Zoom Promises Fix for Scary Webcam Spying Flaw

(Image credit: Future / Laptop Mag)

Any Mac with the Zoom teleconferencing app can be spied on right now. Yep, it's a bad day for Apple security, as malicious websites can be coded to remotely start a video conference call on your Mac — and the attack can even be sent over email. 

The good news? Zoom promises that a fix is on the way. 

This news, disclosed by security researcher Jonathan Leitschuh, shows that even Macs that don't have Zoom installed anymore — but once did — are vulnerable. The good news, though, is that there are solutions (one is seriously difficult, though), and Zoom seems to be fixing it all soon.

What to do now:

The fix, thanks to Zoom changing its stance, appears to be as simple as accepting Zoom updates as they arrive. In an update to Zoom's big blog post about the flaw, the company stated a patch coming tonight (July 9) at or before 3 a.m. EST/midnight PST will solve things. Users will be prompted to update the app and that once the update is finished, "the local web server will be completely removed on that device."

The update will also supposedly improve the uninstall procedure. Zoom's post states "We’re adding a new option to the Zoom menu bar that will allow users to manually and completely uninstall the Zoom client, including the local web server."

We look forward to seeing if Jonathan Leitschuh and other security researchers think Zoom's doing a thorough and proper job.

Leitschuh shared this tip in his post revealing the flaw.

Leitschuh shared this tip in his post revealing the flaw. (Image credit: Jonathan Leitschuh)

To safeguard your Mac until that update, open Settings for Zoom — click Zoom in the menu bar, then click Settings — and open the Video section. Then check the box next to "Turn off my video when joining a meeting."

In his post, Leitschuh also shared code for use in the Terminal. Those instructions get a bit complicated and are best for the super-tech savvy users who would prefer it. Those tips are made to eradicate the web server that Zoom creates on the Mac.

How it works

Yes, this is all possible because Zoom secretly installs a web server on Macs, one that receives — and accepts — requests that your web browsers wouldn’t. Leitschuh explained that he tried to work with Zoom, reaching out to the company this past March, but that its "solutions were not enough to fully protect their users."

Also, as I mentioned earlier, even those users who have uninstalled Zoom from their Macs are vulnerable. Leitschuh explains that the web server installed by Zoom stays behind even after you remove the program, and that the server can be remotely triggered to update and automatically install the latest version of Zoom. 

Oh, and a victim doesn't even need to even be tricked into opening a web page.  First off, Vimeo user 'fun jon' posted video evidence that you can attack this flaw via email, and the target doesn't even need to open the message. They just need to be using an email client app that downloads the maliciously coded message.

After Leitschuh argued with Zoom, alleging telling the company that "allowing a host to choose whether or not a participant will automatically join with video" is a "standalone security vulnerability," the company disagreed, positioning its decision as pro-user: "Zoom believes in giving our customers the power to choose how they want to Zoom."

Zoom also released a blog post arguing its side of the story. It admits no fault or wrongdoing.

Want to see it for yourself?

If you've ever had Zoom on your machine, you can see this for yourself. Just search Leitschuh's blog post for the phrase "zoom_vulnerability_poc/" — as that's the link to his proof of concept, which launches a Zoom call. The first is an audio-only version; the second link, which includes 'iframe' in the URL, starts a call with video active.

Henry T. Casey
Managing Editor (Entertainment, Streaming)

Henry is a managing editor at Tom’s Guide covering streaming media, laptops and all things Apple, reviewing devices and services for the past seven years. Prior to joining Tom's Guide, he reviewed software and hardware for TechRadar Pro, and interviewed artists for Patek Philippe International Magazine. He's also covered the wild world of professional wrestling for Cageside Seats, interviewing athletes and other industry veterans.

Latest in Video Conferencing
A composite image showing Skype and Microsoft Teams side by side
I used Skype for years, and Teams is a poor replacement for the video calling service that started it all
Google Meet
Google Meet is getting a very handy automatic picture-in-picture mode — what you need to know
Project Starline 3D video conferencing
I just tried Google’s 3D video conferencing tool launching next year — here’s what Project Starline is like
Microsoft Teams
New Microsoft Teams is live — here's the 3 biggest upgrades
Google Meet update
It's official — Google Meet is getting one of Zoom’s best features
Zoom call on MacBook
Zoom flaw allows hackers to take over your Mac — update right now
Latest in News
Rendered images of rumored foldable iPhone.
Foldable iPhone report just revealed key details — here's what we know
NYTimes Connections
NYT Connections today hints and answers — Saturday, March 23 (#651)
NYT Strands on a cellphone
NYT Strands today — hints, spangram and answers for game #385 (Sunday, March 23 2025)
Nintendo Switch 2
Nintendo Switch 2 rumored specs — here’s what we know so far
iPhone 17 Pro render
iPhone 17 Pro — 7 biggest rumored upgrades
CAD renderings of the Google Pixel 10 Pro XL
Pixel 10 leak could be good news for all Android phones