Zooms Company Directory feature in its desktop app can expose email addresses, full names and profile photos for certain users when it should not. The issue would also allow a stranger to initiate a chat with someone using the same email domain. Zoom tells Information Security Media Group that it blacklists domains that shouldnt be enumerated. A test done by ISMG suggests that blacklisting domains may not be the most efficient approach. As Zoom’s business grows, it may be difficult for the company to keep up with blacklisting a diversifying pool of email domains.”]
Source: https://www.databreachtoday.com/zoom-contacts-feature-leaks-email-addresses-photos-a-14039

