CERT-In Highlights Zoom Security Flaws That Could Let Hackers Access Meeting, Sensitive Information

CERT-In has advised Zoom users on Windows, macOS, Android, iOS, and iPadOS to download the latest update with security fixes.

Advertisement
Written by Dhruv Raghav, Edited by David Delima | Updated: 17 October 2025 15:35 IST
Highlights
  • Zoom has addressed the vulnerabilities and released a patch
  • CERT-In said that the flaws exist due to improper input sanitisation
  • Zoom's older version failed to properly validate user IDs

Zoom released to updates on October 14 to fix the issue

Photo Credit: Zoom

The Indian Computer Emergency Response Team (CERT-In) has published a vulnerability note alerting Zoom users that multiple security flaws have been detected on certain versions of the video conferencing platform. The vulnerability exists across operating systems like Windows, macOS, iOS, and Android. By exploiting the flaw, hackers can gain unauthorised access to Zoom Rooms, remotely execute malicious commands, exit meetings, reveal information not meant to be shared, and access configuration data. The issue has since been resolved in a recently rolled out update, and users are urged to update to the latest version.

Multiple Security Flaws Spotted in Certain Versions of Zoom

In its latest vulnerability note CIVN-2025-0261, CERT-In warns Zoom users about multiple vulnerabilities with a "medium" severity rating. The security flaws were found in the Zoom for Windows, macOS, Android, and iOS versions 6.5.1. The vulnerabilities can be exploited by threat actors, allowing them to gain unauthorised access to meetings and configuration data. Moreover, the same can be misused by bad actors to disclose sensitive information and execute arbitrary commands, like running scripts.

CERT-In highlighted that the vulnerability affects both individuals and organisations using the video conferencing software, compromising the security of the ongoing and future meetings.

Advertisement

However, the company has already patched the vulnerabilities in an update rolled out on October 14. CERT-In advises people using the above-mentioned versions of the app to update to the latest available version of Zoom on their device. This will help them protect themselves against cyberattacks, which compromise their personal data and sensitive organisational information like trade secrets.

Advertisement

Zoom said that the authentication bypass issue allowed unauthenticated users to disclose information via network access. On the other hand, the command injection flaw in Zoom Clients for Windows allowed authenticated users to disclose information after gaining network access.

The security vulnerabilities seem to exist due to improper input sanitisation and inadequate session validation, CERT-In said. This means that these particular Zoom versions do not validate the user ID of the person joining Zoom Rooms. Moreover, the video conferencing platform has been unable to adequately filter and transform the input data provided by users before it is fed into the system.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement
Popular Mobile Brands
  1. iPhone 17e Launched in India With MagSafe, 48-Megapixel Camera: See Price
  2. iPad Air (2026) With M4 Chip Launched in India at This Price
  3. Nothing Phone 4a Price in India, RAM and Storage Options Leaked Online
  4. MediaTek to Demonstrate 6G, Wi-Fi 8 CPE, AI Glasses at MWC 2026
  5. Xiaomi Watch 5, Xiaomi Tag Arrive Globally at These Prices
  6. Lenovo Refreshes ThinkPad Portfolio With AI PCs at MWC 2026
  1. Poco X8 Series, Poco C85x 5G Teased on Flipkart, Could Launch in India in March
  2. iPad Air (2026) Launched in India With M4 Chip, Up to 13-Inch Display: Price, Specifications
  3. iPhone 17e Launched in India With MagSafe, Ceramic Shield 2 and A19 Chip: Price, Specifications
  4. MWC 2026: Tecno Camon 50 Series Launched as Firm Unveils Modular Concept Phone, Lamborghini Collaboration
  5. Samsung Galaxy S26 Ultra's Successor Tipped to Feature 200-Megapixel ISOCELL HPA Sensor With LOFIC
  6. Moto Buds 2 Plus Launched With Dynamic ANC, Sound by Bose Alongside Moto Buds 2 at MWC 2026
  7. MediaTek Set to Demonstrate 6G, 5G-Advanced, Edge AI Innovations at ‘AI For Life’ Showcase at MWC 2026
  8. MWC 2026: Lenovo Unveils New Yoga, IdeaPad Series Laptop Models Alongside Legion Tab (2026), Idea Tab Pro Gen 2
  9. Bluepoint Games Reportedly Pitched a Bloodborne Remake, but Was Turned Down by FromSoftware
  10. Lenovo ThinkPad T-Series, X13 Detachable, ThinkTab X11 and ThinkBook 14 2-in-1 Launched at MWC 2026
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.