CVE-2022-22784
Zoom Client vulnerability analysis and mitigation

Overview

The vulnerability CVE-2022-22784 affects the Zoom Client for Meetings (for Android, iOS, Linux, MacOS, and Windows) before version 5.10.0. The vulnerability was discovered in February 2022 and involves improper parsing of XML stanzas in XMPP messages. This high-severity vulnerability has a CVSS score of 8.1 (NVD, CERT-EU).

Technical details

The vulnerability is related to improper XML parsing in Zoom's chat functionality, which is built on top of the XMPP standard. The issue, dubbed 'XMPP Stanza Smuggling,' exploits parsing inconsistencies between XML parsers on Zoom's client and server. This allows an attacker to 'smuggle' arbitrary XMPP stanzas to the victim client, enabling them to break out of the current XMPP message context and create a new message context to have the receiving user's client perform various actions (Hacker News, Security Week).

Impact

A successful exploitation of this vulnerability could allow an attacker to forge XMPP messages appearing to come from the server. The attack requires no user interaction for success, with the only requirement being the ability to send messages to the victim over Zoom chat using the XMPP protocol. This could lead to the victim's client performing various unauthorized actions (Threatpost).

Mitigation and workarounds

Zoom has patched this vulnerability in version 5.10.0 of the Zoom Client for Meetings. Users are strongly recommended to update their client software to this version or later to receive the security fixes (CERT-EU).

Community reactions

The vulnerability was discovered and reported by Ivan Fratric of Google Project Zero, who provided a detailed technical analysis of the issue. The discovery was part of a larger set of vulnerabilities found in Zoom's client software, highlighting the ongoing security scrutiny of video conferencing platforms (Security Week).

Additional resources


SourceThis report was generated using AI

Related Zoom Client vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-49457HIGH8.8
  • Zoom ClientZoom Client
  • cpe:2.3:a:zoom:rooms:*:*:*:*:*:windows:*:*
NoYesAug 12, 2025
CVE-2025-58133HIGH7.5
  • Zoom ClientZoom Client
  • cpe:2.3:a:zoom:rooms:*:*:*:*:*:windows:*:*
NoYesOct 15, 2025
CVE-2025-49460HIGH7.5
  • Zoom ClientZoom Client
  • cpe:2.3:a:zoom:virtual_desktop_infrastructure
NoYesSep 09, 2025
CVE-2025-49464MEDIUM6.5
  • NixOSNixOS
  • cpe:2.3:a:zoom:zoom:*:*:*:*:*:windows:*:*
NoYesJul 10, 2025
CVE-2025-49463MEDIUM6.5
  • NixOSNixOS
  • cpe:2.3:a:zoom:zoom
NoYesJul 10, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management