国产精品美女一区二区三区-国产精品美女自在线观看免费-国产精品秘麻豆果-国产精品秘麻豆免费版-国产精品秘麻豆免费版下载-国产精品秘入口

Set as Homepage - Add to Favorites

【lee???? ????????】Zoom lets a website turn on your Mac's camera without permission

Source:Global Hot Topic Analysis Editor:fashion Time:2025-07-03 04:52:10

Video conferencing app Zoom has a major security flaw in its Mac client,lee???? ???????? letting any website turn on your Mac's camera without a warning, security researcher Jonathan Leitschuh claims.

In a blog post Monday, Leitschuh detailed the vulnerability, which he says he'd disclosed to Zoom more than 90 days ago, and the company still hasn't fixed it.

SEE ALSO: Google Nest camera security flaw allows former owners to observe others' homes

The problem lies in Zoom's usage of a web server on users' local machines. This makes some of Zoom's cool features possible, for example, clicking on a simple link in your web browser automatically starts up the app.

Having an app install and run a web server on a user's machine with an undocumented API "feels incredibly sketchy," Leitschuh says. But there's more. According to Leitschuh, "this web server can do far more than just launch a Zoom meeting. (...) this web server can also re-install the Zoom app if a user has uninstalled it."

This is bad by itself, but Leitschuh discovered a vulnerability that let him launch a Zoom call, with video enabled, on a user's machine without permission. The same vulnerability allows the attacker to perform a DOS (denial of service) type attack on a user's machine.

Mashable Light Speed Want more out-of-this world tech, space and science stories? Sign up for Mashable's weekly Light Speed newsletter. By clicking Sign Me Up, you confirm you are 16+ and agree to our Terms of Use and Privacy Policy. Thanks for signing up!

Leitschuh says that he'd contacted Zoom on March 26, offering the company a quick fix for the vulnerability. After a lot of back and forth, Zoom partially fixed the flaw, but Leitschuh was able to bypass their fix, after which the company offered no additional fix. The security issue is still present in the latest version of Zoom for Mac, 4.4.4.

In a blog post Monday, Zoom defended its app's functionality, claiming that users are prompted to turn their video off when joining their first meeting, and can set the video to off in subsequent meetings; if they do so, it would be impossible for the host or other participants to turn their camera on. Furthermore, Zoom claims, "because the Zoom client user interface runs in the foreground upon launch, it would be readily apparent to the user that they had unintentionally joined a meeting and they could change their video settings or leave immediately."

The company said they will give users more control of their video settings in an upcoming, July 2019 release.

The company also addresses the presence of the web server on user machines, saying it's a "workaround to a change introduced in Safari 12" and a "legitimate solution to a poor user experience problem."

Zoom has assessed that both the video call issue and the DOS issue were "low risk," which is why the company decided not to change the app's functionality. The company also promised it will launch a public vulnerability disclosure program in the "next several weeks."

The main question users should be asking themselves is whether they want to sacrifice their system's security for a bit of added functionality -- likely, functionality they can live without. Zoom's ability to re-install itself without user permission after it's been uninstalled is particularly worrisome. Since there's no official fix for the issue, you can remove Zoom's web server from your machine by following the steps described in Leitschuh's post.


Featured Video For You
Flipboard’s data breach exposes usernames, passwords

Topics Cybersecurity

0.1377s , 10013.3203125 kb

Copyright © 2025 Powered by 【lee???? ????????】Zoom lets a website turn on your Mac's camera without permission,Global Hot Topic Analysis  

Sitemap

Top 主站蜘蛛池模板: a片无限看日本的 | 91超级碰久久久久香蕉人人 | www.亚洲天堂网 | a片地址 | 潮喷大喷水系列无 | 99久久99久久精品 | 国产91色综合九九高清在线观看 | 午夜福利视频一区二区 | 99久久久久国产精品免费 | 99久久无码一区人妻a黑 | 国产爆乳合集在线播放 | 波多野吉衣人妻无码潮喷av | 国产av自拍人人操 | 国产91福利久久aⅴ无码 | av永久综合在线观看红杏 | 福利姬视频在线观看 | 二区三区道夜a | 成年人黄色大片大全 | 丰满少妇大力进入 | 99热国品| 91精品国产91热久久久福利 | 韩国午夜无码片在线观看 | 97av无码人妻秘书 | 1区2区3区4区精品免费视频 | 91星空无限传媒在线 | av手机原创精品网址 | 91制片厂果冻传媒天美 | 高清大片国产片 | 动精品动漫专区3d在线看 | 丰满人妻熟妇乱又伦精品视频三 | 国产720刺激在线视频 | 国产v在线在线 | 97精品人妻无码专区在线视频区 | A片又大又粗又爽免费视频 a片在线播放 | 午夜福利国产在线观看 | 丰满老熟女毛片 | 91精品国产综合久久四虎久久 | A片人人澡C片人人人妻付费 | 一区两区三不卡 | 午夜无码视频在 | 久久精品福利 |