An AI Found a Zoom Takeover Bug in Under 20 Prompts. Your Patch Habits Are the Real Story.

An AI Found a Zoom Takeover Bug in Under 20 Prompts. Your Patch Habits Are the Real Story.

Three flaws in Zoom’s annotation feature let another participant on your call run code on your machine. Zoom fixed the main one twelve days after it was reported, which is a vendor doing its job well.

What should worry a small business owner is not the bug. It is how cheap the bug was to find, and how slowly most companies actually install updates.

“Researchers say it took fewer than 20 prompts for a public AI tool to find a flaw (now fixed) allowing anyone on a Zoom call to hijack another participants’ device.”

Lily Hay Newman, WIRED

Our take

The timeline is the part worth sitting with. Per the research team’s own disclosure writeup, senior vulnerability researcher Idan Levcovich at Ⓐ Security found the first flaw on June 8, 2026 and reported it to Zoom on June 10. Zoom shipped a client-side patch on June 22 and a server-side mitigation on July 15. Public disclosure came August 11. A second issue was triaged by his colleague Lidor Elias.

Three CVEs came out of the work. CVE-2026-53413 is a missing bounds check in Zoom’s annotator function that can lead to remote code execution on another participant’s machine; it carries a CVSS v3 score of 8.3. CVE-2026-53414 is an information-disclosure over-read at 6.5. CVE-2026-53415 also scores 8.3 and had already been mitigated by Zoom before the report landed. Fixed builds are Zoom Workplace 7.1.5 and 7.0.6, Zoom Rooms 7.1.0, Meeting SDK 7.1.0, and VDI Client 7.0.11 and 6.6.16. Zoom tracks the set in bulletin ZSB-26015.

Here is what the coverage keeps missing. AI collapsed the cost of finding the bug. It did nothing at all to the cost of installing the fix. Those two curves used to move together, roughly. They do not anymore.

For a fifteen-person company, patch deployment is not a technical problem. It is a scheduling problem. Someone dismisses the update prompt because a client call starts in four minutes. They dismiss it again the next day. Three weeks later that laptop is still on an old build and nobody knows, because nobody is checking. Zoom’s patch existed for roughly seven weeks before most users had any reason to learn they needed it.

Now add the part that makes this specific to marketing and sales teams. Your video calls are a public-facing surface. You are not on Zoom with ten trusted colleagues. You are on Zoom with a prospect you met yesterday, a contractor you hired last month, a webinar list you never vetted, and a recurring link that has been sitting in an email signature since 2024. The guest list is the attack surface. A flaw that requires the attacker to be in the meeting is a serious flaw when anyone can be in the meeting.

That leads to a second-order effect nobody is naming: this changes what a permanent meeting link costs you. A personal meeting ID pasted into your website footer, your booking page, and your newsletter used to be a mild spam nuisance. Once “another participant can reach your machine” enters the threat model, that convenience carries a different price. Marketers optimized those links for conversion. Nobody priced them for risk.

I would push back on one framing. Most of the coverage landed as “AI is arming attackers.” That is half the story and the less useful half. The same publicly available tooling let one researcher compress a month of work into a day, and he used it to report the bug responsibly so Zoom could fix it. Defenders got the first swing here. For a small business, the practical risk is not that attackers got smarter. It is that the window between public disclosure and real-world exploitation is now shorter than your update habits assume, and you currently have no way to know which of your laptops is current.

Cost it out honestly. Checking and updating Zoom across a ten-person team is about twenty minutes of somebody’s Tuesday. Rebuilding a workstation a stranger reached during a sales call is a day of lost billable time, a client conversation you do not want to have, and, if that machine held client logins, a breach-notification question for your attorney. The math is not close.

What this means for your business

  • Verify versions this week, and name the person who does it. Everyone opens Zoom, clicks their profile, and checks for updates. Anything below Workplace 7.1.5 or 7.0.6 gets updated before the next call. Put the names in a shared doc so you can see who has not replied.
  • Turn off what you do not use, at the account level. In Zoom admin settings, disable annotation, remote control, and file transfer by default. If your team does not screen-annotate on client calls, that feature is pure exposure. Require waiting rooms and passcodes on every meeting.
  • Retire your permanent personal meeting ID from public places. Pull it out of your site footer, your email signature, and your booking confirmations. Use generated per-meeting IDs. This costs you nothing and shrinks the guest list problem immediately.
  • Ask your software vendors one question. “When you patch a security issue, how and when do you notify us?” A vendor who cannot answer that is a vendor whose fixes you will learn about from the news, seven weeks late. Subscribe to security bulletins for every tool your team logs into daily.
  • Check your own site for stale meeting links and stale plugins. Search your published pages for hardcoded conferencing URLs. While you are in there, confirm auto-updates are on for your WordPress core and plugins. The habit that leaves Zoom unpatched is the same habit that leaves a plugin unpatched.

Read the original reporting: A Zoom Screen-Sharing Bug Let Anyone Take Over Other Devices on a Call by Lily Hay Newman at WIRED.


Put AI to Work for Your Business

MCNM Marketing — the team behind this publication — helps businesses across Las Vegas, Southern California, and Northern Arizona turn stories like this into revenue with AI marketing solutions, SEO & digital strategy, and marketing automation.

By PTSNV Staff

PTSNV Staff is the newsroom byline of the Philippine Times of Southern Nevada, the bilingual community newspaper serving Filipinos and Filipino-Americans in Las Vegas, Henderson, and North Las Vegas since 2006. Staff reports are written and edited by the newsroom; columns and contributed pieces carry the writer's own byline. Corrections and story tips: editor@ptsnv.com.

Another Website Developed by MCNM LLC.