Zoom Annotation Bug Could Let Attackers Hijack Any Meeting Client

A critical flaw in Zoom's annotation feature could have allowed any meeting participant to silently take over another attendee's computer. No clicks, no downloads, and no visible warnings were required.

A Flaw Hidden in Plain Sight

Every day, millions of people share their screens on Zoom calls without a second thought. A newly disclosed vulnerability shows just how dangerous that routine action could have been. Researchers have revealed a critical security flaw in Zoom’s annotation feature — the tool that lets meeting participants draw, highlight, and type on top of a shared screen — that could have allowed a malicious actor to silently execute code on another attendee’s machine and take full control of it.

What makes this vulnerability particularly alarming is what it did not require. There was no malicious link to click, no file to download, no suspicious prompt to dismiss. Simply being present in a Zoom meeting — either as a screen sharer or as a viewer — was sufficient exposure. The attack left no visible indication on the victim’s screen that anything unusual was occurring.

How the Attack Would Have Worked

The flaw operated in both directions across a meeting, which significantly expanded its potential blast radius. A participant sharing their screen could have been targeted by anyone watching, and conversely, anyone watching a shared screen could have been targeted by the presenter. This bidirectional nature meant that a single compromised participant — or a bad actor who had simply joined a call — could have leveraged the annotation surface as an attack vector against every other person in the session.

The underlying mechanism involved the annotation tool’s handling of data passed between clients during a live session. By crafting malicious input through that channel, an attacker could trigger code execution on a remote machine without the target needing to interact with anything. In security terms, this class of attack is known as a zero-click exploit, and it is considered among the most severe categories of vulnerability precisely because it removes the human error element that most security training is designed to address.

Scope and Scale of the Risk

Zoom’s user base numbers in the hundreds of millions, spanning corporate boardrooms, classrooms, government agencies, healthcare consultations, and casual personal calls. The annotation feature is enabled by default and widely used during presentations, training sessions, and collaborative reviews. That ubiquity is exactly what elevated the severity of this flaw — an attacker would not have needed to search for unusual environments or misconfigured setups. Any standard meeting with screen sharing active would have been a viable target.

The vulnerability has since been patched by Zoom, and users are strongly advised to ensure their desktop clients are updated to the latest available version. Zoom’s automatic update mechanism should handle this for most users, but organizations that manage software deployment centrally should verify that the fix has been rolled out across their fleets.

The Annotation Surface as an Attack Vector

Collaborative drawing and annotation tools have historically received less security scrutiny than core communication features like audio, video, and chat. They tend to be perceived as lightweight add-ons rather than as components that process and transmit complex, user-controllable data between clients in real time. This vulnerability is a pointed reminder that any feature capable of passing arbitrary input between networked endpoints deserves the same rigorous analysis applied to the rest of an application’s attack surface.

Security researchers have noted a broader trend of attackers targeting peripheral features within otherwise well-audited platforms — the assumption being that edge functionality receives fewer eyes during code review and less frequent penetration testing. Zoom has invested substantially in security improvements since facing intense scrutiny over “Zoomboming” incidents in 2020, but this latest disclosure suggests that deeper layers of the client application still hold surprises.

What This Means Going Forward

This vulnerability illustrates a maturing threat landscape in which attackers no longer need to rely on user mistakes. Zero-click exploits in widely deployed collaboration software represent a category of risk that traditional security awareness training simply cannot mitigate. Organizations should treat platform patching for tools like Zoom, Teams, and Webex with the same urgency applied to operating system and browser updates. As hybrid work cements video conferencing as critical infrastructure, the security bar for these platforms must rise accordingly — because the meeting room, it turns out, is now part of the attack surface.