Vulnerability in the Mac Zoom client allows malicious websites to enable camera
1–10 of 473 posts
Re: Vulnerability in the Mac Zoom client allows malicious websites to enable camera
#2...
“All a website would need to do is embed the above in their website and any Zoom user will be instantly connected with their video running. This is still true today!”
Re: Vulnerability in the Mac Zoom client allows malicious websites to enable camera
#3its more valuable than 90-days of a developer's time, not even correlated to time at all really
Re: Vulnerability in the Mac Zoom client allows malicious websites to enable camera
#4Re: Vulnerability in the Mac Zoom client allows malicious websites to enable camera
#5The article does not clearly state this, ceding a plain English word to a corporation, enabling a takeover of human language.
P.S.: This part
> Apr 26, 2019 — Video call with Mozilla and Zoom Security Teams
is funny, and would be way funnier if it was an non-consensual video call.
Finally, note that Zoom effectively does not pay for bug bounties, so researchers should think twice about donating their expertise to a selfish for-profit corporation, and users should think twice about using a videochat product that allows its entire security team to take blackout vacations, and also doesn't pay its outsourced sercurity researchers.
Re: Vulnerability in the Mac Zoom client allows malicious websites to enable camera
#6But, assuming I’m reading it correctly, the “maybe an RCE?” part seems like fear-mongering, because it would require that Zoom lose control of one of the domains that they trust for transparent client installs/upgrades.
I’m also a little concerned about how some parts of the article don’t match up. For example, the “UPDATE: June 7th, 2019:” does not have (as far as I can see) a matching entry in the Timeline. There is an entry for July 7, noting a regression; but there is an update the next day (July 8) noting that the regression has been fixed.
Re: Vulnerability in the Mac Zoom client allows malicious websites to enable camera
#7Re: Vulnerability in the Mac Zoom client allows malicious websites to enable camera
#8as demonstrated, "responsible disclosure" is a huge time waster for the discovery, and the price of this is undervalued even if the company had a clear bug bounty program. its more valuable than 90-days of a developer's time, not even correlated to time at all really
Re: Vulnerability in the Mac Zoom client allows malicious websites to enable camera
#9“On Mac, if you have ever installed Zoom, there is a web server on your local machine running on port 19421.” ... “All a website would need to do is embed the above in their website and any Zoom user will be instantly connected with their video running. This is still true today!”
Re: Vulnerability in the Mac Zoom client allows malicious websites to enable camera
#10Sooo... this is still vulnerable?!
WARNING, this will open a video chat with random strangers, and will turn your webcam on. Consider yourself warned!