VYPR
Unrated severityNVD Advisory· Published Jan 9, 2023· Updated Apr 9, 2025

Path Traversal in Zoom for Android Clients

CVE-2022-36928

Description

A path traversal vulnerability in Zoom for Android prior to 5.13.0 allows a third-party app to read and write the Zoom application data directory.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A path traversal vulnerability in Zoom for Android prior to 5.13.0 allows a third-party app to read and write the Zoom application data directory.

Vulnerability

Zoom for Android clients before version 5.13.0 contain a path traversal vulnerability [1]. A malicious third-party app installed on the same device can exploit this flaw to read from and write to the Zoom application data directory. The vulnerability exists in the file handling logic of the Zoom Android client, allowing directory traversal outside of the intended sandbox.

Exploitation

An attacker requires the ability to install a third-party app on the victim's Android device. No additional authentication or user interaction beyond installation of the malicious app is needed. The exploit leverages the path traversal weakness to access files in the Zoom app's private data directory, bypassing Android's normal app sandbox restrictions.

Impact

Successful exploitation allows an attacker to read sensitive data stored by the Zoom application (such as chat logs, meeting recordings, or cached credentials) and write arbitrary files into the Zoom data directory. This could lead to further compromise of the application’s integrity or data injection attacks.

Mitigation

Zoom released version 5.13.0 for Android to address this vulnerability [1]. Users should update their Zoom client to 5.13.0 or later via the Google Play Store or Zoom's official channel. No workaround is available; updating is the recommended mitigation.

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

1

News mentions

0

No linked articles in our index yet.