Zoomsday: A Critical Flaw Hiding in a Familiar Feature

A pair of critical vulnerabilities, collectively nicknamed "Zoomsday," have put Zoom users on notice this week. According to reporting from Malwarebytes, the flaws could allow an authenticated attacker already sitting in the same meeting as you to run malicious code on your device, no phishing link, no suspicious download required. All they need is a seat in the call.

The issue traces back to Zoom's annotation feature, the tool that lets participants draw, highlight, or mark up shared screens during a call. Researchers found that the way Zoom's proprietary communication protocol parses annotation data could be abused to trigger remote code execution. In plain terms: a routine feature meant for collaboration became a doorway for an attacker to take control of another participant's system, all from inside a meeting that looked completely ordinary.

How the Flaw Was Found, and Why That Matters

What makes Zoomsday stand out isn't just the technical mechanism, it's how quickly it was uncovered. Israeli cybersecurity firm A Security has described how a researcher used fewer than 20 AI prompts to build a working exploit chain in about a day, a pace that would have been unusual for this kind of vulnerability research even a couple of years ago. Zoom itself has rated the issue as high severity, and it has been tracked as involving at least two distinct critical flaws working together in the annotation parser.

This speed matters for two reasons. First, it shows how AI-assisted tools are lowering the barrier to finding serious software flaws, which is good news when it's done by researchers responsibly disclosing to vendors, but a sobering reminder that malicious actors have access to the same tools. Second, it underscores that widely used communication software, even mature platforms with dedicated security teams, can still harbor deep protocol-level weaknesses that go unnoticed for a long time.

Why This Is a Privacy Problem, Not Just a Security One

It's tempting to file this under "another software bug," but the privacy implications deserve more attention than they've gotten so far. Video conferencing platforms like Zoom sit at the center of enormous amounts of sensitive conversation: business negotiations, legal consultations, medical appointments, journalist source calls, and personal conversations that people assume are private simply because the meeting has a password and a waiting room.

A vulnerability that lets one participant compromise another's device from inside a legitimate meeting bypasses almost every privacy assumption people make about video calls. It doesn't require breaking into the meeting from outside or guessing a password; the attacker is already an invited or authenticated guest. That means the usual advice about vetting meeting links or avoiding suspicious senders doesn't fully apply here. The trust boundary that fails is the one between participants who are already inside the (virtual) room together, which is a much harder thing for the average user to guard against on their own.

What This Means For You

If you use Zoom for work, school, telehealth, or personal calls, the Zoomsday flaws are a reminder that meeting software deserves the same patching discipline as your operating system or browser. Zoom has addressed the underlying issues, and the fix requires nothing more than updating to the latest version of the app. The vulnerability only matters if you're running an outdated client, so this is one of the rare security stories where the fix is genuinely simple and fully within your control.

For organizations, this is also a good moment to check whether Zoom updates are being pushed automatically across managed devices, rather than left to individual employees to install whenever they get around to it. A single unpatched laptop in a shared meeting is enough to expose the whole call to risk.

Actionable Takeaways

  • Update Zoom immediately on every device you use, desktop, laptop, and mobile, since the annotation-related flaws only affect outdated versions.
  • If you manage Zoom deployments for a business or school, confirm that automatic updates are enabled rather than relying on manual patching.
  • Treat video conferencing software with the same urgency as your browser or operating system when security patches are released, not as an afterthought.
  • Be cautious about which features, like screen annotation, you enable in sensitive meetings until you've confirmed your client is fully patched.

The Zoomsday vulnerabilities are a clear signal that even trusted, everyday tools can carry serious risks hiding in plain sight. The good news is that this particular threat has a straightforward fix. Updating Zoom now closes the door before it becomes a problem, so there's no reason to wait.