Apple Pushes Another Automatic Mac Software Update to Address Further Zoom-Related Vulnerabilities

Apple today pushed a second silent security update to Macs to address further vulnerabilities related to the Zoom video conferencing app for macOS, reports The Verge.

Apple removed software that was installed by RingCentral and Zhumu, two video conferencing apps that relied on technology from Zoom and were also found to have the same vulnerabilities as Zoom earlier this week.

zoom logo
These two apps installed software able to respond to commands that could potentially allow websites to open up your webcam during a video conference without permission. Removing the apps did not remove the secondary software that was vulnerable to exploitation, which is also how Zoom worked.

Discovered last week, the Zoom vulnerability let a website forcibly initiate a video call on a Mac with the Zoom app installed, due to a web server that Zoom installed in the background.

When the vulnerability was first discovered, Zoom said that it used a local web server as a workaround to Safari changes that Apple introduced in Safari 12, calling it a "legitimate solution" to an otherwise "poor user experience" that allowed users to access "seamless, one-click-to-join meetings."

At issue was a new popup Apple implemented to require user approval when launching a third-party app, which Zoom wanted to avoid. Zoom did so through the aforementioned web server, which was designed to wait for calls to open up Zoom conferences automatically.

Zoom eventually released a patch to address the issue, and Apple also took the step of removing web server software that was not initially removed from the Mac when uninstalling the Zoom app. Zoom has since made it so uninstalling the Zoom app will remove the web server, and has made other changes.

Installing Zoom no longer installs a local web server on Mac devices, and there is a new setting to save the "Always turn off my video" preference that disables video in Zoom by default until it is manually enabled.

As with the original Zoom patch, the new patch for RingCentral and Zhumu is deployed automatically so that users are not required to apply it manually for it to take effect. Apple told The Verge that it plans to fix the vulnerability for all of Zoom's partner apps.

Tag: Zoom

Popular Stories

iOS 18

iOS 18.3 Available as Soon as Today With These New Features

Monday January 27, 2025 6:35 am PST by
Update: Apple has released iOS 18.3. In its press release unveiling a new Black Unity Sport Loop for the Apple Watch today, Apple confirmed that iOS 18.3 is "upcoming." According to Bloomberg's Mark Gurman, Apple Stores are being instructed to update the software on demo devices today, so iOS 18.3 should be released either today or within the next few days. Below, we recap everything new...
Generic iOS 18

iOS 18.4 Beta Coming Soon With These New Features for Your iPhone

Friday January 24, 2025 8:16 am PST by
iOS 18.3 is expected to be widely released next week, and that means the first iOS 18.4 beta for iPhones should be just around the corner. Apple has previously implied that iOS 18.4 will be released in April, as that is when it promised to make Apple Intelligence available in even more languages. Below, we outline what to expect from iOS 18.4 so far. Apple Intelligence for Siri Siri ...
iOS 18

5 New Things Your iPhone Can Do in iOS 18.3

Friday January 24, 2025 1:55 am PST by
Apple is set to release iOS 18.3 next week, bringing further refinements to Apple Intelligence features, a couple of neat new capabilities to iPhone 15 Pro and iPhone 16 devices, and bug fixes. While not quite as packed with new features as Apple's preceding iOS 18 point releases, iOS 18.3 still introduces capabilities that aim to make your iPhone smarter and more intuitive. Below, we've...
airpods 4 blue

Apple Finally Explains How to Install New Firmware on Your AirPods

Monday January 27, 2025 11:17 am PST by
Apple regularly releases new firmware for the AirPods, AirPods Pro, and AirPods Max, but the company has historically provided limited information on how to initiate an update. That changed today, and Apple updated its AirPods firmware support page with more specific instructions. Prior to today, here's what Apple said on the subject: Firmware updates are delivered automatically while your...
iOS 18

Apple Expected to Release iOS 18.3 This Week With These New Features

Thursday January 23, 2025 6:41 am PST by
iOS 18.3 should be released to the public this week, following beta testing since mid-December. While the software update is a relatively minor one, it still includes a handful of new features, changes, and bug fixes for iPhones. Below, we recap everything new in iOS 18.3. Notification Summary Changes Examples of inaccurate Apple Intelligence notification summaries Apple Intelligence...
airpods pro purple

Apple Still 'Exploring' New AirPods With Tiny Cameras

Sunday January 26, 2025 7:52 am PST by
Apple continues to explore the idea of releasing camera-equipped AirPods in the future, according to Bloomberg's Mark Gurman. Gurman only briefly mentioned the possibility of AirPods gaining tiny cameras, as part of his Power On newsletter intro this week, focused on Apple's future wearables ambitions. He did not explain what the cameras would be used for. The tiny cameras would not be...
apple tv 4k new orange

New Apple TV Launching This Year With These New Features

Wednesday January 22, 2025 6:01 pm PST by
A new Apple TV is expected to be released later this year. In this article, we recap rumored features and changes for the device. The next Apple TV will be equipped with Apple's own combined Wi-Fi and Bluetooth chip, according to Bloomberg's Mark Gurman. He said the chip supports Wi-Fi 6E, which would be an upgrade over the current Apple TV's standard Wi-Fi 6 support. Wi-Fi 6E extends the...
iPhone 17 Air Size Feature

iPhone 14 Pro vs. Rumored iPhone 17 Air: Upgrade or Downgrade?

Saturday January 25, 2025 6:40 am PST by
After hanging on to my iPhone 14 Pro for a few years, I will likely upgrade to an iPhone 17 model this year. Typically, I only consider the Pro models, but the rumored iPhone 17 Air sounds intriguing. After reflecting on rumors, I have realized that upgrading to this device might not have as many compromises as I first thought. Of course, the iPhone 17 Air is not yet official. Apple should...
iPhone 16 Apple Store Levels

Gurman: Apple Stores Receiving 'Merchandise' Updates Next Week

Saturday January 25, 2025 5:07 pm PST by
Apple's retail stores will be rolling out "merchandise/floor marketing updates" next week, according to Bloomberg's Mark Gurman. Gurman did not explicitly say if the store updates are related to any upcoming product announcements, but he did mention that next week is around the time that Apple rolls out its annual Black Unity watch band for the Apple Watch. In each of the past four years, ...

Top Rated Comments

BWhaler Avatar
72 months ago
NO

It was NOT discovered last week.

ZOOM was informed months ago, decided not to fix the patch because it would lower their value proposition and product strategy. Again, they chose to leave the security hole open for their business gain.

Two weeks ago was when the researcher got fed up and disclosed it to the public. Only then did Zoom jump into PR mode and fox the problem.

Apple, god bless them, learned of this and shut the exploit down. No point waiting for an unethical company. What else does Zoom know about they still haven’t disclosed?

MacRumors writers, do your job. Don’t let unethical companies spin or this behavior will never go away.
Score: 30 Votes (Like | Disagree)
arkmannj Avatar
72 months ago
Even if you discount the security issues... thanks companies for installing a 24x7 service consuming resources just to avoid a potential CLICK.

Good on Apple for pushing out the updates to help mitigate the stupidity of these companies.
Score: 14 Votes (Like | Disagree)
Westside guy Avatar
72 months ago
Any chance you’re willing to share your script? :) It’s a shame that you’d even need to make something like that, especially having to run regularly.
Here it is, warts and all (replace "{username1}, {username2}, etc. with actual user accounts of course).

* There should really be some error checking added to this, for example it shouldn't try to move the files if it's unable to create the "-unused" directories.
* Released under the "you break it, you get to keep both pieces" license


#!/bin/bash -f

#
# Cleans out all the cruft that Adobe, Microsoft, and Google try to hide
# in the Launch* directories. This script works from the command line, but
# it's mainly intended for use as a cron job.
#
# Needs to be run with sudo, or as root
#
#
# Changelog: Added Skype to the list 2018-12-03 TLS
#
# Initial script written 2018-08-15 TLS
#

if [ $USER != "root" ] ; then
echo "Error - needs to be run with root permissions (you are $USER). Please use sudo."
exit 1;
fi

DIRECTORY_LIST=(
"/Library/LaunchAgents"
"/Library/LaunchDaemons"
"/Users/{username1}/Library/LaunchAgents"
"/Users/{username2}/Library/LaunchAgents"
)
UNWANTED_LAUNCHERS_LIST=(
"com.adobe.*"
"com.citrix.*"
"com.google.*"
"com.lifescan.*"
"com.microsoft.*"
"com.skype.*"
)

for THIS_DIR in ${DIRECTORY_LIST* } ; do
if [ ! -d $THIS_DIR ] ; then
continue
fi
STORAGE_DIR="$THIS_DIR-unused"
if [ ! -d $STORAGE_DIR ] ; then
mkdir $STORAGE_DIR
fi
for THIS_GLOB in ${UNWANTED_LAUNCHERS_LIST* } ; do
find $THIS_DIR -maxdepth 1 -type f -iname $THIS_GLOB -exec mv \{\} $STORAGE_DIR \;
done
done
Score: 12 Votes (Like | Disagree)
Westside guy Avatar
72 months ago
Even if you discount the security issues... thanks companies for installing a 24x7 service consuming resources just to avoid a potential CLICK.
Yeah, this is a problem - even setting aside security concerns. All sorts of companies add superfluous scripts to our system's LaunchAgents and LaunchDaemons folders, usually for no good reason. Adobe, Citrix, Google, Microsoft, etc. Maybe each one doesn't normally chew up much memory, but the effect is cumulative... and sometimes those processes run away.

I actually have a "cleanup unwanted launchers" bash script running as a cron job on all my Macs. It runs each hour and moves the cruft any of these companies (and a couple others) placed into the various LaunchAgents and LaunchDaemons folders into LaunchAgents-unused and LaunchDaemons-unused, respectively.
Score: 8 Votes (Like | Disagree)
Kaibelf Avatar
72 months ago
Automatic silent OS updates huh? Sounds like some Google privacy invading stuff to me.
Howso? By making sure people can NOT access your camera and mic without your knowledge in a way that was designed to sidestep basic OS protections, now it's invading your privacy?
Score: 7 Votes (Like | Disagree)
iGeneo Avatar
72 months ago
Good!

I have ZERO issue with these silent updates
Score: 7 Votes (Like | Disagree)