Zoomtopia is here. Unlock the transformative power of generative AI, helping you connect, collaborate, and Work Happy with AI Companion.
Register nowEmpowering you to increase productivity, improve team effectiveness, and enhance skills.
Learn moreKeep your Zoom app up to date to access the latest features.
Download Center Download the Zoom appDownload hi-res images and animations to elevate your next Zoom meeting.
Browse Backgrounds Zoom Virtual BackgroundsEmpowering you to increase productivity, improve team effectiveness, and enhance skills.
Zoom AI CompanionUser groups are unique spaces where community members can collaborate, network, and exchange knowledge on similar interests and expertise.
Help & Resources is your place to discover helpful Zoom support resources, browse Zoom Community how-to documentation, and stay updated on community announcements.
The Events page is your destination for upcoming webinars, platform training sessions, targeted user events, and more. Stay updated on opportunities to enhance your skills and connect with fellow Zoom users.
2025-05-12 08:13 PM - edited 2025-05-12 08:14 PM
Zoom’s Bug Bounty Program incentivizes the discovery and responsible disclosure of security vulnerabilities. Here's a look at the past year's highlights.
At Zoom, security isn’t just a feature — it’s foundational to everything we build. We’re excited to share the remarkable progress we’ve made through our bug bounty initiatives in partnership with HackerOne. This year represented our strongest commitment yet to crowdsourced security, engaging with nearly 1000 talented researchers worldwide to make our products more secure for millions of people.
Our multi-layered security approach
This year, we continued our strategic approach of running multiple complementary programs:
“Our multi-tiered approach lets us match the right security talent with the right testing environments,” explained Sandra McLeod, interim Chief Information Security Officer at Zoom. “This strategy delivered exceptional results throughout 2024.”
By the numbers: A year of security wins
Our bug bounty programs saw impressive engagement this year, with hundreds of unique vulnerabilities identified and addressed. Zoom’s engineering team’s efforts have resulted in a significant reduction in the average time-to-fix compared to previous years. Average time to resolution improved by over 90% from February 2024 to January 2025, and researcher participation doubled during the same period. According to HackerOne, the Zoom Bug Bounty program is among the top 10 with regard to bounty payouts across their entire platform. The statistics tell a compelling story: our security team resolved critical issues before they could be exploited, protecting our users while rewarding the talented researchers who help safeguard our platform.
Notable security improvements
Several standout vulnerabilities discovered through our programs led to key security improvements, including:
Each vulnerability addressed represents not just a patch, but a learning opportunity that has made our entire development process more secure.
Celebrating our security researchers
Behind every vulnerability report is a dedicated security researcher who chose to work with us to make Zoom more secure. We’re immensely grateful to this community and proud to highlight some exceptional contributors:
“The relationship between Zoom and the security research community has never been stronger,” noted our Bug Bounty program manager Clara Andress. “The collaborative atmosphere has fostered mutual respect and produced outstanding security outcomes.”
Looking ahead: Security in 2025
As we enter the new year, we’re excited to announce several enhancements to our bug bounty initiatives:
Our commitment remains unwavering: to build the most secure communications platform possible through open collaboration with the security community.
Join us on our security journey
Whether you’re an experienced vulnerability researcher or just starting your security journey, we invite you to participate in our bug bounty programs. Together, we can continue building a more secure digital world. Submit your ‘@wearehackerone.com’ email address to bugbounty@zoom.us to join the team.
To learn more about Zoom privacy and security, visit our Trust Center. Found a bug? Submit a vulnerability issue here.
***Original article published in the Zoom Blog.
2025-05-14 12:12 PM
Thanks for highlighting this @rome810 🔥