Zoom for Mac Has Two New Security Flaws GA S REGULAR Menu Lifewire Tech for Humans Newsletter! Search Close GO News > Software & Apps
Zoom for Mac Has Two New Security Flaws
They require local access to your Mac, but can let hackers take over
By Rob LeFebvre Rob LeFebvre Associate Editorial Director, News UCLA California State University, Northridge Rob LeFebvre is the Associate Editorial Director, News for Lifewire. He has been a technology writer for more than 12 years with articles appearing in 148Apps, Cult of Mac, Engadget, and more. lifewire's editorial guidelines Published on April 1, 2020 01:47PM EDT Tweet Share Email Tweet Share Email Software & Apps Mobile Phones Internet & Security Computers & Tablets Smart Life Home Theater & Entertainment Software & Apps Social Media Streaming Gaming Making sure your Mac is secure while using Zoom is paramount, of course, but as this attack requires local access to your computer, it's less an issue of fear. More importantly, we all need to be aware of the status of the tools we all suddenly find ourselves using, and ask the developers to patch things as soon as possible. Original image by Pixabay Ex-NSA hacker Patrick Wardle discovered two new vulnerabilities in the suddenly-popular Zoom software for macOS. Stay calm: First of all, the security flaws require local access to your Mac, which means someone malicious has to physically use your computer to make it happen. So it's of less concern than, say, a hack that can work remotely, over the internet. The details: The first bug involves how Zoom gets installed on Mac. A local attacker who even has low-level system privileges can add malicious code to the Zoom installer to grant themselves root access, which is the highest level possible on Mac. The attacker can then do basically whatever they want on your system, including running spyware or malware on it. The second vulnerability involves an ability to add malicious code to Zoom to give the attacker access to your webcam and microphone. They can then watch and record your video stream and hear what you're saying in meetings. When will this be fixed: So far, Zoom hasn't made any fixes to its app, but it's likely they will. Don't over worry: Yes, this is a big deal in the sense that we're all using any and every tool out there to manage our pandemic stay-at-home business and personal lives, and we have to be aware of issues like this. Of course, don't let anyone you don't know use your Mac, but also make sure you know the potential risks when using Zoom or other software that may also have vulnerabilities that aren't discovered because they're less popular. Ultimately, whether you continue to use Zoom or not, be sure to update it when the new vulnerabilities (there are also some for Windows) are patched. Via: TechCrunch Learn More About Zoom
How to Use Zoom: The 13 Best Tips for Successful Video Conferencing How to Change Background on Zoom Was this page helpful? Thanks for letting us know! Get the Latest Tech News Delivered Every Day Subscribe Tell us why! Other Not enough details Hard to understand Submit More from Lifewire How to Zoom In or Out With Your Keyboard How to Change the Font Size on Your Screen How to Use Lockdown Mode on Mac How to Fix It When a Zoom Camera Is Not Working How to Zoom in or out on Windows or a Mac How to Zoom In and Out on Apple Watch How to Use an iPhone as a Webcam How to Use Zoom, Apple's Built-In Screen Magnifier How to Update Your Logitech Unifying Receiver How to Use Zoom on an iPhone How to Use Zoom on Android How to Use Zoom: The 13 Best Tips for Successful Video Conferencing How to Update Zoom on Your Desktop (Windows or Mac) How to Change Background on Zoom How to Update Zoom on Chromebook 5 MacBook Security Tips - Internet / Network Security Newsletter Sign Up Newsletter Sign Up Newsletter Sign Up Newsletter Sign Up Newsletter Sign Up By clicking “Accept All Cookies”, you agree to the storing of cookies on your device to enhance site navigation, analyze site usage, and assist in our marketing efforts. Cookies Settings Accept All Cookies