Zoom Patches Mac Web Server Flaw That Enabled Secret Camera Activation
Zoom releases a patch for its Mac client to remove a hidden web server that allows websites to force users into video calls without permission. The vulnerability, which remains active even after uninstalling the app, affects over four million Mac users.
Video conferencing company Zoom releases a patch for its Mac client that removes a hidden web server allowing any website to force users into a video call without permission. Security researcher Jonathan Leitschuh discovers that this web server remains on a user's computer even after they uninstall the Zoom application, automatically reinstalling the software the moment a user visits a malicious webpage.
The flaw essentially acts as a zero-day vulnerability that puts over four million Mac users at risk of an invasion of privacy. Leitschuh reports that he discloses the issue to Zoom in March and provides a proposed quick fix, but the company takes over three months to implement a solution, missing the standard 90-day disclosure window.
Zoom acknowledges the security issue and confirms that its default setting turns on a user's video when they join a meeting, which theoretically creates a potential exploit for hackers. The company states that it has no indication that any bad actors have ever actually exploited this flaw in the wild, but users are highly encouraged to update their Mac client immediately.