Apple has pushed a silent Mac update to remove hidden Zoom web server
1–10 of 552 posts
Re: Apple has pushed a silent Mac update to remove hidden Zoom web server
#2Re: Apple has pushed a silent Mac update to remove hidden Zoom web server
#3Re: Apple has pushed a silent Mac update to remove hidden Zoom web server
#4From the article, this sounds like it was a GateKeeper change, de-whitelisting the signature, rather than an update, per se.
Re: Apple has pushed a silent Mac update to remove hidden Zoom web server
#5My Macbook pro froze this morning...the mouse moved, but I couldn't interact with anything. After a few mins, I hard rebooted it, and it worked fine after that. I'm not sure if it was related to this update, but it's the first time that this has ever happened, so it's a little bit of a coincidence.
Re: Apple has pushed a silent Mac update to remove hidden Zoom web server
#6From the article, this sounds like it was a GateKeeper change, de-whitelisting the signature, rather than an update, per se.
Of note, Apple has had its own malware detection and removal system in place since the Mountain Lion - Snow Leopard timeframe. Since this article speaks to removal, it's sounding like the Zoom local server may have had its signature added to that system.
Re: Apple has pushed a silent Mac update to remove hidden Zoom web server
#7I wonder if there's a known exploit for the Zoom server specifically, or if Apple discovered one while looking into it. It seems strange for them to go to these lengths in this case when it sounds like other software has been using a similar technique too. Maybe it's just the reinstallation aspect that makes Zoom's case exceptional?
Re: Apple has pushed a silent Mac update to remove hidden Zoom web server
#8Earlier quoted context omitted.
Of note, Apple has had its own malware detection and removal system in place since the Mountain Lion - Snow Leopard timeframe. Since this article speaks to removal, it's sounding like the Zoom local server may have had its signature added to that system.
So the local server is not a regular price of software with a vulnerability, it is now considered malware?
So yes, malware.
Re: Apple has pushed a silent Mac update to remove hidden Zoom web server
#9From the article, this sounds like it was a GateKeeper change, de-whitelisting the signature, rather than an update, per se.
Re: Apple has pushed a silent Mac update to remove hidden Zoom web server
#10It's been really interesting to see how quickly the original Zoom response of "there's nothing wrong with this, everybody does it" ended up being reversed. I wonder if there's a known exploit for the Zoom server specifically, or if Apple discovered one while looking into it. It seems strange for them to go to these lengths in this case when it sounds like other software has been using a similar technique too. Maybe i…
"Additionally, if you’ve ever installed the Zoom client and then uninstalled it, you still have a localhost web server on your machine that will happily re-install the Zoom client for you, without requiring any user interaction on your behalf besides visiting a webpage. This re-install ‘feature’ continues to work to this day."