- Sources: primary post, HN discussion
- Summary: Tatham posted the observation on 2026-09-02 from a verified account, reporting that an update to the Linux Zoom client made it start reading the clipboard. The affected versions are not yet known, because the report identifies only that a recent update introduced the behaviour and names no version boundary. Zoom has not responded publicly and no CVE has been assigned.
- Comments: HN commenters raise a correction worth checking first. X11 has selections rather than a central clipboard, so the client that copied owns the data and serves it on request, and modern desktop environments already run a daemon that grabs selection contents and claims ownership to emulate clipboard behaviour. Whether Zoom's reads exceed that ordinary pattern is the open question.
- Why it matters: A password manager that moves secrets through the X11 clipboard hands them to the Zoom client on every copy.
- Follow-up: Whether Zoom responds, whether the behaviour is reproduced independently, and whether a CVE is assigned.
send feedback on this story