Zoom flaw allows hackers to take over your Mac — update right now

Zoom call on MacBook
(Image credit: Shutterstock)

A PSA for Mac owners who use Zoom for their meetings and family video calls: update your software right away. The company has acted quickly to patch a serious security weakness that could allow a hacker to take control of macOS, letting them edit, add or even delete files at will.

The exploit is blocked in version 5.11.5 of the Zoom app for macOS, and affected users should make the update immediately. The vulnerability got a CVSS score of 8.8 on the company’s security bulletin, denoting it of “high” severity.

It marks a quick turnaround for Zoom’s developers, as the bug was only exposed at the DEF CON hacking conference on Friday (August 12). The security researcher who found the weakness, Patrick Wardle, was certainly impressed, tweeting: “Mahalos to @Zoom for the (incredibly) quick fix!”

The Verge, which attended the event last week, has more details on the now-defanged vulnerability, which targeted the installer of the Zoom application. Wardle found that while the installer required a Mac owner to enter a password for installations, the auto-update function ran in the background with superuser privileges.

The updater would check that updates officially distributed by the developers had been cryptographically signed. But Wardle discovered that feeding the updater any file with the same credentials would fool it, allowing malicious types to substitute malware of their choosing to run on a Mac with Zoom open.

That loophole is now, thankfully, closed. Wardle followed up on his congratulatory tweet by explaining exactly how Zoom had made the fix

“Reversing the patch, we see the Zoom installer now invokes lchown to update the permissions of the update .pkg, thus preventing malicious subversions,” he explained — accompanied with a padlock and thumbs up emoji, suggesting this gets the Wardle seal of approval.

To update Zoom on your Mac, load it up and then click zoom.us (or whatever your geographical equivalent is) from the menu bar at the top of the screen. Select “Check for updates” and Zoom should pop open a window giving you the details of what’s included. Click “Update” and your download will begin.

Once you're all updated, don't forget to check out our guides to the best free Zoom backgrounds, how to get Snapchat filters on Zoom and our overall page on how to use Zoom.

TOPICS
Alan Martin

Freelance contributor Alan has been writing about tech for over a decade, covering phones, drones and everything in between. Previously Deputy Editor of tech site Alphr, his words are found all over the web and in the occasional magazine too. When not weighing up the pros and cons of the latest smartwatch, you'll probably find him tackling his ever-growing games backlog. Or, more likely, playing Spelunky for the millionth time.

Read more
iPhone 16 Pro shown held in hand
Apple just patched its first zero-day flaw of the year — update your iPhone and Mac right now
Apple iPhone 16 Plus Review.
Apple just released an emergency security update for a flaw used in an ‘extremely sophisticated attack’ — update your devices right now
MacBook Pro 16-inch 2021 sitting on a patio table
Critical macOS flaw puts your data and cameras at risk — update right now
Apple iPhone 16 held in the hand.
iOS 18.3.1 — update your iPhone right now to fix critical zero-day vulnerability
Windows
240 million Windows 10 users are vulnerable to six different hacker exploits — protect yourself now
Google Pixel 9 held in the hand.
Google just fixed a zero-day kernel flaw used by hackers and 47 other vulnerabilities — update your Android phone right now
Latest in Video Conferencing
A composite image showing Skype and Microsoft Teams side by side
I used Skype for years, and Teams is a poor replacement for the video calling service that started it all
Google Meet
Google Meet is getting a very handy automatic picture-in-picture mode — what you need to know
Project Starline 3D video conferencing
I just tried Google’s 3D video conferencing tool launching next year — here’s what Project Starline is like
Microsoft Teams
New Microsoft Teams is live — here's the 3 biggest upgrades
Google Meet update
It's official — Google Meet is getting one of Zoom’s best features
Zoom call on MacBook
Zoom flaw allows hackers to take over your Mac — update right now
Latest in News
Apple Peek Performance
Apple makes a move to revive its Siri revamp — and the Vision Pro boss could play a part
NYTimes Connections
NYT Connections today hints and answers — Friday, March 21 (#649)
Xbox Elite Wireless Controller Series 2
Deleted image reveals Steam games in the Xbox app — here's what it could mean
Severance season 2 finale
How to watch 'Severance' finale online – stream final episode of season 2 tonight
Render of the alleged design of the iPhone 17 Pro
New iPhone 17 Pro dummy leak highlights redesigned camera and part glass body
Nintendo Switch 2
Nintendo Switch 2 just tipped for three display upgrades — here's what we know