Rapid7’s 2026 Global Cybersecurity Summit is now available on-demand.Watch sessions.
Rapid7

vulnerability

Zoom Zoom: CVE-2022-22784: Improper XML Parsing in Zoom Client for Meetings

Severity
5
CVSS
(AV:N/AC:L/Au:S/C:P/I:P/A:N)
Published
May 17, 2022
Added
Jan 8, 2025
Modified
Mar 25, 2026

Description

The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.10.0 fails to properly parse XML stanzas in XMPP messages. This can allow a malicious user to break out of the current XMPP message context and create a new message context to have the receiving user’s client perform a variety of actions. This issue could be used in a more sophisticated attack to forge XMPP messages from the server.

Solution

zoom-zoom-upgrade-latest
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.