Set as Homepage - Add to Favorites

日韩欧美成人一区二区三区免费-日韩欧美成人免费中文字幕-日韩欧美成人免费观看-日韩欧美成人免-日韩欧美不卡一区-日韩欧美爱情中文字幕在线

【映画 館 アダルト】Zoom lets a website turn on your Mac's camera without permission

Video conferencing app Zoom has a major security flaw in its Mac client,映画 館 アダルト letting any website turn on your Mac's camera without a warning, security researcher Jonathan Leitschuh claims.

In a blog post Monday, Leitschuh detailed the vulnerability, which he says he'd disclosed to Zoom more than 90 days ago, and the company still hasn't fixed it.

SEE ALSO: Google Nest camera security flaw allows former owners to observe others' homes

The problem lies in Zoom's usage of a web server on users' local machines. This makes some of Zoom's cool features possible, for example, clicking on a simple link in your web browser automatically starts up the app.

Having an app install and run a web server on a user's machine with an undocumented API "feels incredibly sketchy," Leitschuh says. But there's more. According to Leitschuh, "this web server can do far more than just launch a Zoom meeting. (...) this web server can also re-install the Zoom app if a user has uninstalled it."

This is bad by itself, but Leitschuh discovered a vulnerability that let him launch a Zoom call, with video enabled, on a user's machine without permission. The same vulnerability allows the attacker to perform a DOS (denial of service) type attack on a user's machine.

Mashable Light Speed Want more out-of-this world tech, space and science stories? Sign up for Mashable's weekly Light Speed newsletter. By clicking Sign Me Up, you confirm you are 16+ and agree to our Terms of Use and Privacy Policy. Thanks for signing up!

Leitschuh says that he'd contacted Zoom on March 26, offering the company a quick fix for the vulnerability. After a lot of back and forth, Zoom partially fixed the flaw, but Leitschuh was able to bypass their fix, after which the company offered no additional fix. The security issue is still present in the latest version of Zoom for Mac, 4.4.4.

In a blog post Monday, Zoom defended its app's functionality, claiming that users are prompted to turn their video off when joining their first meeting, and can set the video to off in subsequent meetings; if they do so, it would be impossible for the host or other participants to turn their camera on. Furthermore, Zoom claims, "because the Zoom client user interface runs in the foreground upon launch, it would be readily apparent to the user that they had unintentionally joined a meeting and they could change their video settings or leave immediately."

The company said they will give users more control of their video settings in an upcoming, July 2019 release.

The company also addresses the presence of the web server on user machines, saying it's a "workaround to a change introduced in Safari 12" and a "legitimate solution to a poor user experience problem."

Zoom has assessed that both the video call issue and the DOS issue were "low risk," which is why the company decided not to change the app's functionality. The company also promised it will launch a public vulnerability disclosure program in the "next several weeks."

The main question users should be asking themselves is whether they want to sacrifice their system's security for a bit of added functionality -- likely, functionality they can live without. Zoom's ability to re-install itself without user permission after it's been uninstalled is particularly worrisome. Since there's no official fix for the issue, you can remove Zoom's web server from your machine by following the steps described in Leitschuh's post.


Featured Video For You
Flipboard’s data breach exposes usernames, passwords

Topics Cybersecurity

0.1475s , 9827.140625 kb

Copyright © 2025 Powered by 【映画 館 アダルト】Zoom lets a website turn on your Mac's camera without permission,Public Opinion Flash  

Sitemap

Top 主站蜘蛛池模板: 2024天堂在线亚洲精品专区 | 国产婷婷在线精品综合 | 国产制服专区在线观看 | 国产欧美亚洲精品 | 国产人妻大保健私密推油按摩无码 | 免费看一区无码无A片 | WWW国产亚洲精品久久 | 久久无码精品一一区二区三区 | 四虎影视国产在线观看精品 | 2024国产精品网站在线播放 | 色窝窝免费播放视频在线 | 波多野结衣人妻渴望A片 | 三级黄rlri看三级黄 | 海角社区破解版 | 99国产精品久久久久久久成人热 | 91精品无人区麻豆乱码一区 | 国产免费网站看v片元遮挡 国产免费网站看V片在线观看 | 国产欧美精品AAAAAA片 | WWW色情成人免费视频软件 | 人禽无码视频在线观看 | 日本人妻和老人中文字幕 | 久久国产毛片 | 无码高潮又爽又黄A片日本动漫 | 久久无码人妻热线精品 | 亚洲色精品一区二区三区四区 | 久久国产日韩精品久久 | 91精品自拍视频在线观看 | 伊人久久精品一区二区三区 | 国产cd人妖在线观看 | a亚洲无码中字幕在线观看 a亚洲在线观看不卡高清 | 91性高湖久久久久久精品中文字幕 | 精品人妻无码一区二区三区手机板 | 在线观看av不卡网站永久 | 日韩精品人妻系列无码专区 | 久久久久久老熟妇人妻av | 精品国产亚一区二区三区 | 色成人国产欧美一区二区三区 | 精品无码三级在线观看 | 伊人无码视屏 | 国产水多视频在线观看免费 | 欧美亚洲国产一区二区三区 |