Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee's Client
A Zoom annotation tool flaw allowed any meeting participant to hijack another attendee's computer without any action from the victim, enabling both presenters and viewers to take control of each other's devices.
A flaw in Zoom’s annotation tool let screen-sharing participants hijack viewers’ computers—and vice versa—without any action from the victim. No click, download, or on-screen prompt was needed; simply being in the meeting was sufficient. The vulnerability allowed a meeting participant to take over another attendee’s client, posing a serious security risk during shared-screen sessions.