Zoom Vulnerability Could Let Websites Turn on Your Mac's Cameras Without Permission

Zoom doesn’t seem to be doing much about it.

Advertisement
By Gaurav Shukla | Updated: 9 July 2019 12:05 IST
Highlights
  • Zoom installs a local Web server on Mac
  • Even after deleting the Zoom app, the Web server remains functional
  • Web server can even re-install Zoom client without user interaction
Zoom Vulnerability Could Let Websites Turn on Your Mac's Cameras Without Permission

The vulnerability was originally disclosed to Zoom on March 26

Photo Credit: Zoom

A zero-day vulnerability present in the popular video conferencing app Zoom for Mac computers has come to light. Disclosed by security researcher Jonathan Leitschuh in a Medium post earlier today, the vulnerability allows any malicious website to forcibly join a Mac user to a Zoom call with video camera activated. This is possible because of a Web server installed by Zoom on Mac computers. Even after you have uninstalled the application, the Web server remains functional and “can reinstall the Zoom client without requiring any user interaction.”

In the Medium post, Leitschuh writes that the security vulnerability potentially exposes hundreds of thousands of businesses that use Zoom for Mac on a daily basis to exploitation. The flaw is a result of Zoom feature that triggers the Zoom client when a Zoom meeting link is clicked. Unless the user has explicitly configured their Zoom client to disable video upon joining meetings, their video is immediately shared with anyone they are in a Zoom call with, including an attacker who has exploited the vulnerability to trigger a video call.

According to Leitschuh, the vulnerability could also allow any webpage to DoS (Denial of Service) a Mac by repeatedly joining a user to an invalid call. This is, however, only possible if a person is running an older unpatched version of Zoom, which included another vulnerability.

Leitschuh had disclosed the Mac-related vulnerability to Zoom back in March this year along with a proposed “quick fix”, however he claims that the company took ten days to confirm the existence of the vulnerability and a total of 87 days to fix the issue with the “quick fix” solution.

Advertisement

The quick fix implemented by Zoom doesn't patch the vulnerability completely and there are still workarounds to exploit it.

The company has now stated that it plans to apply and save the user's video preference from their first Zoom meeting to all future Zoom meetings. Thereby allowing them to switch off video by default for all Zoom meetings, however if a user keeps the video option on, they will still be vulnerable to malicious third parties as the company doesn't seem to have any plans to change the Web server or its behaviour.

Advertisement

“Zoom installs a local Web server on Mac devices running the Zoom client. This is a workaround to an architecture change introduced in Safari 12 that requires a user to accept launching Zoom before every meeting,” Zoom said in a statement on its website. “The local web server automatically accepts the peripheral access on behalf of the user to avoid this extra click before joining a meeting. We feel that this is a legitimate solution to a poor user experience, enabling our users to have seamless, one-click-to-join meetings, which is our key product differentiator.”

Essentially, it is up to the Mac users to turn their cameras off by default to avoid giving other a peek into their lives.

Advertisement

How to patch Zoom on your Mac right now

  • Head over to Zoom client settings on Mac, then select Video.
  • In the Meetings section of Video settings, check the option “Turn off my video when joining a meeting”.

Photo Credit: Medium/ Jonathan Leitschuh

 

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Further reading: Zoom, Zero Day, Apple, Mac, Safari
Advertisement

Related Stories

Popular Mobile Brands
  1. Apple Announces iOS 26 With Liquid Glass Design, These New Features
  2. ChatGPT Down: Users Report Problems While Generating Responses
  3. Motorola Edge 60 With 5,500mAh Battery Launched in India: Price, Offers
  4. Everything We Know About the Vivo T4 Ultra Ahead of Its June 11 Launch
  5. Samsung Galaxy Z Fold 7 Claimed to Be Thinnest, Lightest Foldable to Date
  6. Lava Storm Play 5G, Storm Lite 5G Design Teased; India Launch Date Set
  7. WazirX Parent Zettai Seeks Moratorium Extension, Responds to Court Criticism
  8. WWDC: Prepare for iOS 26, iPadOS 26, and the Dazzling Era of Liquid Glass
  1. Realme GT 7, Realme GT 7T Get Up to Rs. 6,000 Discount for a Limited Time in India
  2. Nothing Phone 3 Leaked Render Suggests Transparent Back Panel, Triple Rear Cameras, No Glyph Interface
  3. ChatGPT Down: Thousands of Users Report Problems While Generating Responses, Video Generation on Sora
  4. Hollow Knight: Silksong Will Release Before Holiday 2025, Not Tied to Xbox Ally Launch, Developer Says
  5. Samsung Galaxy S25 Ultra Allegedly Saves Life by Stopping Shrapnel; Samsung Offers Free Repair
  6. WWDC 2025: Xcode 26 Adds ChatGPT Integration, Support for Other AI Models
  7. Vivo Y400 Pro Design, Key Specifications Leaked; Tipped to Get Dimensity 7300 SoC, 5,500mAh Battery
  8. Motorola Edge 60 With MediaTek Dimensity 7400 SoC, Triple Rear Cameras Launched in India: Price, Features
  9. iPadOS 26 Brings Improved Multitasking With New Windowing System, Menu Bar, and More
  10. WWDC 2025: visionOS 26 Announced With Improvements to Personas and New Spatial Features
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.