Live data from Hacker News

Vulnerability in the Mac Zoom client allows malicious websites to enable camera

medium.com

11–20 of 473 posts

Re: Vulnerability in the Mac Zoom client allows malicious websites to enable camera

#11
post #5

Note: "Zoom" is a videoconfrerencing app, not a built-in Mac OS accessibility feature for "zoom". The article does not clearly state this, ceding a plain English word to a corporation, enabling a takeover of human language. P.S.: This part > Apr 26, 2019 — Video call with Mozilla and Zoom Security Teams is funny, and would be way funnier if it was an non-consensual video call. Finally, note that Zoom effectively does…

>The article does not clearly state this, ceding a plain English word to a corporation, enabling a takeover of human language.

I agree with your outrage, but you have a long way to go. That sort of behavior is the soup du jour of SV the past ten years or so.

Keep fighting the good fight. I've given up, but I hope you win.

Re: Vulnerability in the Mac Zoom client allows malicious websites to enable camera

#12
post #2

“On Mac, if you have ever installed Zoom, there is a web server on your local machine running on port 19421.” ... “All a website would need to do is embed the above in their website and any Zoom user will be instantly connected with their video running. This is still true today!”

This server is still running on my machine despite having "removed" Zoom a few months ago (macOS).

Guess I was a bit naive in thinking just trashing the .app and immediate artifacts in Library would do the trick.

EDIT: I missed the .zoomus directory in my home folder that had the culprit. Funny enough Zoom's instructions on how to uninstall the app on macOS just points to documentation from Apple and wikiHow (???) with standard methods that don't fully remove Zoom.

Re: Vulnerability in the Mac Zoom client allows malicious websites to enable camera

#13
post #4

Sooo... this is still vulnerable?!

Personally, I do not think so.

I did a test with myself and a coworker. I’m using macOS 10.12; he’s using 10.14. We both have up-to-date Zoom clients.

In our Zoom clients, we both already had the “Turn off my video when joining a meeting” box checked.

I set up a meeting, with participant video set to On, as the article describes. I took the new Meeting ID, launched Zoom, and joined my new meeting. I then sent my coworker the join URL using Slack.

My coworker clicked on the link, which opened the URL in Safari. Safari asked my coworker if he wanted to launch Zoom. My coworker confirmed that yes, he wanted to launch Zoom.

My coworker’s Zoom client did _not_ automatically start video. I never saw video come in from him.

Re: Vulnerability in the Mac Zoom client allows malicious websites to enable camera

#14
post #10
post #4

Sooo... this is still vulnerable?!

Yes. Try this link from the article to see it in action if you have (or had) Zoom installed: https://jlleitschuh.org/zoom_vulnerability_poc/ WARNING, this will open a video chat with random strangers, and will turn your webcam on. Consider yourself warned!

HOLLY SH*T! This is insane.

Re: Vulnerability in the Mac Zoom client allows malicious websites to enable camera

#17
post #4

Sooo... this is still vulnerable?!

Personally, I do not think so. I did a test with myself and a coworker. I’m using macOS 10.12; he’s using 10.14. We both have up-to-date Zoom clients. In our Zoom clients, we both already had the “Turn off my video when joining a meeting” box checked. I set up a meeting, with participant video set to On, as the article describes. I took the new Meeting ID, launched Zoom, and joined my new meeting. I then sent my cowo…

> In our Zoom clients, we both already had the “Turn off my video when joining a meeting” box checked.

I believe this is one of the mitigations, which is why it didn’t work.

Re: Vulnerability in the Mac Zoom client allows malicious websites to enable camera

#18
post #2

“On Mac, if you have ever installed Zoom, there is a web server on your local machine running on port 19421.” ... “All a website would need to do is embed the above in their website and any Zoom user will be instantly connected with their video running. This is still true today!”

I’m surprised more enterprise IT orgs haven’t flagged this behavior, or simply made it impossible via local machine policies that would prevent running a web server.

.../.zoomus/ZoomOpener.app/Contents/MacOS/ZoomOpener

Re: Vulnerability in the Mac Zoom client allows malicious websites to enable camera

#19
post #17

Earlier quoted context omitted.

Personally, I do not think so. I did a test with myself and a coworker. I’m using macOS 10.12; he’s using 10.14. We both have up-to-date Zoom clients. In our Zoom clients, we both already had the “Turn off my video when joining a meeting” box checked. I set up a meeting, with participant video set to On, as the article describes. I took the new Meeting ID, launched Zoom, and joined my new meeting. I then sent my cowo…

> In our Zoom clients, we both already had the “Turn off my video when joining a meeting” box checked. I believe this is one of the mitigations, which is why it didn’t work.

That makes sense. But, I don’t remember ever turning on that checkbox.
Post reply on HN