Zoom Zero-Click Flaws Put Crypto Users at Risk of Device Takeover

New Zoom zero-click vulnerabilities could let meeting participants hijack another user’s device.

Warning

A newly disclosed set of Zoom vulnerabilities could have allowed a malicious meeting participant to take control of another attendee’s device without requiring the victim to click a link, download a file or approve an action.

Israeli cybersecurity firm A Security dubbed the attack “Zoomsday” after a researcher used fewer than 20 prompts with publicly available AI models to identify the flaws and build a working exploit in under 24 hours.

The vulnerabilities affected Zoom’s annotation system, which handles drawings, text and other collaborative content during meetings. Specially crafted annotation data could trigger memory-corruption flaws on another participant’s device and potentially lead to remote code execution.

Zoom assigned CVE-2026-53413 and CVE-2026-53415 high-severity CVSS scores of 8.3. Both could allow one meeting participant to execute code on another participant’s device, while CVE-2026-53414 was rated medium severity.

For crypto users, compromising a computer in this way could expose exchange sessions, wallet software, private documents or other information that attackers could use to target digital assets.

Zoom patches flaws but E2EE creates a catch

A Security reported the first vulnerabilities to Zoom in June, after which the company deployed client-side fixes and a server-side mitigation designed to stop malicious annotation messages before they reach vulnerable devices.

However, the researchers said the server-side filter cannot inspect end-to-end encrypted meetings because Zoom cannot read the encrypted traffic. Older vulnerable clients could therefore still be exposed during E2EE calls.

Zoom says affected Workplace users should upgrade to version 7.1.5 or 7.0.6, depending on their maintained branch. Older Zoom Rooms and Meeting SDK releases are also affected.

The disclosure is relevant to crypto after repeated campaigns used Zoom calls to compromise industry professionals. North Korean-linked attackers have used hacked Telegram accounts and deepfake video calls to convince targets to install malware disguised as fixes for meeting problems.

THORChain co-founder JP Thor lost roughly $1.3 million in a similar attack in September of 2025 after joining what appeared to be a legitimate Zoom meeting.

Zoomsday removes a key hurdle from those attacks: once an attacker is inside a meeting with a vulnerable client, successful exploitation would not require convincing the target to install a fake update first.