Archives August 2026

“Zoomsday” flaws could let one Zoom participant attack another

Researchers have found three vulnerabilities in the popular Zoom meeting platform that could let one meeting participant attack another through malicious collaboration data.

The vulnerabilities, tracked as CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415, affect the code Zoom uses to process annotation data shared during meetings. The researchers named the set of flaws “Zoomsday.”

Affected applications are:

  • Zoom Workplace on all supported platforms before version 7.1.5 and 7.0.6, depending on the release branch
  • Zoom Workplace VDI Client for Windows before versions 7.0.11 and 6.6.16, depending on the release branch
  • Zoom Rooms on all supported platforms before version 7.1.5
  • Zoom Meeting SDK on all supported platforms before version 7.1.5

What can happen

What this means is that someone in the same Zoom meeting could send data that the Zoom app was not prepared to handle. Instead of simply displaying a drawing, text box, or other annotation, a vulnerable client could be tricked into crashing, leaking information, or even running attacker-controlled code.

Annotation features sound simple, but the underlying process is not. Your Zoom client receives structured data from another participant and turns that data into an object it can display on screen. According to the research, the annotation parser contained several memory-safety bugs. Like any software that processes data supplied by a third party, it has to be very careful about validating lengths, counts, and references before using them.

Remarkably, there is a discrepancy between the severity ratings assigned by the researchers, who rated them as Critical, and Zoom, which rated them as High.

The difference appears to come down to how the vulnerabilities are scored under the Common Vulnerability Scoring System (CVSS score). Zoom considers successful exploitation to require user interaction.

In practice, an attacker would first need to get into the same meeting as the intended victim. That could mean joining an open meeting, abusing a leaked meeting link, posing as an expected attendee, or compromising an account that already has access. Zoom considers it user interaction if the attacker persuades the target to join a meeting with the intent to compromise their machine.

How to stay safe

Zoom has published a security bulletin explaining which programs need to be updated and where to find the fixed versions.

To protect yourself from Zoomsday and have safe meetings:

  • Update Zoom to the latest version as soon as possible.
  • Restrict who can join your Zoom meetings. Use passcodes, waiting rooms, authenticated-user restrictions, and unique meeting links for sensitive calls.
  • If features like annotation, whiteboards, remote control, file transfer, or third-party apps are not needed, consider turning them off, especially for meetings that have an open invitation nature.
  • One crashed meeting is not proof of an attack, but if it happens on a regular basis, it’s worth investigating.
  • Use an up-to-date, real-time anti-malware solution to block malicious code on your devices.
  • Organizations should also check their device-management tools to make sure every deployed Zoom client is receiving updates.

From reporting threats to removing them.

Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.

How to fake a data trail (and maybe lower prices) (Lock and Code S07E16)

It may sound entirely bizarre but the prices you once paid for hotels, educational classes, or staplers could have all been higher because you used a Mac computer, lived in a certain zip code, or lacked an Office Depot in your neighborhood.

No, really.

In 2012, The Wall Street Journal reported that the travel booking site Orbitz showed Mac users pricier hotel options than PC users, because the company had determined that Mac users spend, on average, 30% more a night on hotels. That same year, The Wall Street Journal (once again) reported that Staples.com showed higher prices to visitors who lived farther away from a competitor like Office Depot. And in 2015, the reporting outfit ProPublica revealed that customers in certain zip codes were shown higher prices for college test prep courses offered by The Princeton Review.

As that investigation found, if customers:

“type some zip codes into the company’s website, they are offered The Princeton Review’s premier course for as little as $6,600. For other zip codes, the same course cost as much as $8,400. One unexpected effect of the company’s geographic approach to pricing is that Asians are almost twice as likely to be offered a higher price than non-Asians.”

This is surveillance pricing put into action.

Under surveillance pricing, companies collect as much data as possible about consumers so that they can alter the literal prices those consumers pay for the exact same goods as everyone else. It is reportedly what caused some customers to see higher prices for televisions in the Target app when those customers were physically located in a Target parking lot. It is also allegedly why Home Depot customers in wealthy neighborhoods oddly paid less. And it is what Delta Airlines walked away from after public backlash.

The near-omnipresence of surveillance pricing is also why so many videos can be found online today that claim that minor alterations to a person’s data trail—like changing an IP address using a VPN or shopping for airline tickets on a public library’s computer—can lead to lower prices online.

The proof behind these claims, however, is harder to test.

Thankfully, one person has already tried.

Video journalist Chris Parr, known on YouTube as Chris the Producer, ran a wild experiment into whether he could “stress-test” surveillance pricing. Far beyond changing his IP address or making online purchases from different locations, Parr started from scratch. By first registering an LLC in the state of Wyoming, Parr granted that LLC both a credit card and a phone, effectively creating a brand new consumer persona to be tracked. But creating a realistic data trail for his LLC would require a little extra help—help that Parr received from an actor he hired for the part.

Today, on the Lock and Code podcast with host David Ruiz, we speak with Parr about his experiment into surveillance pricing, including a high-wire drone act to purchase a White Castle Crave Case in the air space above his home state’s wealthiest neighborhood:

“To the data collectors, they don’t know that this phone is floating in the air, like 200 feet in the air. They just see a geolocation on it.”

Tune in today to listen to the full conversation.

Show notes and credits:

Intro Music: “Spellbound” by Kevin MacLeod (incompetech.com)
Licensed under Creative Commons: By Attribution 4.0 License
http://creativecommons.org/licenses/by/4.0/
Outro Music: “Good God” by Wowa (unminus.com)


Listen up—Malwarebytes doesn’t just talk cybersecurity, we provide it.

Protect yourself from online attacks that threaten your identity, your files, your system, and your financial well-being with our exclusive offer for Malwarebytes Premium for Lock and Code listeners.