Zoom Workplace Apps Cross-Site Scripting Vulnerability Allowing Integrity Loss

Vulnerability

A cross-site scripting vulnerability has been identified in certain Zoom Workplace applications. This issue may enable an unauthenticated user to manipulate data integrity through adjacent network access. The vulnerability affects multiple platforms, including Windows, macOS, Linux, iOS, and Android, as well as Zoom's VDI client and Rooms Controller and Client applications.

Impact

Exploitation of this vulnerability could lead to cross-site scripting, allowing for the injection of malicious scripts that could be executed in the context of the user's session.

Remediation

Users are advised to update to the latest version of the Zoom Workplace App. The latest version can be downloaded from the Zoom Download Center.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
7.8
impact
1.7
exploitability
4.4
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.