Executive brief
Zoom Workplace and Meeting SDK for mobile devices contain a security flaw in how they handle custom web links. An attacker could use a specially crafted link to gain unauthorized privileges within the application. This could lead to unauthorized access to user data or restricted app functions if a user interacts with a malicious link.
Technical details
A vulnerability classified as Improper Authorization (CWE-939) exists in the custom URL scheme handler of Zoom's mobile clients. The root cause is insufficient validation of requests received via these schemes, which allows an unauthenticated remote attacker to trigger actions that should require higher privileges. While the attack vector is network-based, it typically requires user interaction (UI:R) such as clicking a malicious link. Successful exploitation allows for an escalation of privilege, potentially compromising confidentiality and integrity. The issue is resolved in Zoom Workplace for Android version 7.0.4 and iOS version 7.0.3.
Affected products
- Zoom Workplace before 7.0.4 for Android, before 7.0.3 for iOS
- Zoom Meeting SDK before 7.0.4 for Android, before 7.0.3 for iOS
Timeline
- 2026-06-09: advisory: Initial publication by Zoom (ZSB-26010)
- 2026-06-12: disclosed: NVD publication date