Incorrect behavior order in Zoom Workplace App for iOS and Zoom Meeting SDK for iOS - CVE-2025-0150

 

Incorrect behavior order in Zoom Workplace App for iOS and Zoom Meeting SDK for iOS - CVE-2025-0150

Published: March 17, 2025


Vulnerability identifier: #VU105775
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-0150
CWE-ID: CWE-696
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to crash the application.

The vulnerability exists due to incorrect behavior order. A remote attacker can trick the victim into performing certain actions within the application and crash it.


Affected software

Zoom Workplace App for iOS
Zoom Meeting SDK for iOS

How to mitigate CVE-2025-0150

Install updates from vendor's website.

Zoom Workplace App for iOS - update to 6.3.0 20766
Zoom Meeting SDK for iOS - update to 6.3.0

External References

Related Security Bulletins