The macOS installer for Zoom installer could let hackers hijack your device


Zoom has patched a serious security flaw that could have allowed hackers to take over a macOS device running the video conferencing software.
The move came after Mac security specialist Patrick Wardle demonstrated how a threat actor could abuse the way macOS handles software patches to trigger an escalation of privilege and essentially take over the device.
Initially, he said the vulnerability leveraged multiple flaws, and that the company addressed most of them. One remained, however, and that one was patched on a later date to finally fully mitigate the issue.
Tricking the updater
The problem lies in the way macOS handles updates. When a user first tries to install an app or a program on the endpoint, they need to run with special user permissions, often given by submitting a password. After that, auto-updates run indefinitely, with superuser privileges.
In Zoom’s case, the updater would first check to see if the company cryptographically signed the new package, and if so, proceed with the update. However, should the updater get any file with the same name as Zoom’s signing certificate, it would run it. In other words, an attacker could slip in any malware through the updater, even if it meant giving a third party full access to the device.
The flaw was later identified as CVE-2022-28756, and was fixed in Zoom version 5.11.5 for macOS, which is available now to download.
Even though at first Wardle described the flaw as relatively easy to fix, even he was surprised at the speed at which Zoom addressed the issue: “Mahalos to Zoom for the (incredibly) quick fix!” Wardle tweeted afterwards. “Reversing the patch, we see the Zoom installer now invokes lchown to update the permissions of the update .pkg, thus preventing malicious subversion.”
Via: The Verge (opens in new tab)
Audio player loading… Zoom has patched a serious security flaw that could have allowed hackers to take over a macOS device running the video conferencing software. The move came after Mac security specialist Patrick Wardle demonstrated how a threat actor could abuse the way macOS handles software patches to trigger…
Recent Posts
- Samsung Galaxy Unpacked 2025: Get ready for the Galaxy Z Fold 7 and Galaxy Z Flip 7
- Rock on! Marshall’s great Bluetooth speakers and headphones have hit super-low prices in Amazon’s early Prime Day deals
- Yes, there are AirPods Pro 2 deals in the 4th of July sales – but you shouldn’t buy them, here’s why
- Hunting for early Prime Day deals? Beware, scammers have set up thousands of fake Amazon sites – here’s what to look out for
- Android 16’s answer to iOS Live Activities is coming soon – here are the apps it’ll support, including Google Maps
Archives
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022