Security flaw had meant hackers could bypass protection and convince installer of app to load and run malware
It targets the Zoom installer, which the company uses to enable frictionless automatic updates. In order to make the user journey simpler, the installer continues to run in the background from the moment a user first installs zoom, and does so with “superuser” privileges, allowing it to change anything about the computer.
Normally, the company tries to ensure that is safe by limiting the installer to only operate on code that has been cryptographically signed by Zoom, but the bug discovered by Wardle means that an attacker could trivially bypass that protection and convince the installer to load and run any malware they want.
It is not the first time Zoom’s focus on frictionless use has led to a security hole. In April 2020, when pandemic remote working led to a 500% increase in daily traffic to the Zoom download page,The company’s desire to be the easiest way of joining video calls has led it to seek to bypass security measures that protect a user’s computer.
Australia Latest News, Australia Headlines
Similar News:You can also read news stories similar to this one that we have collected from other news sources.
Ezra Miller breaks silence to apologise ‘to everyone that I have alarmed’In their first statement since legal issues began, non-binary actor says they have begun treatment for ‘complex mental health issues’
Read more »
Ezra Miller issues apology, says they suffer 'complex mental health issues'Actor Ezra Miller issues a statement apologising for their behaviour and promising to do 'the necessary work' to recover.
Read more »
Zoom in: national science week prize puts photography under the microscope – in picturesLab-grown spinal cords and glowing fish larvae are among the images in an annual competition to find the best pictures taken under the microscope
Read more »
Bendigo to use mortgage discounts to retain fixed-rate customersBendigo and Adelaide Bank says one in five customers whose special, low fixed rates have expired over the past three months have departed to another bank.
Read more »
Apple tells staff to come into the office for at least three days a weekMemo from boss Tim Cook backs down from earlier attempt to get all employees in on same three fixed days
Read more »
Ryan Giggs told girlfriend’s sister ‘I’ll head-butt you next’, trial toldEmma Greville tells jurors she was trying to pull Giggs away from her sister when his elbow hit her in face
Read more »