14 C
London
Wednesday, December 18, 2024
HomeNewsTechnologyZoom installer flaw can give attackers root access to Mac: Report

Zoom installer flaw can give attackers root access to Mac: Report

Related stories

J&K police release list of seized assets used for terrorism

Jammu, Feb 16 : The police in Jammu and...

Israel says 4 mln citizens vaccinated against Covid-19

Jerusalem, Feb 17 : Israeli officials announced that some...

Hungary to receive first shipment of Chinese vaccines

Beijing, Feb 17 : A Hungarian cargo plane loaded...

San Francisco: A security researcher has found a way that an attacker could leverage the macOS version of Zoom to gain access over the entire operating system.
According to The Verge, details of the exploit were released in a presentation by Mac security specialist Patrick Wardle at the Def Con hacking conference in Las Vegas this week.
Zoom has already fixed some of the bugs involved, but the researcher also presented one unpatched vulnerability that still affects systems now.
The exploit works by targeting the installer for the Zoom application, which needs to run with special user permissions to install or remove the main Zoom application from a computer.
Though the installer requires a user to enter their password on first adding the application to the system, Wardle found that an auto-update function then continually ran in the background with superuser privileges.
Also Read Samsung Galaxy Watch5 Series to start at Rs 27,999 When Zoom issued an update, the updater function would install the new package after checking that it had been cryptographically signed by Zoom.

Subscribe

- Never miss a story with notifications

- Gain full access to our premium content

- Browse free from up to 5 devices at once

Latest stories