Zoom Latest Update to Mac Fixes Dangerous Security Flaws : Update Zoom for Mac now

Security researcher Patrick Wardle presented several security flaws in the video conferencing software Zoom at the hacker conference Def Con.  There is still no patch for a zero day under MacOS. It can extend rights and thus execute malware as an administrator. Zoom has already fixed several other bugs.Online magazine The Verge had reported.


The vulnerability was first discovered by Patrick Wardle , founder of the Objective-See Foundation , a non-profit Mac OS security organization. Wardle detailed in a presentation at Def Con last week how Zoom's installer asks for a user password when installing or uninstalling, but the automatic update feature, which is enabled by default, does not require a password. Wardle discovered that Zoom's updater was owned and run by root.





Enlarge / Highlights on how Zoom's auto-update utility allows privilege escalation exploits, from Patrick Wardle's Def Con talk.

This appears to be safe as only Zoom clients can connect to the privileged daemon and can only extract packages signed by Zoom. Zoom Video ... Certification Authority Apple Root CA.pkgThe problem is that this check can be bypassed by simply passing the validation checker on the name of the package it is looking for (" "). This means malicious actors can force Zoom to downgrade to a buggy, less secure version, or even pass an entirely different package that could allow them to gain root access to the system.

According to the report, the security problem lies in Zoom's update function, which, for example, installs updates or removes the software. Although this checks whether a downloaded package has been cryptographically signed, an error in the checking method means that the updater can be given any certificate with the same name as Zoom's signing certificate.

 

This would allow attackers to bypass the verification of the software to be installed and execute malware, for example. The malware is executed by the Zoom updater with administrator rights. However, the vulnerability can only be exploited if attackers already have access to the affected person's system, but then they can extend their rights and have far-reaching access to the affected system.

 

Wardle reported the vulnerability back in December 2021, and a first fix introduced another bug that allowed the vulnerability to continue to be exploited, but in a more complicated way, Wardle explained to The Verge. After eight months, he said, he has now decided to make the vulnerability public, even though it remains unfixed.

 

"For me, it was kind of problematic because I wasn't just reporting the bugs to Zoom, I was reporting the bugs and how to fix the code," Wardle said. "So it was really frustrating to wait six, seven, eight months and know that all the Mac versions of Zoom were sitting on users' computers and were vulnerable." With the release, Wardle hopes that the bug, which he said was very easy to fix, will now finally be fixed.

 

Shortly before the conference, Zoom had released an update to fix the flaw. According to The Verge, the update file is now moved to a folder that belongs to the user root. Since the user's read and write permissions are also copied when the file is copied, the user can continue to modify the file - and attackers can continue to exchange the file and expand their permissions.

 

Matt Nagel, Zoom's PR officer for security and privacy, said in a statement to The Verge: "We are aware of the newly reported vulnerability in Zoom Auto-Updater for macOS and are working diligently to fix it."

 

Words from the Heart

Discover the most beautiful love letters ever written

Explore Letters

How It Works

Discover, read, and create beautiful love letters with our simple process

1

Explore Letters

Browse our curated collection of historical and contemporary love letters from famous figures and everyday romantics.

2

Get Inspired

Find inspiration from our writing guides, romantic quotes, and letter templates to craft your perfect message.

3

Create Your Own

Use our tools to write, design, and send your own heartfelt letter to someone special in your life.

Our Story

Love Letters was founded in 2010 with a simple mission: to preserve and celebrate the art of handwritten love letters in our digital age. What began as a personal collection of historical letters has grown into a thriving community of romantics, writers, and love letter enthusiasts.

We believe that in a world of instant messages and fleeting digital communication, the handwritten love letter remains one of the most powerful ways to express deep emotion and create lasting memories.

Learn More
About Love Letters

What People Say

Hear from our community of letter writers and readers

"The letters on this site inspired me to write to my wife for our anniversary. She said it was the most romantic gift I've ever given her."
Michael R.
Michael R.

Married 15 years

"As a history teacher, I use these letters to show my students how people expressed love through different time periods. Fascinating!"
Sarah L.
Sarah L.

High School Teacher

"I was nervous about writing my first love letter, but the templates and examples made it so easy. My partner was moved to tears!"
David T.
David T.

First-time Letter Writer

1,000+

Letters in Our Collection

50+

Historical Periods Represented

10,000+

Letters Sent Through Our Service

100+

Countries Reached

Ready to Express Your Love?

Join thousands of others who have discovered the joy of writing heartfelt letters to their loved ones.

Stay Inspired

Subscribe to receive weekly love letters, writing tips, and romantic inspiration

My Dearest Love

My dearest,

As I sit here with pen in hand, I find myself at a loss for words to describe the depth of my feelings for you. How does one capture the essence of a love so profound, so all-encompassing, that it colors every moment of every day?

From the moment I wake until the moment I close my eyes at night, thoughts of you fill my mind and heart. Your laughter is the melody that plays in my soul, your smile the light that brightens my darkest days.

I remember the first time our eyes met across that crowded room - it was as if time stood still. In that instant, I knew my life would never be the same. You've brought me more joy than I ever thought possible, more love than I believed existed.

Every day with you is a gift I cherish. Even when we're apart, I carry you with me in my heart. Your strength inspires me, your kindness humbles me, your love completes me.

Forever yours,

Sealed
with
Love