None
EN
Zoom fixed three bugs that let anyone on a call take over your machine
['Ana Maria Constantin', 'Story By']
The Next Web
Zoom has patched three memory corruption flaws in its annotation feature that allowed any meeting participant to run code on another attendee’s device with no interaction.
The fixes shipped in June and July 2026, roughly two months before the research was made public.
Zoom has patched three flaws in the annotation tools used during screen sharing that let anyone on a call run code on another participant’s device.
Zoom closed the holes roughly two months before the research went public, so anyone on a current client is already covered.
The fixed builds are Zoom Workplace 7.1.5 and 7.0.6, Rooms and the Meeting SDK at 7.1.5, and the Windows VDI client at 7.0.11 and 6.6.16.