CVE-2025-49462: Zoom

Low severity, CVSS 3.5. EPSS: 0.2% chance of exploitation in the next 30 days.

Cross-site scripting in certain Zoom Clients before version 6.4.5 may allow an authenticated user to conduct a disclosure of information via network access.

Affected products

  • Zoom Zoom: before 6.4.5 (fixed in 6.4.5)

Published 2025-07-10. Last modified 2026-06-17.