Synapse Consulting
Home SynapseRM / TPRM Services Pricing About BlogCareersLabsContact
EN · FR
Test access Book a demo
ZERO-DAY

Zoomsday: a zero-click RCE, and the day exploit development got cheap

A researcher chained three flaws in Zoom’s annotation library into a zero-click remote code execution: one crafted message, and every participant in the meeting is compromised, with nothing to click and nothing to see. The bug is serious. What it says about the future is more serious.

SYNAPSE CONSULTING  ·  14 AUGUST 2026  ·  2 MIN READ

The chain

The flaws live in libannotate.so, the component that handles the drawings, shapes and text people share on screen during a call. A malicious annotation object triggers an unbounded copy in CAnnoFormatBlock::Deserialize, corrupting memory. A second flaw leaks heap memory back, and a third gives a write-what-where primitive. Together they hand the attacker control of the process, on every platform, with no user interaction. Server-side filtering that Zoom deployed does not help end-to-end encrypted meetings, where the server cannot see the payload.

Malicious PDUannotation objectone message Deserialize overflowCAnnoFormatBlockunbounded copy Memory controlheap over-read +write-what-where Zero-click RCEevery participant,no user interaction Discovered with fewer than 20 prompts to public AI models, in under 24 hours.
One annotation message drives an overflow, a memory leak and a write primitive into full remote code execution on every participant, with no click required.

The part that should change your planning

The researcher reported finding and weaponising the chain with fewer than twenty prompts to publicly available AI models, in under a day. Read that twice. The capability to build a zero-click exploit for a mainstream product, until recently the preserve of well-funded teams, was reproduced with consumer tools over an afternoon. The vulnerability will be patched. The economics will not go back.

The practical consequence is speed. The window between a product flaw existing and a working exploit existing is collapsing. Defence that assumed weeks of attacker effort now has days, and planning that leaned on “nobody would bother” has lost its main assumption.

What to do now

What it means for your register

If exploits arrive faster, the value of a maintained risk picture goes up, not down. When a zero-click hits a tool that touches your whole organisation, the useful questions are immediate: which business processes depend on this tool, who owns the response, what is our patch status across managed and unmanaged fleets. Those are register questions. The collaboration client is not a low-criticality asset because it is familiar; a single message compromising every participant is a maximum-impact scenario, and it should have been scored that way before the news broke. Cheaper exploits do not change what you should track. They shorten the time you have to already know it.

Technical breakdown and the AI-assisted discovery from the aSecurity research write-up.

NEXT STEP
Bring us one real project

In a 45-minute session we run your own scope through SynapseRM: requirements, findings, scored risks, register entry. You keep the output either way.

Book a demo Request test access
Synapse Consulting

A Belgium-based provider of cybersecurity solutions, and the team behind SynapseRM / TPRM.

PLATFORM
SynapseRM / TPRM Pricing Test accessPresentation (PDF)
SERVICES
Governance Operational Training
COMPANY
About Contact Blog Careers Labs Privacy & cookies
Brussels, Belgium