Zoom Linux Client Found Reading Clipboard Without Authorization
In September 2026, open-source security researchers and Linux users found that the latest Zoom desktop client for Linux continuously polls and reads the system clipboard while running in the background, without user authorization or paste interaction. The behavior was first spotted in system resource and API call logs. Under X11 and some Wayland compatibility layers, the Zoom main process triggers clipboard API calls at high frequency even when minimized, resident in the background, or idle in a meeting. As of September 13, 2026, Zoom had not publicly responded.
In September 2026, the latest version of Zoom's desktop client for Linux was found to carry a privacy overreach risk. Open-source security researchers and Linux users testing the client found that while it runs in the background, it continuously polls and reads the contents of the system clipboard without user authorization or an active paste interaction.
The behavior was first discovered by open-source community users while investigating system resource scheduling and interface call logs. Technical evidence shows that under the X11 display server environment, and under some Wayland compatibility layers that do not impose strict sandbox restrictions on clipboard isolation, the Zoom main process triggers system clipboard API calls at high frequency even when minimized, resident in the background, or idle during a meeting.
Text data that users copy, such as account passwords, two-factor authentication (2FA) recovery keys, private communications, and confidential business code, is captured by the Zoom client in the background within milliseconds of entering the system clipboard. The clipboard is a temporary staging area used for information exchange in desktop operating systems.
As of September 13, 2026, Zoom had not given a public response on the cause of the issue, the specific range of affected versions, or a schedule for rolling out an official fix.
Why this event matters
The event has a measured impact on 2 industrys. The strongest current signal is negative for General Software & IT Services, with intensity 45/100 and 60% confidence over a short term horizon.
General Software & IT Services
- Direction
- negative
- Intensity
- 45
- Confidence
- 60%
- Horizon
- Short term
Cloud Services & Data Centres
- Direction
- negative
- Intensity
- 30
- Confidence
- 50%
- Horizon
- Short term
Impact figures are analytical estimates that combine direction, intensity, confidence and event importance. They are not investment advice.