You Should Probably Update Zoom on Your Mac

Zoom has fixed a bug that could’ve allowed unrestricted access to macOS systems.

According to an Aug. 13 security bulletin(Opens in a new window), Zoom versions 5.7.3 to 5.11.5 contain an auto-update vulnerability that could be exploited by a local low-privileged user to gain unrestricted access to Apple’s operating system. The weakness, revealed by Mac security specialist Patrick Wardle at last week’s DefCon, was patched in Zoom version 5.11.5, which is available now.

The exploit targets the Zoom installer, which requires a user password when first added, The Verge notes(Opens in a new window). Wardle, however, found that an auto-update function running continuously in the background could be tricked into embedding malware by using Zoom’s cryptographic signature. Once inside the system, a hacker can modify, delete, or add files to the device.

“I was curious about exactly how they were setting this up,” Wardle told Wired(Opens in a new window) before his DefCon talk. “And when I took a look, it seemed on first pass that they were doing things securely—they had the right ideas. But when I looked closer, the quality of the code was more suspect, and it appeared that no one was auditing it deeply enough.”

On Twitter, Wardle praised(Opens in a new window) Zoom for its “incredibly quick fix.” In evaluating the patch, Wardle says the “Zoom installer now invokes lchown to update the permissions to the update .pkg, thus preventing malicious subversion.”

Recommended by Our Editors

To install the 5.11.5 update on your Mac, sign in to the Zoom desktop client, tap your profile picture, and select Check for updates. If there is a newer version, Zoom will download and install it.

At the other big security conference last week, Black Hat, another security researcher demonstrated how he used Zoom’s technology underlying other applications to completely control a target’s computer. Patches have also been issued for that vulnerability.

SecurityWatch newsletter for our top privacy and security stories delivered right to your inbox.”,”first_published_at”:”2021-09-30T21:22:09.000000Z”,”published_at”:”2022-03-24T14:57:33.000000Z”,”last_published_at”:”2022-03-24T14:57:28.000000Z”,”created_at”:null,”updated_at”:”2022-03-24T14:57:33.000000Z”})” x-show=”showEmailSignUp()” class=”rounded bg-gray-lightest text-center md:px-32 md:py-8 p-4 mt-8 container-xs” readability=”31.423799582463″>

Like What You’re Reading?

Sign up for SecurityWatch newsletter for our top privacy and security stories delivered right to your inbox.

This newsletter may contain advertising, deals, or affiliate links. Subscribing to a newsletter indicates your consent to our Terms of Use and Privacy Policy. You may unsubscribe from the newsletters at any time.

Facebook Comments Box

Hits: 0