The flaws could let someone in a meeting take control of another participant’s device without the victim clicking anything.