Saturday, May 10, 2025
Germany Latest News
  • Sports
  • USA
  • Asia
  • Health
  • Life Style
  • Tech
  • Science
  • Latin America
  • Africa
  • Europe
No Result
View All Result
Germany Latest News

Your Mac could be hijacked through major security flaw in Zoom conferencing app – CNET

by The Editor
July 9, 2019
in Science
0
Your Mac could be hijacked through major security flaw in Zoom conferencing app     – CNET

Zoom says the flaw was born out of a workaround for Safari 12.

Sarah Tew/CNET

Your computer's webcam has always been a gateway for potential security intrusion, which is why people like Mark Zuckerberg and ex-FBI head James Comey put tape over theirs. On Monday, security researcher Jonathan Leitschuh gave Mac users another reason to fret over their webcams — there's a security flaw in the Zoom video-conferencing app.

Zoom is most notable for its click-to-join feature, where clicking on a browser link takes you directly to a video meeting in Zoom's app. But Leitschuh in a Medium post explained that he months ago discovered Zoom achieves this in insecure ways, allowing websites to join you to a call as well as activating your webcam without your permission.

He adds that this would allow any webpage to denial-of-service a Mac by repeatedly joining you to an invalid call. Uninstalling the Zoom app from your Mac isn't enough to fix the problem, either. Zoom achieves its click-to-join function by installing a web server on your computer — which can reinstall Zoom without your permission.

"If you've ever installed the Zoom client and then uninstalled it, you still have a localhost web server on your machine that will happily re-install the Zoom client for you," Leitschuh writes, "without requiring any user interaction on your behalf besides visiting a webpage. This re-install 'feature' continues to work to this day."

1-mrgy9jojkkjsrp-xjsyomw

Here's the first setting you should change in Zoom.

Jonathan Leitschuh/Medium

If you have the Zoom app installed on your Mac, Leitschuh lists directions to neutralize the local server in his Medium post. You should also activate the Turn off my video setting when joining a meeting, as seen above.

The researcher says he contacted Zoom on March 26, giving the company a public disclosure deadline of 90 days. He says Zoom patched the issue, disabling the ability of a webpage to automatically turn on your webcam, but still this partial fix regressed on July 7, allowing webcams to once again be turned on without permission.

Zoom in a statement said the local web server is a workaround for Apple's Safari 12 web browser introduced last September.

"Zoom installs a local web server on Mac devices running the Zoom client," the statement reads. "This is a workaround to an architecture change introduced in Safari 12 that requires a user to accept launching Zoom before every meeting. The local web server automatically accepts the peripheral access on behalf of the user to avoid this extra click before joining a meeting. We feel that this is a legitimate solution to a poor user experiRead More – Source

cnet

Related posts

Can Misinfo Harm Science?

Can Misinfo Harm Science?

February 7, 2023
Climate change: World aviation agrees ‘aspirational’ net zero plan

Climate change: World aviation agrees ‘aspirational’ net zero plan

October 8, 2022

Zoom says the flaw was born out of a workaround for Safari 12.

Sarah Tew/CNET

Your computer's webcam has always been a gateway for potential security intrusion, which is why people like Mark Zuckerberg and ex-FBI head James Comey put tape over theirs. On Monday, security researcher Jonathan Leitschuh gave Mac users another reason to fret over their webcams — there's a security flaw in the Zoom video-conferencing app.

Zoom is most notable for its click-to-join feature, where clicking on a browser link takes you directly to a video meeting in Zoom's app. But Leitschuh in a Medium post explained that he months ago discovered Zoom achieves this in insecure ways, allowing websites to join you to a call as well as activating your webcam without your permission.

He adds that this would allow any webpage to denial-of-service a Mac by repeatedly joining you to an invalid call. Uninstalling the Zoom app from your Mac isn't enough to fix the problem, either. Zoom achieves its click-to-join function by installing a web server on your computer — which can reinstall Zoom without your permission.

"If you've ever installed the Zoom client and then uninstalled it, you still have a localhost web server on your machine that will happily re-install the Zoom client for you," Leitschuh writes, "without requiring any user interaction on your behalf besides visiting a webpage. This re-install 'feature' continues to work to this day."

1-mrgy9jojkkjsrp-xjsyomw

Here's the first setting you should change in Zoom.

Jonathan Leitschuh/Medium

If you have the Zoom app installed on your Mac, Leitschuh lists directions to neutralize the local server in his Medium post. You should also activate the Turn off my video setting when joining a meeting, as seen above.

The researcher says he contacted Zoom on March 26, giving the company a public disclosure deadline of 90 days. He says Zoom patched the issue, disabling the ability of a webpage to automatically turn on your webcam, but still this partial fix regressed on July 7, allowing webcams to once again be turned on without permission.

Zoom in a statement said the local web server is a workaround for Apple's Safari 12 web browser introduced last September.

"Zoom installs a local web server on Mac devices running the Zoom client," the statement reads. "This is a workaround to an architecture change introduced in Safari 12 that requires a user to accept launching Zoom before every meeting. The local web server automatically accepts the peripheral access on behalf of the user to avoid this extra click before joining a meeting. We feel that this is a legitimate solution to a poor user experiRead More – Source

cnet

Previous Post

After Jony Ive leaves Apple, these are the products he should redesign next – CNET

Next Post

Largely unchallenged, the Big Three stroll into the Wimbledon final eight

Next Post
Largely unchallenged, the Big Three stroll into the Wimbledon final eight

Largely unchallenged, the Big Three stroll into the Wimbledon final eight

RECOMMENDED NEWS

Moonshots may never see liftoff without a plan

Moonshots may never see liftoff without a plan

7 years ago
Taiwan by bike: Around the island in 12 days

Taiwan by bike: Around the island in 12 days

6 years ago
Massive superflares have been seen erupting from stars like the sun

Massive superflares have been seen erupting from stars like the sun

6 years ago
Pepe and protest pig: Internet memes come to life at Hong Kong rally

Pepe and protest pig: Internet memes come to life at Hong Kong rally

5 years ago

FOLLOW US

  • 139 Followers
  • 87.2k Followers
  • 202k Subscribers

BROWSE BY CATEGORIES

  • 1xbet Casino Russia
  • 1xbet Russian Top
  • Africa
  • Asia
  • Europe
  • Health
  • latest news
  • Latin America
  • Life Style
  • Mail Order Brides
  • Mostbet
  • Online dating
  • onlyfans
  • Pin Up
  • Pin Up Russia
  • Science
  • Sports
  • Tech
  • Uncategorized
  • USA

BROWSE BY TOPICS

2018 League Bali United Beijing BlackBerry Brazil Broja Budget Travel Bundesliga California Champions League Chelsea China Chopper Bike Coronavirus COVID COVID-19 Crime Doctor Terawan EU France French German Istana Negara Italy Kazakhstan Market Stories Mexico National Exam Nigeria Omicron Pakistan Police protests Qatar Ronaldo Russia Smart Voting Sweden TikTok Trump UK Ukraine US vaccine Visit Bali
No Result
View All Result

Recent Posts

  • OnlyFans Platform Analysis
  • How to Day German Fashion
  • Southeast Continental Capabilities
  • What is a Mail Order Wife?
  • What to Discuss on a First Date?

Categories

  • 1xbet Casino Russia
  • 1xbet Russian Top
  • Africa
  • Asia
  • Europe
  • Health
  • latest news
  • Latin America
  • Life Style
  • Mail Order Brides
  • Mostbet
  • Online dating
  • onlyfans
  • Pin Up
  • Pin Up Russia
  • Science
  • Sports
  • Tech
  • Uncategorized
  • USA

Tags

2018 League Bali United Beijing BlackBerry Brazil Broja Budget Travel Bundesliga California Champions League Chelsea China Chopper Bike Coronavirus COVID COVID-19 Crime Doctor Terawan EU France French German Istana Negara Italy Kazakhstan Market Stories Mexico National Exam Nigeria Omicron Pakistan Police protests Qatar Ronaldo Russia Smart Voting Sweden TikTok Trump UK Ukraine US vaccine Visit Bali
Federal Government focuses on “integrated security”
latest news

Federal Government focuses on “integrated security”

by The Editor
June 14, 2023
0

Berlin (dpa) – The Federal Government is responding to the challenges of an increasingly unstable world order by means of a “policy...

Read more

Recent News

  • OnlyFans Platform Analysis
  • How to Day German Fashion
  • Southeast Continental Capabilities

Category

  • 1xbet Casino Russia
  • 1xbet Russian Top
  • Africa
  • Asia
  • Europe
  • Health
  • latest news
  • Latin America
  • Life Style
  • Mail Order Brides
  • Mostbet
  • Online dating
  • onlyfans
  • Pin Up
  • Pin Up Russia
  • Science
  • Sports
  • Tech
  • Uncategorized
  • USA

Recent News

OnlyFans Platform Analysis

June 12, 2024

How to Day German Fashion

May 5, 2024
  • About
  • Advertise
  • Careers
  • Contact

© 2025 JNews - Premium WordPress news & magazine theme by Jegtheme.

No Result
View All Result
  • Sports
  • USA
  • Asia
  • Health
  • Life Style
  • Tech
  • Science
  • Latin America
  • Africa
  • Europe

© 2025 JNews - Premium WordPress news & magazine theme by Jegtheme.