Set as Homepage - Add to Favorites

九九视频精品全部免费播放-九九视频免费精品视频-九九视频在线观看视频6-九九视频这-九九线精品视频在线观看视频-九九影院

【порнография молодые кореянки】Zoom lets a website turn on your Mac's camera without permission

Video conferencing app Zoom has a major security flaw in its Mac client,порнография молодые кореянки letting any website turn on your Mac's camera without a warning, security researcher Jonathan Leitschuh claims.

In a blog post Monday, Leitschuh detailed the vulnerability, which he says he'd disclosed to Zoom more than 90 days ago, and the company still hasn't fixed it.

SEE ALSO: Google Nest camera security flaw allows former owners to observe others' homes

The problem lies in Zoom's usage of a web server on users' local machines. This makes some of Zoom's cool features possible, for example, clicking on a simple link in your web browser automatically starts up the app.

Having an app install and run a web server on a user's machine with an undocumented API "feels incredibly sketchy," Leitschuh says. But there's more. According to Leitschuh, "this web server can do far more than just launch a Zoom meeting. (...) this web server can also re-install the Zoom app if a user has uninstalled it."

This is bad by itself, but Leitschuh discovered a vulnerability that let him launch a Zoom call, with video enabled, on a user's machine without permission. The same vulnerability allows the attacker to perform a DOS (denial of service) type attack on a user's machine.

Mashable Light Speed Want more out-of-this world tech, space and science stories? Sign up for Mashable's weekly Light Speed newsletter. By clicking Sign Me Up, you confirm you are 16+ and agree to our Terms of Use and Privacy Policy. Thanks for signing up!

Leitschuh says that he'd contacted Zoom on March 26, offering the company a quick fix for the vulnerability. After a lot of back and forth, Zoom partially fixed the flaw, but Leitschuh was able to bypass their fix, after which the company offered no additional fix. The security issue is still present in the latest version of Zoom for Mac, 4.4.4.

In a blog post Monday, Zoom defended its app's functionality, claiming that users are prompted to turn their video off when joining their first meeting, and can set the video to off in subsequent meetings; if they do so, it would be impossible for the host or other participants to turn their camera on. Furthermore, Zoom claims, "because the Zoom client user interface runs in the foreground upon launch, it would be readily apparent to the user that they had unintentionally joined a meeting and they could change their video settings or leave immediately."

The company said they will give users more control of their video settings in an upcoming, July 2019 release.

The company also addresses the presence of the web server on user machines, saying it's a "workaround to a change introduced in Safari 12" and a "legitimate solution to a poor user experience problem."

Zoom has assessed that both the video call issue and the DOS issue were "low risk," which is why the company decided not to change the app's functionality. The company also promised it will launch a public vulnerability disclosure program in the "next several weeks."

The main question users should be asking themselves is whether they want to sacrifice their system's security for a bit of added functionality -- likely, functionality they can live without. Zoom's ability to re-install itself without user permission after it's been uninstalled is particularly worrisome. Since there's no official fix for the issue, you can remove Zoom's web server from your machine by following the steps described in Leitschuh's post.


Featured Video For You
Flipboard’s data breach exposes usernames, passwords

Topics Cybersecurity

0.1259s , 7980.328125 kb

Copyright © 2025 Powered by 【порнография молодые кореянки】Zoom lets a website turn on your Mac's camera without permission,Data News Analysis  

Sitemap

Top 主站蜘蛛池模板: 两性色午夜视频免费网 | 天堂mv在线mv免费mv香蕉 | 成人免费看www网址入口 | 国产激情在线观看免费视频 | 亚洲无线码| 视频一区视频二区日韩专区 | 91日本在线观看亚洲精品 | 亚洲男人夜夜精品电影 | 国产又黄的a级鬼片在线观看 | 精品区在线观看 | 日韩精品一区二区三区中文字幕 | 丝瓜影院首页 | 豆国产97在线 | 国产精品部在 | 免费观看视频 | 扒开老师大| 一次处破女hd精品 | 国产视频高清在线观看 | 99re这里只有精品国产精品 | 国产在线欧 | 欧美中文字幕在线第一页 | 两性色午夜视频免费国产 | 国产一卡2卡3卡4卡网站免费 | 免费一级欧美片在线观看欧美 | 国产免费直播在线观看视频 | 欧美日韩综合另类 | 亚洲日产在线播 | 国产亚洲高清一区二区 | 欧美一级精品视频一区 | 免费人成视频在线观看播放网站 | 韩国日本免费不 | 国产色a在线观看 | 日韩欧美国产精品免费一二 | 日本中文字幕有码在线播放 | 妇女偷汉对白视频 | 今日吃瓜 | 日韩综合一二三区视 | 国产高颜值大学生情侣酒店 | 日本成a人片在线播放 | 日韩高清在线日韩视一区 | 欧美日韩一区二区综合 |