• Sources: primary post, HN discussion
  • Summary: Tatham posted the observation on 2026-09-02 from a verified account, reporting that an update to the Linux Zoom client made it start reading the clipboard. The affected versions are not yet known, because the report identifies only that a recent update introduced the behaviour and names no version boundary. Zoom has not responded publicly and no CVE has been assigned.
  • Comments: HN commenters raise a correction worth checking first. X11 has selections rather than a central clipboard, so the client that copied owns the data and serves it on request, and modern desktop environments already run a daemon that grabs selection contents and claims ownership to emulate clipboard behaviour. Whether Zoom's reads exceed that ordinary pattern is the open question.
  • Why it matters: A password manager that moves secrets through the X11 clipboard hands them to the Zoom client on every copy.
  • Follow-up: Whether Zoom responds, whether the behaviour is reproduced independently, and whether a CVE is assigned.

send feedback on this story