Zoom patches 'Zoomsday' zero-click RCE chain that researchers weaponized in under 24 hours with fewer than 20 AI prompts
Security Affairs·high signal
Disclosed 2026-08-11, the ZOOMSDAY chain (CVE-2026-53413, CVE-2026-53414, CVE-2026-53415) targets Zoom's screen-share annotation feature and lets one meeting participant execute code on another participant's device with no interaction — enough to steal data, enable camera and mic, or install malware. The lead bug is a buffer overwrite rated 8.3/10. Researchers at A Security said they built a working exploit in under 24 hours using fewer than 20 prompts against publicly available AI models — work that previously implied nation-state time and budget. Fixed in Zoom Workplace 7.1.5/7.0.6, Rooms 7.1.5 and Meeting SDK 7.1.5.