A zero-click Zoom flaw lets any meeting participant take over another attendee's device through the annotation feature.
Zoom fixed CVE-2026-53412, a critical account takeover vulnerability with a CVSS score of 9.8 affecting Windows users.