web3 : Zoom Zero-click vulnerabilities affect the security of encrypted users' devices
Coinpaper
2h ago
Ai Focus
Zoom has been exposed to a high-risk zero-click vulnerability; devices with unupdated clients may still be remotely exploited in certain meeting scenarios, posing additional risks to the security of users' devices and wallets.
Helpful
No.Help

一组新披露的 Zoom 漏洞引发安全关注。研究人员称,恶意参会者理论上可在受害者无需点击链接、下载文件或确认操作的情况下,直接控制对方设备。对加密用户而言,这类入侵可能进一步暴露交易所登录状态、钱包软件和本地敏感文件。

漏洞出在会议注释功能

此次问题涉及 Zoom 的注释系统。该功能用于会议中的绘图、文字和协作内容展示。研究人员表示,攻击者可构造特殊注释数据,触发其他参会者设备上的内存损坏,并进一步实现远程代码执行。

Zoom 为其中两个漏洞分配了 CVE-2026-53413 和 CVE-2026-53415,严重性评分均为 8.3。另一个编号为 CVE-2026-53414 的漏洞被列为中等风险。

  • CVE-2026-53413:高危,可能导致跨参会者执行代码
  • CVE-2026-53415:高危,影响路径与前者相近
  • CVE-2026-53414:中危,风险等级低于前两项

补丁已发布,但 E2EE 仍有缺口

以色列网络安全公司 A Security 表示,已在 6 月向 Zoom 报告首批漏洞。此后,Zoom 推出了客户端修复,并增加服务器侧缓解措施,尝试在恶意注释消息到达终端前进行拦截。

不过,研究人员指出,服务器侧过滤无法检查端到端加密会议中的内容,因为 Zoom 无法读取加密流量。这意味着在 E2EE 会议场景下,仍在使用旧版客户端的用户可能继续暴露在风险中。

Zoom 表示,受影响的 Workplace 用户应升级至 7.1.5 或 7.0.6,具体取决于所维护的版本分支。部分旧版 Zoom Rooms 和 Meeting SDK 版本也在影响范围内。

加密行业曾多次遭遇会议钓鱼

这次披露之所以受到加密行业关注,是因为攻击者过去已多次借助 Zoom 会议入侵业内人士。报道提到,与朝鲜有关联的攻击者曾利用被盗 Telegram 账号和深度伪造视频通话,诱导目标安装伪装成会议修复工具的恶意软件。

2025 年 9 月,THORChain 联合创始人 JP Thor 就曾在加入一场看似正常的 Zoom 会议后遭遇类似攻击,损失约 130 万美元。

与以往需要诱导受害者手动安装“更新”不同,这次披露的零点击漏洞降低了攻击门槛。只要攻击者进入同一场会议,并遇到仍存在漏洞的客户端,就可能直接发起利用。

Tip
$0
Like
1
Save
1
Views 21
HQYC reminds readers to view blockchain rationally, stay aware of risks, and beware of virtual token issuance and speculation. All content on this site represents market information or related viewpoints only and does not constitute any form of investment advice. If you find sensitive content, please click“Report”,and we will handle it promptly。
Submit
Comment 0
Hot
Latest
No comments yet. Be the first!
Related
web3: Harmony Evaluating on-chain rollback, ONE Sharp drop after abnormal issuance
Harmony experiences a large-scale abnormal issuance due to a vulnerability. The team is collaborating with the exchange to freeze the relevant funds and assessing whether to roll back the blockchain.
Coinpaper
·2026-08-13 20:31:28
0
web3: HYPE Approaching the $58 mark, futures positions also rise accordingly
HYPE Continues to rebound, corporate holdings increase, open interest rises to $2.39 billion, short-term focus on performance around $58.
CoinJournal
·2026-08-13 20:31:25
0
web3: Can the funds be recovered after being scammed with ATM encryption?
It is usually difficult to recover funds stolen through encryption ATM scams, but there are still remedies available under the circumstances of exchange freezes, law enforcement recovery efforts, and refund policies in some states.
Coinpaper
·2026-08-13 20:31:22
0
web3: Foreign media: SEC gives the green light to tokenized stocks
Foreign media reports that SEC is brewing an exemption from tokenized stock regulations, and the on-chain RWA market may embrace a clearer compliance path.
Coinpaper
·2026-08-13 20:10:22
10
Ethereum: Bitcoin consolidates around $64,000, while XMR and HYPE show strength
After the release of CPI, the encrypted market remained consolidating, with Bitcoin approaching $64,000. XMR and HYPE were relatively strong, while futures and options data indicated that short-term sentiment was still cautious.
CoinDesk
·2026-08-13 19:19:07
21
View More