Categories: Tech

After the last fix was circumvented, Zoom updates a major vulnerability.

A MacOS security expert was able to go around the fix that was just released over the weekend.

 

Zoom Mac users need to upgrade once more.

This week, Zoom corrected a flaw in its Mac auto-update tool that might grant malicious users root access. On Wednesday, Zoom released a follow-up patch, indicating that the initial repair may have been circumvented.

Users of Zoom should install and utilise the August 17-released version 5.11.6 (9890) on macOS. For updates, you can also look at Zoom’s menu bar. If you wait for an automatic update while this issue is known to the public, you might have to wait days.

Csaba Fitzl, also known as theevilbit of Offensive Security, a macOS security researcher, disclosed Zoom’s insufficient remedy. The day before Fitzl tweeted about it, Zoom acknowledged Fitzl in its security bulletin (ZSB-22019) and released a patch.

 

 

Neither Fitzl nor Zoom explained how Fitzl was able to get around the patch for the flaw that Patrick Wardle, the creator of the Objective-See Foundation, first identified. Wardle discussed Zoom’s auto-update utility’s ability to maintain its privileged status to install Zoom packages yet be deceived into checking other packages at Def Con last week. As a result, bad actors might utilise it to degrade Zoom in order to improve their access to the system’s exploits or even to acquire root access.

Himanshu Mahawar

Himanshu Mahawar is the Editor and Founder at Flaunt Weekly.

Share
Published by
Himanshu Mahawar
Tags: ZoomZoom Mac

Recent Posts

Some Chromecasts are giving ‘Untrusted device’ errors today

Flaunt Weeekly Users say their 2nd-gen Chromecasts and Chromecast Audios are prompting ‘outdated’ firmware warnings.Users…

6 hours ago

Music labels will regret coming for the Internet Archive, sound historian says

Flaunt Weeekly But David Seubert, who manages sound collections at the University of California, Santa…

7 hours ago

Doechii Performing “Doo Wop (That Thing)” With Lauryn Hill Was A Surreal Full-Circle Moment For Hip Hop

Flaunt Weeekly Image Image Credit Lester Cohen / Contributor via Getty Images and Kristy Sparow…

7 hours ago

Ebony celebrates 40 years in music

Flaunt Weeekly Flaunt Weeekly 403 ERRORRequest blocked.We can't connect to the server for this app…

8 hours ago

Jeddah’s Ramadan Nights Illuminated with Cultural Festivities at Hayy Jameel

Flaunt Weeekly Ramadan Nights and Hayy JameelFollowing last year’s success, Ramadan Nights at Hayy Jameel…

8 hours ago

Wura Samba Out With ‘Ajo Rebirth

Flaunt Weeekly The Nigerian Afro Percussion band led by Percussionist, Singer and songwriter Abiodun Oke…

8 hours ago