国产三级大片在线观看-国产三级电影-国产三级电影经典在线看-国产三级电影久久久-国产三级电影免费-国产三级电影免费观看

Set as Homepage - Add to Favorites

【top phim khiêu dam c?a pháp】Zoom lets a website turn on your Mac's camera without permission

Source:Feature Flash Editor:focus Time:2025-07-02 04:15:28

Video conferencing app Zoom has a major security flaw in its Mac client,top phim khiêu dam c?a pháp letting any website turn on your Mac's camera without a warning, security researcher Jonathan Leitschuh claims.

In a blog post Monday, Leitschuh detailed the vulnerability, which he says he'd disclosed to Zoom more than 90 days ago, and the company still hasn't fixed it.

SEE ALSO: Google Nest camera security flaw allows former owners to observe others' homes

The problem lies in Zoom's usage of a web server on users' local machines. This makes some of Zoom's cool features possible, for example, clicking on a simple link in your web browser automatically starts up the app.

Having an app install and run a web server on a user's machine with an undocumented API "feels incredibly sketchy," Leitschuh says. But there's more. According to Leitschuh, "this web server can do far more than just launch a Zoom meeting. (...) this web server can also re-install the Zoom app if a user has uninstalled it."

This is bad by itself, but Leitschuh discovered a vulnerability that let him launch a Zoom call, with video enabled, on a user's machine without permission. The same vulnerability allows the attacker to perform a DOS (denial of service) type attack on a user's machine.

Mashable Light Speed Want more out-of-this world tech, space and science stories? Sign up for Mashable's weekly Light Speed newsletter. By clicking Sign Me Up, you confirm you are 16+ and agree to our Terms of Use and Privacy Policy. Thanks for signing up!

Leitschuh says that he'd contacted Zoom on March 26, offering the company a quick fix for the vulnerability. After a lot of back and forth, Zoom partially fixed the flaw, but Leitschuh was able to bypass their fix, after which the company offered no additional fix. The security issue is still present in the latest version of Zoom for Mac, 4.4.4.

In a blog post Monday, Zoom defended its app's functionality, claiming that users are prompted to turn their video off when joining their first meeting, and can set the video to off in subsequent meetings; if they do so, it would be impossible for the host or other participants to turn their camera on. Furthermore, Zoom claims, "because the Zoom client user interface runs in the foreground upon launch, it would be readily apparent to the user that they had unintentionally joined a meeting and they could change their video settings or leave immediately."

The company said they will give users more control of their video settings in an upcoming, July 2019 release.

The company also addresses the presence of the web server on user machines, saying it's a "workaround to a change introduced in Safari 12" and a "legitimate solution to a poor user experience problem."

Zoom has assessed that both the video call issue and the DOS issue were "low risk," which is why the company decided not to change the app's functionality. The company also promised it will launch a public vulnerability disclosure program in the "next several weeks."

The main question users should be asking themselves is whether they want to sacrifice their system's security for a bit of added functionality -- likely, functionality they can live without. Zoom's ability to re-install itself without user permission after it's been uninstalled is particularly worrisome. Since there's no official fix for the issue, you can remove Zoom's web server from your machine by following the steps described in Leitschuh's post.


Featured Video For You
Flipboard’s data breach exposes usernames, passwords

Topics Cybersecurity

0.2036s , 8093.0546875 kb

Copyright © 2025 Powered by 【top phim khiêu dam c?a pháp】Zoom lets a website turn on your Mac's camera without permission,Feature Flash  

Sitemap

Top 主站蜘蛛池模板: 久久久久人妻精品一区蜜桃 | 精品日韩国产欧美在线观看 | 丁香五月综合缴清中文 | 欧美精品18videose | 成人综合网站在线 | jizz全部免费播放在线观看日韩中字在线观看 | 国产精品成久久久久三级 | 无码av动漫精品一区二区免费 | 精品樱空桃一区二区三区 | 国产成人无码片视频在线播放 | 国产三级麻豆 | 亚洲av无码成人影片在线观看 | av区无码字幕中文 | 午夜福利理论片高清在线 | 97国产v欧美 | 中文字幕欧美日韩在线不卡 | 日韩欧美三级在线观看 | 久久精品中文字幕少妇 | 91精品视品在线播放 | 99精品偷自拍| 国产超短裙丝袜在线播放 | 欧美成精品色网在线观看 | 久久亚洲中文字幕精品有坂深 | 狠狠色伊人亚洲综合第8页 狠狠色伊人亚洲综合网站l | 国产人妻精品一区二区三区不卡 | 一区精品视频在线观看免费 | 国产精品伦一区二区在线 | 无码少妇精品一区二区免费动态 | v无码东京热亚洲男人的天堂 | 一区二区三区国产乱码在线播放 | 亚洲性夜色噜噜噜在线观看不卡 | 男人的天堂av2024在线 | 久久99热这里只有精品高清 | 性一交一乱一优A片 | 成人片在线视频 | 亚洲中文字幕在线观看 | 国产综合无码一区二区色蜜蜜 | 日本免费人成网站在线观看 | 亚洲成年人女熟片9页 | 李宗瑞完整版种子 | 亚洲日本在线观看视频 |