Apple Silently Patches Zoom Mac Vulnerability Without User Action
Apple automatically pushes a silent update to Macs that removes a hidden Zoom web server capable of activating user cameras without permission.
Apple releases a silent update for Mac users to eliminate a vulnerable hidden web server installed by the Zoom video conferencing app. This undocumented component allows any website to forcibly join a user to a video call and activate their camera without any permission. Apple deploys this automatic patch without requiring any user interaction to protect people from this severe privacy risk.
The vulnerability comes to light after security researcher Jonathan Leitschuh publicly discloses the flaw and provides a proof-of-concept demonstration. He reveals that the hidden web server stays installed even if a user completely uninstalls Zoom, creating a persistent loophole that allows the app to reinstall itself. Although Zoom releases its own patched app version, Apple takes the rare step of independently pushing a system-level fix.
Apple states that this background update protects both past and present users without hindering the core functionality of the Zoom application. Moving forward, the fix ensures that the app prompts users before opening instead of launching automatically. Zoom expresses appreciation for Apple's collaboration in resolving the issue, which impacts millions of users across hundreds of thousands of companies worldwide.