Vulnerabilities

Zoom patches high-severity flaw in macOS client

0

Video messaging platform Zoom fixed a high-severity vulnerability in its client for macOS devices. The vulnerability that has been tracked CVE-2022-28762 refers to a debugging port misconfiguration affecting versions between 5.10.6 and 5.12.0 (excluded).

It received a common vulnerability scoring system (CVSS) of 7.3 out of 10.

When the camera mode rendering context is enabled as part of the Zoom App Layers API by running certain Zoom Apps, a local debugging port is opened by the Zoom client.

According to the company, the flaw if exploited, could allow a malicious actor to connect to their client and control the Zoom Apps running in it.

From a technical standpoint, Zoom Apps are integrations with external apps that users can access from within the video messaging platform. They include tools such as Miro, Dropbox Spaces and Asana, among others.

The vulnerability was discovered by the Zoom’s own security team as part of a routine assessment. It was fully patched in the latest version of the macOS client (5.12.0), which is now available on the company’s website and through settings in already installed iterations of the video messaging platform.

The messaging firm stated that the users can keep themselves secure by applying current updates or downloading the latest Zoom software with all current security updates.

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

Online wine retailer Vinomofo suffers data breach

Previous article

Medibank suffers breach impacting 3.9 million customers

Next article

You may also like

Comments

Leave a reply

Your email address will not be published. Required fields are marked *