Security

Apple has pushed a silent Mac update to remove hidden Zoom web server

Comment

zoom app
Image Credits: Getty Images

Apple has released a silent update for Mac users removing a vulnerable component in Zoom, the popular video conferencing app, which allowed websites to automatically add a user to a video call without their permission.

The Cupertino, Calif.-based tech giant told TechCrunch that the update — now released — removes the hidden web server, which Zoom quietly installed on users’ Macs when they installed the app.

Apple said the update does not require any user interaction and is deployed automatically.

The video conferencing giant took flack from users following a public vulnerability disclosure on Monday by Jonathan Leitschuh, in which he described how “any website [could] forcibly join a user to a Zoom call, with their video camera activated, without the user’s permission.” The undocumented web server remained installed even if a user uninstalled Zoom. Leitschuh said this allowed Zoom to reinstall the app without requiring any user interaction.

He also released a proof-of-concept page demonstrating the vulnerability.

Although Zoom released a fixed app version on Tuesday, Apple said its actions will protect users both past and present from the undocumented web server vulnerability without affecting or hindering the functionality of the Zoom app itself.

The update will now prompt users if they want to open the app, whereas before it would open automatically.

Apple often pushes silent signature updates to Macs to thwart known malware — similar to an anti-malware service — but it’s rare for Apple to take action publicly against a known or popular app. The company said it pushed the update to protect users from the risks posed by the exposed web server.

Zoom spokesperson Priscilla McCarthy told TechCrunch: “We’re happy to have worked with Apple on testing this update. We expect the web server issue to be resolved today. We appreciate our users’ patience as we continue to work through addressing their concerns.”

More than four million users across 750,000 companies around the world use Zoom for video conferencing.

The sinkhole that saved the internet

More TechCrunch

Peak XV, the largest India and Southeast Asia-focused venture firm, is reducing the size of a handful of its funds and lowering fees as it seeks to become “deeply aligned”…

Peak XV trims fund size and fees as Indian market overheats

Palmer Luckey raged against America’s adversaries, endorsed completely autonomous weapons, and hinted at an Anduril IPO. 

Palmer Luckey: Every country needs a ‘warrior class’ excited to enact ‘violence on others in pursuit of good aims’

Impulse Space has raised a massive new tranche of funding as big-name investors bet that moving satellites around in orbit will soon be a high demand service.  The startup, which…

Impulse bets shuttling satellites between orbits is big business, and raises $150M to scale up

Featured Article

A comprehensive list of 2024 tech layoffs

A complete list of all the known layoffs in tech, from Big Tech to startups, broken down by month throughout 2024.

A comprehensive list of 2024 tech layoffs

In San Francisco’s Mission district, good music is all around you. That’s why, high up on a street pole at an undisclosed location in the Mission, Riley Walz installed a…

A hidden microphone on a San Francisco street pole is spotting ‘bops’ in the wild

Instagram head Adam Mosseri announced on Tuesday that users who have connected their accounts to the fediverse, also known as the open social web, can now see who follows them…

Threads users can now see who follows them from other fediverse servers

Durk Kingma, one of the lesser-known co-founders of OpenAI, today announced that he’ll be joining Anthropic. In a series of posts on X, Kingma revealed that he’ll be working mostly…

Anthropic hires OpenAI co-founder Durk Kingma

Amsterdam-based Brineworks, a company specializing in seawater electrolysis technology, says its innovative method is expected to cost under $100 per ton of CO2 at scale.

Direct ocean capture may be the next frontier for carbon removal

It’s been a tumultuous week for OpenAI, full of executive departures and major fundraising developments, but the startup is back at it, trying to convince developers to build tools with…

OpenAI’s DevDay brings Realtime API and other treats for AI app developers

The new capability, rolling out Tuesday, will help advertisers who want to enhance their Pinterest Product Pins (ads) and attract more clicks, according to Pinterest.

Pinterest rolls out genAI tools for product imagery to advertisers

Monorepos are becoming an increasingly popular way to manage source code, but they require a slightly different toolset. Google developed its own internal build and test tool on top of…

Aspect Build gets $3.85M to help developers create software with Bazel

Sometimes, a demo is all you need to understand a product. And that’s the case with Runware. If you head over to Runware’s website, enter a prompt and hit enter…

Runware uses custom hardware and advanced orchestration for fast AI inference

Where most startups aim to recreate the superheated, super-pressurized conditions inside of a star, Acceleron takes a different approach.

Acceleron Fusion has raised $15M to take another stab at cold fusion, filing reveals

Microsoft was ahead of the game in the world of enterprise AR.

Microsoft HoloLens 2 discontinued with no successor in sight

Get ready for TechCrunch Disrupt 2024, our signature event for startups of all stages, taking place at Moscone West in San Francisco from October 28-30. This year, we’re expecting a…

The complete agenda for the Disrupt Stage at TechCrunch Disrupt 2024

Last year, Sound Ventures, the 9-year-old, Beverly Hills, California-based venture firm led by general partners Ashton Kutcher, Guy Oseary, and Effie Epstein, announced a new $265 million AI fund that…

Ashton Kutcher, Effie Epstein, and Guy Oseary are coming to TechCrunch Disrupt 2024

Numa, a startup developing AI-powered automation tech for car dealerships, has raised fresh capital in a Series B round.

Numa raises $32M to bring AI and automation to car dealerships

Featured Article

How the FBI and Mandiant caught a ‘serial hacker’ who tried to fake his own death

Jesse Kipf was a prolific hacker who sold access to systems he hacked, had contacts with a notorious cybercrime gang, and tried to use his hacking skills to get off the grid for good.

How the FBI and Mandiant caught a ‘serial hacker’ who tried to fake his own death

Ford is slashing both the monthly and annual cost of its hands-free driver-assistance feature, BlueCruise, for new and existing owners in response to “customer and dealer” feedback, the company tells…

Ford cuts price of BlueCruise hands-free driving feature

Drones and sidewalk delivery robots promise to make last-mile delivery cheaper and more efficient, but they both have their limitations. Drones have trouble touching down in dense urban areas, and…

Serve Robotics and Wing to trial robot-to-drone delivery in Dallas

People participating on the open social web have a problem: It’s not yet possible to reach users on multiple sites like Bluesky, Mastodon, and Threads with a single post. While…

Croissant debuts a cross-posting app for Threads, Bluesky, and Mastodon

Microsoft has given its Copilot assistant on Windows a makeover — and a voice. Copilot can now read your screen, speak aloud, and more.

Microsoft Copilot can now read your screen, think deeply, and speak aloud to you

Microsoft has broadly launched Bing Generative Search, its answer to Google’s AI Overviews and other AI-powered search apps.

Microsoft brings AI-powered overviews to Bing

Microsoft is paying publishers for content as part of a new Copilot feature, Copilot Daily, that gives a spoken summary of current events.

Microsoft starts paying publishers for content surfaced by Copilot

Evil Corp maintains a “privileged” relationship with the Kremlin, and was often tasked with launching cyberattacks on behalf of Russia. 

UK unmasks LockBit ransomware affiliate as high-ranking hacker in Russia state-backed cybercrime gang

E-commerce giant eBay, facing stiff competition from newer rivals, has removed final-value sales fees for all items excluding cars sold domestically in the U.K. This mirrors a similar move the…

eBay removes UK seller fees to counter new wave of marketplace startups

Google is announcing new Chromebook models today with Samsung and Lenovo. With Samsung’s Galaxy Chromebook Plus model in particular, the company is also introducing a new multifunctional quick insert key.…

Google adds a multi-functional quick insert key and new AI features to Chromebook Plus

Anduril sued defense tech startup Salient Motion. It still raised $12 million with participation from Anduril investor a16z.

Palmer Luckey tried to crush aeronautics startup Salient Motion. But Anduril backer a16z invested.

The company laid out a plan it hopes will go a long way toward reversing fortunes and repairing relationships.

Sonos outlines turnaround plan following app disaster

A team of founders who sold their last company to Amazon to build a new unit within AWS is setting out to reinvent the tricky business of backing up organizations’…

Eon emerges from stealth with $127M to bring a fresh approach to backing up cloud infrastructure