AfterDawn: Tech news

Zoom flaw put Mac webcams at risk of hijacking, says researcher

Written by James Delahunty @ 09 Jul 2019 11:36

Zoom flaw put Mac webcams at risk of hijacking, says researcher

Some Macs may have been vulnerable to webcam hijacking due to a flaw in how the Zoom video conferencing app handled one-click-joining.
Zoom aims to make it as easy as possible to add users to a video conference. One of its selling points is that users can join a video conference session by clicking on a link. However, the way in which this was achieved posed some security risks.

Researcher Jonathan Leitschuh found that the Mac version of the app installs a web server on the local machine. The web server left the user's computer open to certain attacks.

For example, an attacker could send a target a link to a maliciously crafted website that would join the user to the Zoom call with their webcam activated. A malicious page could also effectively carry out a denial of service attack on the Mac by repeatedly forcing the user to join an invalid call.



Another issue noted by Leitschuh is that even after the Zoom client is installed, the local web server remains and can be tricked to reinstall the Zoom client by visiting a malicious webpage.

The Windows version of the software is not vulnerable.

The first flaw which could force users into a conference call with the webcam activated did not affect any use that manually changed a setting that turned video off when they joined a meeting.

An update has been pushed out by Zoom that ensures video is turned off on joining a meeting by default. Zoom also disputed the scale of Leitschuh's claims.

The developer also said that there was no evidence of the flaw being exploited in the wild, and that had users been targeted in this way it would have been very clear they had unintentionally joined a video conference, as the software is forced to the foreground.

Tags: Zoom
Previous Next  
Comments have been disabled for this article.

Latest news

GitHub Copilot to train its AI with users' prompts, code - here's how to opt out GitHub Copilot to train its AI with users' prompts, code - here's how to opt out (30 Mar 2026 3:49)
GitHub, the world's largest code repository for software development projects, owned by Microsoft, will start using user interactions to train its AI models.
Sony suspends memory card sales because memory chips are simply not available Sony suspends memory card sales because memory chips are simply not available (28 Mar 2026 6:49)
Sony has announced that it is temporarily suspending the sale of memory cards used in mobile phones and digital cameras, among other things. The company states that the reason is problems with the availability of memory chips.
Austria plans to ban social media for under 14 year olds Austria plans to ban social media for under 14 year olds (28 Mar 2026 6:17)
Austria is planning to ban social media for children under 14. The reform aims to protect children from harmful effects and addictions, but at the same time, it is problematic from a privacy perspective.
TP-Link urges users to update their routers - several vulnerabilities patched TP-Link urges users to update their routers - several vulnerabilities patched (26 Mar 2026 1:56)
Serious security vulnerabilities have been discovered in several TP-Link router models, for which patches were released at the end of March 2026. The company urges users to update their router software immediately.
Google: The feared Q-Day is now expected to happen in 2029 Google: The feared Q-Day is now expected to happen in 2029 (25 Mar 2026 4:32)
Google has advanced its estimate of when current forms of encryption will become insecure. The moment is called Q-Day, or Quantum Day, when the computational power of quantum computers will be sufficient to break currently used encryptions.

News archive