Junglewise Threat Intelligence

CVE-2026-53407: Zoom Workplace improper authorization in custom URL scheme handler

CVE-2026-53407 · Severity: high · CVSS 8.1 · Published 2026-06-12

Technologies: Zoom Workplace, Zoom Meeting SDK. Vendors: Zoom.

Executive brief

Zoom Workplace and Meeting SDK for Android and iOS contain a security flaw in how they handle custom web links. An attacker could use a specially crafted link to gain unauthorized privileges or access sensitive data within the app. This could lead to account compromise or unauthorized actions being performed on behalf of the user.

Technical details

A vulnerability classified as Improper Authorization (CWE-939) exists in the custom URL scheme handler of Zoom's mobile applications. The root cause is insufficient validation of requests initiated via these schemes, which can be triggered by a remote attacker through network access (typically requiring user interaction like clicking a link). An unauthenticated attacker can exploit this to conduct an escalation of privilege, potentially gaining unauthorized access to application functions or data. The issue is resolved in Zoom Workplace for Android version 7.0.4 and iOS version 7.0.3, as well as corresponding Meeting SDK versions.

Affected products

  • Zoom Workplace before 7.0.4 (Android), before 7.0.3 (iOS)
  • Zoom Meeting SDK before 7.0.4 (Android), before 7.0.3 (iOS)

Timeline

  • 2026-06-09: advisory: Initial publication by Zoom
  • 2026-06-12: disclosed: NVD publication date

References

Related threats