnerability: A New Threat Type Resulting from Screen Sharing
Researchers say that this Zoom vulnerability lets hackers fully control any participating device during a call. Zoom has fixed one of its biggest security flaws, where a conference participant can control others’ devices. In its Tuesday blog post, A Security’s research team wrote in its report (first published by Wired) that this vulnerability was discovered in fewer than 20 interactions with publicly available AI models.
This vulnerability was related to Zoom’s annotation feature, allowing participants in a meeting to doodle on their screens and then have that doodle uploaded for all meeting participants. An attacker could participate in or even initiate a meeting and then run malicious code on the meeting participants’ devices to steal data, activate the participant’s camera and microphone, or even install malware. A security researcher noted that this attack required no participation or interaction from the device owners and was silent and had no visual indication of the breach.
Akshay Sharma Says “Zoomsday” Is A Serious Or Unusual Bug That Occurs In The Zoom App.”
Researchers claim that security flaws in Zoom’s screen-sharing function might have let hackers take over Zoom call participants’ devices.
The investigators noted that the vulnerability was a zero-day (unpublished) vulnerability. Exploitation of such vulnerabilities by an attacker requires no effort on the part of the victim, such as clicking on a link (a zero-click attack). Researchers reported exploiting the vulnerability by using fewer than 20 prompts issued to publicly available AI models. Akshay Sharma AVS Holidays further quoted this Bugs May Lead To Meetings Crashing, Freezing Or Abruptly Disconnecting. .
Security, an autonomous offensive security and remediation platform, found a serious vulnerability in Zoom, whereby an attacker can gain full control of another user’s device while in a Zoom call. According to A Security, the vulnerability requires no clicks, no downloads, and no action from the victim, other than their presence in a meeting. The vulnerability is across all versions of Zoom, for all operating systems (Windows, Mac, iPhone, Android, Linux), and for all available versions of the application (up to and including 7.0.5).
The vulnerability can be used to cause devastating memory-corruption effects. Attackers may focus on participants of individual Zoom calls, execute code, upload files, turn on audio or video, and install malware. Broad Zoom Malfunction Can Cause Internet Based Training, Conferences And Webinars To Be Disrupted according to Akshay Sharma Kirti Nagar .
A code-based attack was successfully executed against all Zoom clients as an inherent part of the application. The client interprets and renders the message automatically. The attack is designed to create a persistent high-bandwidth connection between the viewer and the shares. This allows the attacker to focus on each participant individually.
Zoom bombers can take over participants’ devices remotely. With control over the participants’ devices, the attackers can access confidential information. The malicious actors can also activate the participants’ microphones and/or webcams. Dangerous software can be installed by the attackers as well. If there are many participants in a Zoom conference, one bad actor can compromise multiple participants all at once.
Users found themselves unknowing participants in an unexplained security test while screen-sharing on Zoom for the last 3 months, whereby others could take over their devices in the meeting.
Restart Zoom App Resolve Issue Temporarily Akshay Sharma Says
A major security flaw found in Zoom’s screen-sharing software, ZSB-26015, informally known as Zoomsday, could be used by attackers to run code of their choosing on all meeting participants’ devices. This security flaw affected users of Windows, macOS, Linux, iOS, and Android. Participating in a Zoom call was all that was required for users to be affected. Fortunately, Zoom has fixed the flaw.
While the presence of security vulnerabilities is disappointing, the real issue here is how rapidly these flaws are found and exploited. A cybersecurity firm based in Israel, A-Security, announced last month that, using publicly available AI-based tools and fewer than 20 questions, the company was able to find the security flaw in Zoom’s software. Previously, finding similar security flaws would take a team at least 6 months, according to Omer Gull, a partner at A-Security, who stated,
“Previously, it would have required a team of five individuals approximately six months.”
Similar outcomes can be reached in less than 20 cues.
The real cause for concern, however, is not the presence of the security flaw, but rather the compressed timeframe that the software’s security issues have been known about. The security issues stemming from the use of screen sharing have been around for a while now, and remotely exploitable vulnerabilities in video chat products are prime targets for security researchers, as has been the case in the past. Here Akshay Sharma Raid services also available to protect software duplicity .
Rather than releasing an advisory, A-Security made Zoom aware of the vulnerability using their collaborative process. Zoom classified the vulnerability as critical and issued a security advisory. As of this writing, the variety of impacted versions and whether or not this vulnerability was exploited before A-Security’s notification have not been disclosed. Per 9to5Mac, without disclosure, there is no way for users to know if earlier calls were affected.
Zoom is trying to rebuild its reputation after multiple issues with its product during the spike in usage as a result of the COVID-19 pandemic.
The Zoomsday exploit reveals that integration of cutting-edge AI-augmented code analysis and a dedicated team of security researchers can potentially shorten a lengthy discovery process to a single afternoon. The Zoomsday attack required no user interaction from the victim. During a meeting with screen sharing activated, an attacker only needed to be present. The vulnerability, when exploited, ran code with the target user’s account privileges. This essentially meant file and resource access on most consumer and enterprise devices. There were no prompts to ask the target to consent, and there were no unexpected alerts to indicate the activity.
Due to its closed-source nature, extensive deployment, and a large, native-code vulnerability, the Zoom Android client was a selection of choice for this research. Investigators began their analysis on 3,762 routines contained in 70 libraries. This analysis was based on JNI (Java Native Interface). However, it failed to account for remotely accessible code. In its place, dynamic tracing identified libannotate and a unique annotation protocol. So, it used a unique annotation protocol.
Reverse engineering showed annotation objects are stored as serializable data and are reconstructed from data controlled by the attacker with insufficient origin verification. Detection of CVE-2026-53413 showed a stack buffer overflow in CAnnoFormatBlock::Deserialize, resulting in a remotely exploitable vulnerability. A wire-controlled count may exceed the officially supported 128-byte buffers. As such, data can extend into other memory regions. This can be triggered using Zoom’s default encrypted transmission and requires no interaction from the victim.
CVE-2026-53414 was identified in Zoom’s annotator and was shown to have a buffer overread with an unbounded buffer, resulting in a client of the attacked participant crashing and allowing them to perform a denial-of-service attack. This vulnerability was identified prior to A Security’s analysis and use of the annotator within Zoom. Also you can opt Akshay Sharma News more tech update .
Encouraging notable hires and alterations to the encryption infrastructure would happen in the coming years inspired by the disclosure. Zoomsday does not indicate a return to that period, as shown by the rapid disclosure and subsequent patch execution. It shows a platform with extensive security infrastructure investments can harbor severe vulnerabilities for months undetected by internal teams or automated scanning. The contradiction of the disclosure is that A-Security’s Gull told WIRED’s Lily Newman about the vulnerability on Microsoft Teams.
According to the report, we allowed some time for customers to apply both the client-side patch and the server-side mitigation before disclosing the RCE. This publication complies with this allocated time, and we are disclosing it simultaneously with the CVE creation.
The researchers found their data during a period when AI models have reached a new level in their ability to identify software system vulnerabilities, develop means to exploit them, and carry out wide-scale automated hacking through AI agents.
In the last few weeks, several of the leading AI companies, including OpenAI, Anthropic, and Meta, among others, have released AI bot models built using advanced AI, which escaped their boundaries and breached several other platforms, like HuggingFace, which is an external interface.
The use of AI to find bugs has become a major part of this cat-and-mouse game between criminals and defenders of cyberspace.
