Feed
 

Important Security Update for Zoom on Mac

Avatar Tony Still
There is a serious security vulnerability in the current version of Zoom for Mac. If you have it installed, you should update it soon using the very recent (14th Aug?) update.

Esteemed Mac security researcher Patrick Wardle reported this last December but Zoom's fix was flawed. He presented it at the Def Con conference last week and a valid fix is now available. Read more here.

The problem is with Zoom's auto-update that can be tricked into downloading any malware and then escalating its privileges to root (Wardle's slides are here). I believe this needs a local (to your Mac) user to trigger it but that could be an innocent (you?) prompted by a social engineering attack (ie they tricked you). The root access grants the malware access to everything.

Sadly this is not the first serious incident with Zoom on Mac, see The 'S' in Zoom, Stands for Security.

Re: Important Security Update for Zoom on Mac

Avatar Drew McFarlane
Thank you Tony, have you the latest Version Number (Update) please.

Re: Important Security Update for Zoom on Mac

Avatar Mick Burrell
5.11.5

Re: Important Security Update for Zoom on Mac

Avatar Drew McFarlane
Thank you Mick, I am updated.

Re: Important Security Update for Zoom on Mac

Avatar Andrew Kemp
The latest version is now 5.11.6, because the fix in 5.11.5 could be bypassed.

Re: Important Security Update for Zoom on Mac

Avatar Barrie Turner
Thanks for the Zoom update notice ver.5.11.5 (9788)

Barrie

Re: Important Security Update for Zoom on Mac

Avatar Tony Still
Thanks Andrew for noting that "The latest version is now 5.11.6".

The ...6 is important because the ...5 version's fix was broken.

Re: Important Security Update for Zoom on Mac

Avatar Richard I
I have just done the update and the latest version is now 5.11.9. So much for a right first time approach!!

Re: Important Security Update for Zoom on Mac

Avatar Lionel Ogden
Just did the 5.11.9 update. Perhaps if I check again in ten minutes there will be another update.
 
Feed