Zoomsday Vulnerability May Lead to Zero-Click Attacks on Encrypted Users
2026-08-13 16:05:12
According to CoinMeta, a recently disclosed vulnerability identified as Zoom allows attackers to control the devices of meeting participants without any action required from the victims, posing new security risks to encrypted users. Researchers from the Israeli cybersecurity company A Security discovered these vulnerabilities using publicly available artificial intelligence models and developed an effective attack within less than 24 hours. The attack, named “Zoomsday,” affects the annotation system of Zoom, which allows participants to draw or add comments to shared content. Once exploited, malicious code can run on another participant's device without the need to download any files or click on links. Attackers can steal personal information, install malware, or activate the device's microphone and camera. Researchers noted that attackers only need to join or host a meeting to send malicious data that triggers the vulnerability, and victims receive no warnings at all. This vulnerability is also associated with CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415, and it affects applications on Windows, macOS, Linux, Android, and iOS.
Bullish 0
Bearish 0
Source:Cryptonews
This content is for market information only and does not constitute investment advice.