Video conferencing app Zoom has a major security flaw in its Mac client, letting any website turn on your Mac's camera without a warning, security researcher Jonathan Leitschuh claims.
In a blog post Monday, Leitschuh detailed the vulnerability, which he says he'd disclosed to Zoom more than 90 days ago, and the company still hasn't fixed it.
SEE ALSO: Google Nest camera security flaw allows former owners to observe others' homesThe problem lies in Zoom's usage of a web server on users' local machines. This makes some of Zoom's cool features possible, for example, clicking on a simple link in your web browser automatically starts up the app.
Having an app install and run a web server on a user's machine with an undocumented API "feels incredibly sketchy," Leitschuh says. But there's more. According to Leitschuh, "this web server can do far more than just launch a Zoom meeting. (...) this web server can also re-install the Zoom app if a user has uninstalled it."
This is bad by itself, but Leitschuh discovered a vulnerability that let him launch a Zoom call, with video enabled, on a user's machine without permission. The same vulnerability allows the attacker to perform a DOS (denial of service) type attack on a user's machine.
Leitschuh says that he'd contacted Zoom on March 26, offering the company a quick fix for the vulnerability. After a lot of back and forth, Zoom partially fixed the flaw, but Leitschuh was able to bypass their fix, after which the company offered no additional fix. The security issue is still present in the latest version of Zoom for Mac, 4.4.4.
In a blog post Monday, Zoom defended its app's functionality, claiming that users are prompted to turn their video off when joining their first meeting, and can set the video to off in subsequent meetings; if they do so, it would be impossible for the host or other participants to turn their camera on. Furthermore, Zoom claims, "because the Zoom client user interface runs in the foreground upon launch, it would be readily apparent to the user that they had unintentionally joined a meeting and they could change their video settings or leave immediately."
The company said they will give users more control of their video settings in an upcoming, July 2019 release.
The company also addresses the presence of the web server on user machines, saying it's a "workaround to a change introduced in Safari 12" and a "legitimate solution to a poor user experience problem."
Zoom has assessed that both the video call issue and the DOS issue were "low risk," which is why the company decided not to change the app's functionality. The company also promised it will launch a public vulnerability disclosure program in the "next several weeks."
The main question users should be asking themselves is whether they want to sacrifice their system's security for a bit of added functionality -- likely, functionality they can live without. Zoom's ability to re-install itself without user permission after it's been uninstalled is particularly worrisome. Since there's no official fix for the issue, you can remove Zoom's web server from your machine by following the steps described in Leitschuh's post.
Copyright © 2023 Powered by
Zoom lets a website turn on your Mac's camera without permission-燕尔新婚网
sitemap
文章
84339
浏览
282
获赞
97332
The best of Martha Stewart's deeply weird personal Instagram account
To truly understand the heart of Martha Stewart, you need to dig deep into her personal Instagram acMeta discontinues the Quest 2 and Quest Pro after revealing Quest 3S
One of the best early (or early-ish) VR headsets is dead.Meta has discontinued the Quest 2 and QuestIs Google Fitbit in trouble? Website shutdown revitalizes concern about the brand's future
Is Fitbit in trouble?9to5Google spotted that Fitbit.com, the official website for the popular brandHow to factory reset a PS4
Wondering how to factory reset a PS4? Sony's PlayStation 4 has been a trusty sidekick for over a decThis cat opening a door by himself is truly impressive
Videos of cats opening doors are always good, but here is a particularly good one.It was taken by TwDo not accept New York Mag's climate change doomsday scenario
Climate change is a tough issue to cover as a journalist. It's like following a slow-motion train wrPerfecting the Art of Pedantry
Bailey Trela ,February 20, 2025 PerfectingThis tiny Japanese space agency drone is giving us a glimpse of life in space
If you've ever wondered about what it's like to be inside the International Space Station through thGmail's compose button on Android gets bigger, but only when you scroll down
Gmail's compose button is annoyingly small and unintuitive on phones. You may have not noticed it, bAstrophysicist Neil deGrasse Tyson is here for legal weed
Astrophysicist Neil deGrasse Tyson got real about marijuana during a Facebook Live question sessionOctober Prime Day unlocked phone deals: Samsung Galaxy S24 FE, Motorola razr, and more
UPDATE: Oct. 7, 2024, 11:48 a.m. EDT This article has been updated with the latest unlocked phone deMicrosoft outage: Users report 365 issues again
Microsoft users reported lots of issues and outages on Thursday. The issue appeared to lie with itsSophie Turner chugging wine on a Jumbotron is deeply inspiring
Game of Thronesstar Sophie Turner (also known as Sansa Stark) dabbed then chugged a glass of red winApple fixes dangerous 'GAZEploit' Vision Pro security flaw
Apple's Vision Pro has a way of showing the world a virtual version of you while you interact with oBest Apple Watch deal: Get an Apple Watch Series 10 for a new low price
SAVE $23:As of Oct. 18, get the Apple Watch Series 10 (42mm, GPS) for $376 at Amazon, down from its