Connect with us

Hi, what are you looking for?

Tech

Zoom’s latest update on Mac includes a fix for a dangerous security flaw

available ad 970x250

Zoom has issued a patch for a bug on macOS that could allow a hacker to take control of a user’s operating system (via MacRumors). In an update on its security bulletin, Zoom acknowledges the issue (CVE-2022-28756) and says a fix is included in version 5.11.5 of the app on Mac, which you can (and should) download now.

Patrick Wardle, a security researcher and founder of the Objective-See Foundation, a nonprofit that creates open-source macOS security tools, first uncovered the flaw and presented it at the Def Con hacking conference last week. My colleague, Corin Faife, attended the event and reported on Wardle’s findings.

As Corin explains, the exploit targets the Zoom installer, which requires special user permissions to run. By leveraging this tool, Wardle found that hackers could essentially “trick” Zoom into installing a malicious program by putting Zoom’s cryptographic signature on the package. From here, attackers can then gain further access to a user’s system, letting them modify, delete, or add files on the device.

“Mahalos to Zoom for the (incredibly) quick fix!” Wardle said in response to Zoom’s update. “Reversing the patch, we see the Zoom installer now invokes lchown to update the permissions of the update .pkg, thus preventing malicious subversion.”

You can install the 5.11.5 update on Zoom by first opening the app on your Mac and hitting zoom.us (this might be different depending on what country you’re in) from the menu bar at the top of your screen. Then, select Check for updates, and if one’s available, Zoom will display a window with the latest app version, along with details about what’s changing. From here, select Update to begin the download.

available ad 970x250

Source link

Click to comment

You must be logged in to post a comment Login

Leave a Reply

Trending

Save Up To 62%

You May Also Like

Tech

Public fintechs lost 72% in market value last year While the public market correction has been widespread, tech and fintech stocks have seen the...

Tech

Welcome back to Chain Reaction, a podcast diving deep into the stories, backgrounds and latest news with the biggest names in crypto. For this...

Business

Nearly two-dozen YC-backed Indian startups have over $1 million stuck in accounts with Silicon Valley Bank and over four dozen more have over $250,000...

Health

10 March 2023 Highly pathogenic avian influenza (HPAI) H5N1 was confirmed in commercial poultry on 10 March 2023 at a premises near Southwaite, Eden,...