Low severity3.3NVD Advisory· Published Nov 14, 2022· Updated Jun 17, 2026
CVE-2022-28764
CVE-2022-28764
Description
The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.12.6 is susceptible to a local information exposure vulnerability. A failure to clear data from a local SQL database after a meeting ends and the usage of an insufficiently secure per-device key encrypting that database results in a local malicious user being able to obtain meeting information such as in-meeting chat for the previous meeting attended from that local user account.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
15cpe:2.3:a:zoom:meetings:*:*:*:*:*:android:*:*+ 4 more
- cpe:2.3:a:zoom:meetings:*:*:*:*:*:android:*:*range: <5.12.6
- cpe:2.3:a:zoom:meetings:*:*:*:*:*:iphone_os:*:*range: <5.12.6
- cpe:2.3:a:zoom:meetings:*:*:*:*:*:linux:*:*range: <5.12.6
- cpe:2.3:a:zoom:meetings:*:*:*:*:*:macos:*:*range: <5.12.6
- cpe:2.3:a:zoom:meetings:*:*:*:*:*:windows:*:*range: <5.12.6
cpe:2.3:a:zoom:rooms:*:*:*:*:*:android:*:*+ 4 more
- cpe:2.3:a:zoom:rooms:*:*:*:*:*:android:*:*range: <5.12.6
- cpe:2.3:a:zoom:rooms:*:*:*:*:*:iphone_os:*:*range: <5.12.6
- cpe:2.3:a:zoom:rooms:*:*:*:*:*:linux:*:*range: <5.12.6
- cpe:2.3:a:zoom:rooms:*:*:*:*:*:macos:*:*range: <5.12.6
- cpe:2.3:a:zoom:rooms:*:*:*:*:*:windows:*:*range: <5.12.6
- cpe:2.3:a:zoom:vdi_windows_meeting_clients:*:*:*:*:*:*:*:*Range: <5.12.6
- Range: <5.12.6
- Zoom Video Communications, Inc./Zoom (for Android, iOS, Linux, macOS, And Windows) Clients Before Version 5.13.5cpe-rescueRange: unspecified
- Range: unspecified
- Range: unspecified
Patches
Vulnerability mechanics
References
1- explore.zoom.us/en/trust/security/security-bulletin/nvdVendor Advisory
News mentions
0No linked articles in our index yet.