Description
Use after Free in the annotator function of Zoom Clients may allow a meeting participant to achieve remote code execution of another participant via network access.
Published: 2026-08-11
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a use‑after‑free bug in the Zoom Clients’ annotator function that can be triggered by a meeting participant. Exploitation would allow the attacker to execute arbitrary code on another participant’s device, potentially leading to full system compromise, data exfiltration, or further network infiltration. The flaw stems from an improper free of memory that is later accessed, matching CWE‑416.

Affected Systems

The affected product is the Zoom Communications Zoom Clients. No specific version range is listed, indicating that all client builds released before a vendor‑supplied fix may be impacted. The vulnerability applies to Windows, macOS, iOS, and Android clients that support the annotator feature.

Risk and Exploitability

The CVSS score of 8.3 rates this as a high‑severity issue, yet the EPSS score is less than 1%, suggesting that exploitation in the wild is currently low but possible. The flaw is not yet in the CISA KEV catalogue. An attacker would need to be a meeting participant with network access to the vulnerable client and would exploit the annotator function to trigger the use‑after‑free and gain code execution.

Generated by OpenCVE AI on August 12, 2026 at 21:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update all Zoom Clients to the latest version released by Zoom Communications, which removes the annotator use‑after‑free flaw.
  • If an update cannot be applied, configure Zoom meetings to prohibit or limit the annotator feature and isolate the meeting network to prevent an attacker from interacting with vulnerable participants.
  • Monitor meeting participants’ processes for abnormal activity and verify that no unauthorized code is running on client devices.

Generated by OpenCVE AI on August 12, 2026 at 21:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
First Time appeared Zoom Communications
Zoom Communications zoom Clients
Vendors & Products Zoom Communications
Zoom Communications zoom Clients

Tue, 11 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Description Use after Free in the annotator function of Zoom Clients may allow a meeting participant to achieve remote code execution of another participant via network access.
Title Zoom Clients - Use After Free
Weaknesses CWE-416
References
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H'}


Subscriptions

Zoom Communications Zoom Clients
cve-icon MITRE

Status: PUBLISHED

Assigner: Zoom

Published:

Updated: 2026-08-13T03:55:45.806Z

Reserved: 2026-06-09T10:18:05.660Z

Link: CVE-2026-53415

cve-icon Vulnrichment

Updated: 2026-08-11T16:53:09.000Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-11T16:17:32.833

Modified: 2026-08-28T18:39:48.167

Link: CVE-2026-53415

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T05:45:02Z

Weaknesses