WorkOS
82 Case Studies
A WorkOS Case Study
zoom faced a significant security challenge following the disclosure of a zero-click remote code execution vulnerability. The exploit, developed in under 24 hours, highlighted that stolen user sessions could remain valid long after an attack was contained, posing a major security risk. Their existing session management configuration was not treated as a security control.
WorkOS provided a solution through its AuthKit product, enabling zoom to implement critical session containment controls. These included shortening refresh token lifetimes, enforcing refresh token rotation, and utilizing the WorkOS Sessions API to quickly revoke all active sessions for a compromised user. The result was a drastically reduced blast radius from a credential theft, ensuring stolen tokens would not outlive the malware that stole them.