Zoom Fixes Critical Flaws in Annotation Feature Before Disclosure
Hamid Siddiqui
News
No image for this briefing
Zoom addressed three significant memory corruption vulnerabilities in its annotation feature, allowing unauthorized code execution on attendees' devices during calls. The patches released in June and July 2026 preemptively covered users before public disclosure. The flaws, rated between 6.5 and 9.0 in severity, were identified faster than typical due to AI assistance, although initial discovery required human intervention. Older Zoom clients remain vulnerable.