Executive brief
Zoom Clients contain a missing bounds check in the annotation tool that can be exploited by a meeting participant to crash another participant's application, causing a temporary denial of service. An attacker needs only to participate in a meeting and send a specially crafted annotation to trigger the issue, requiring no special permissions or credentials.
Technical details
A missing bounds check in the annotator function allows a buffer over-read vulnerability in Zoom Clients. The vulnerability is triggered via network access by a malicious meeting participant who can send a crafted annotation payload to another participant. The attack requires user interaction (victim must be in an active meeting with the attacker) but no authentication beyond normal meeting participation. A successful exploit results in a denial of service condition affecting the targeted participant's client. Patches are available in Zoom Workplace 7.1.0 / 7.0.6, Zoom Rooms 7.1.0, Zoom Meeting SDK 7.1.0, Zoom Video SDK 2.6.0, and Zoom Workplace VDI Client 7.0.11 / 6.6.16.
Affected products
- Zoom Zoom Workplace before 7.1.0 and 7.0.6 (branch-dependent)
- Zoom Zoom Workplace VDI Client for Windows before 7.0.11 and 6.6.16 (branch-dependent)
- Zoom Zoom Rooms before 7.1.0
- Zoom Zoom Meeting SDK before 7.1.0
- Zoom Zoom Video SDK before 2.6.0
Timeline
- 2026-08-11: disclosed: Initial publication of ZSB-26016
- 2026-08-14: other: Revised bulletin adding Zoom Video SDK and correcting version information