I asked Zoom support about this and they sent me to this page: https://blog.zoom.us/wordpress/2019/07/08/response-to-video-... The key thing here is they think this is a fair trade-off because Safari asks if you want to open Zoom. > This is a workaround to a change introduced in Safari 12 that requires a user to confirm that they want to start the Zoom client prior to joining every meeting. The local web server enabl…
Vulnerability in the Mac Zoom client allows malicious websites to enable camera
311–320 of 473 posts
Re: Vulnerability in the Mac Zoom client allows malicious websites to enable camera
#312Earlier quoted context omitted.
(prior reply deleted once I read about the fucking local webserver & phantom reinstallation bullshit. Fuck zoom.)
It's ridiculous to install a constantly running web service that uses tricks to circumvent CORS protection and to get around Safari's protections, which were both rightly created to improve user's security. It's not a "so-called vulnerability". As the article describes, this could be used in concert with another vulnerability to achieve RCE. Combining vulnerabilities is often how RCE is attained. These actions undo t…
But the web server / CORS bypass is completely fucked up, nefarious, and unforgivable.
Accordingly, I edited my post.
Re: Vulnerability in the Mac Zoom client allows malicious websites to enable camera
#313Earlier quoted context omitted.
I’ve had viruses and anti viruses years before I had internet. Getting a virus was trivial in the 90’s when windows had no security and any program could do anything.
Your comment is a bit ambiguous. Are you saying that even retail software could be considered a virus just because of what it can do on the system? Or was virus software making it onto the machine in other ways?
Re: Vulnerability in the Mac Zoom client allows malicious websites to enable camera
#314Well, the company and product are dead to me now, gonna hassle our CTO to switch. I just really hope theres some dev at Zoom who hated this whole installing backdoors idea who's gonna have the greatest "I told you so" day at the office tomorrow.
Interesting to me that this would be your CTO’s decision.
Re: Vulnerability in the Mac Zoom client allows malicious websites to enable camera
#315Re: Vulnerability in the Mac Zoom client allows malicious websites to enable camera
#316Re: Vulnerability in the Mac Zoom client allows malicious websites to enable camera
#317I'm surprised that Mac doesn't have a built-in firewall that warns if an app installs something that listens on a port. They advertise OSX as being "secure by design."
Re: Vulnerability in the Mac Zoom client allows malicious websites to enable camera
#318edited: after some research it is clear that this would work in the Tor browser. So if you are logged into Zoom using your real ID a malicious Tor site could launch the client and harvest your name. And if you are only using the browser bundle (and not routing all traffic through Tor) Zoom and/or Zoom+government could use this to expose the real IP of tor users.
Re: Vulnerability in the Mac Zoom client allows malicious websites to enable camera
#319Earlier quoted context omitted.
Am I right in thinking that CORS only applies to Javascript-initiated requests? This trick uses an embedded image to make the request.
That's correct, and part of my point. If they used CORS headers correctly it could both be secure and not require a crazy image hack. The image hack seems like a lot of work to go through to make an app LESS secure.
If they set CORS to allow interaction from anywhere, why use an image and not load data with js?
Re: Vulnerability in the Mac Zoom client allows malicious websites to enable camera
#320Click on the app icon, hold, move to Trash.