Executive brief
Zoom Workplace for iOS is a mobile application used for video conferencing, chat, and collaboration. A security flaw in versions prior to 7.0.0 could allow an individual with physical access to a device to bypass certain protection mechanisms and view sensitive information. This risk is primarily relevant in scenarios where a device is lost, stolen, or accessed by an unauthorized person in person.
Technical details
A Protection Mechanism Failure (CWE-693) exists in Zoom Workplace for iOS prior to version 7.0.0. The vulnerability allows an authenticated user with physical access to the mobile device to bypass security controls and conduct unauthorized information disclosure. The attack requires physical proximity and high privileges on the device, resulting in a low CVSS score. Zoom has addressed this issue in version 7.0.0.
Affected products
- Zoom Workplace before 7.0.0
Timeline
- 2026-05-12: advisory: Initial publication of ZSB-26006 by Zoom
- 2026-05-13: disclosed: CVE-2026-30904 published to NVD