Live data from Hacker News

Vulnerability in the Mac Zoom client allows malicious websites to enable camera

medium.com

1–10 of 473 posts

Re: Vulnerability in the Mac Zoom client allows malicious websites to enable camera

#2
“On Mac, if you have ever installed Zoom, there is a web server on your local machine running on port 19421.”

...

“All a website would need to do is embed the above in their website and any Zoom user will be instantly connected with their video running. This is still true today!”

Re: Vulnerability in the Mac Zoom client allows malicious websites to enable camera

#3
as demonstrated, "responsible disclosure" is a huge time waster for the discovery, and the price of this is undervalued even if the company had a clear bug bounty program.

its more valuable than 90-days of a developer's time, not even correlated to time at all really

Re: Vulnerability in the Mac Zoom client allows malicious websites to enable camera

#5
Note: "Zoom" is a videoconfrerencing app, not a built-in Mac OS accessibility feature for "zoom".

The article does not clearly state this, ceding a plain English word to a corporation, enabling a takeover of human language.

P.S.: This part

> Apr 26, 2019 — Video call with Mozilla and Zoom Security Teams

is funny, and would be way funnier if it was an non-consensual video call.

Finally, note that Zoom effectively does not pay for bug bounties, so researchers should think twice about donating their expertise to a selfish for-profit corporation, and users should think twice about using a videochat product that allows its entire security team to take blackout vacations, and also doesn't pay its outsourced sercurity researchers.

Re: Vulnerability in the Mac Zoom client allows malicious websites to enable camera

#6
The article’s actual title is: Zoom Zero Day: 4+ Million Webcams & maybe an RCE? Just get them to visit your website!

But, assuming I’m reading it correctly, the “maybe an RCE?” part seems like fear-mongering, because it would require that Zoom lose control of one of the domains that they trust for transparent client installs/upgrades.

I’m also a little concerned about how some parts of the article don’t match up. For example, the “UPDATE: June 7th, 2019:” does not have (as far as I can see) a matching entry in the Timeline. There is an entry for July 7, noting a regression; but there is an update the next day (July 8) noting that the regression has been fixed.

Re: Vulnerability in the Mac Zoom client allows malicious websites to enable camera

#7
Positively terrible... Kudos to this researcher. I liked Zoom when I used it a couple of times, but the reinstall “feature” is a huge violation of my trust. Software from the company behind it will not touch my system anymore. Too bad really, because properly working video chat is hard to find. The App Store model is not my favorite, but at times like these, a forced sandbox and inspection by a trusted third party start to look like the only way forward.

Re: Vulnerability in the Mac Zoom client allows malicious websites to enable camera

#8

as demonstrated, "responsible disclosure" is a huge time waster for the discovery, and the price of this is undervalued even if the company had a clear bug bounty program. its more valuable than 90-days of a developer's time, not even correlated to time at all really

I guess this depends on your definition of responsible. Something like this however is bad enough that users should be informed right away so that they can take steps necessary to secure themselves. Assuming they were responsive I'd have given them the 10 days to confirm it was an actual issue, but I'd have expected them to notify the pubic and their users of the issue and mitigation steps within a week.

Re: Vulnerability in the Mac Zoom client allows malicious websites to enable camera

#9
post #2

“On Mac, if you have ever installed Zoom, there is a web server on your local machine running on port 19421.” ... “All a website would need to do is embed the above in their website and any Zoom user will be instantly connected with their video running. This is still true today!”

I’m surprised more enterprise IT orgs haven’t flagged this behavior, or simply made it impossible via local machine policies that would prevent running a web server.

Re: Vulnerability in the Mac Zoom client allows malicious websites to enable camera

#10
post #4

Sooo... this is still vulnerable?!

Yes. Try this link from the article to see it in action if you have (or had) Zoom installed: https://jlleitschuh.org/zoom_vulnerability_poc/

WARNING, this will open a video chat with random strangers, and will turn your webcam on. Consider yourself warned!

Post reply on HN