Article 62F0Q The Zoom installer let a researcher hack his way to root access on macOS

The Zoom installer let a researcher hack his way to root access on macOS

by
Corin Faife
from The Verge - All Posts on (#62F0Q)
acastro_200331_1777_zoom_0001.0.0.jpg Illustration by Alex Castro / The Verge

Update August 15th, 10:55AM ET: Zoom has updated its Mac app to address the vulnerability, with version 5.11.5, which is available for download now.

A security researcher has found a way that an attacker could leverage the macOS version of Zoom to gain access over the entire operating system.

Details of the exploit were released in a presentation given by Mac security specialist Patrick Wardle at the Def Con hacking conference in Las Vegas on Friday. Some of the bugs involved have already been fixed by Zoom, but the researcher also presented one unpatched vulnerability that still affects systems now.

The exploit works by targeting the installer for the Zoom application, which needs to run with special user permissions in order to install...

Continue reading...

External Content
Source RSS or Atom Feed
Feed Location http://www.theverge.com/rss/index.xml
Feed Title The Verge - All Posts
Feed Link https://www.theverge.com/
Reply 0 comments