Skip to main content

Apple rolls out a silent Mac update that removes Zoom’s local web server

sotck photo of Macbook Pro
Craig Adderley/Pexels

A security researcher recently discovered that the Zoom app has a pretty troubling security flaw for those who use the app on Macs. According to a Medium post published on Monday, July 8, by security researcher Jonathan Leitschuh, the Mac version of the Zoom app has a vulnerability that lets websites launch video calls (and turn on your webcam) without your permission.

Recommended Videos

But as of Wednesday, July 10, Apple decided to address Zoom’s security issue with a solution of its own: A silent Mac update that removes a problematic localhost web server that comes with the Mac version of the popular video conferencing app, TechCrunch reports.

Zoom is well-known and used by countless companies precisely because of its ease of use. (Users can join video calls with just a shared link and a click.) But it turns out that that particular easy-to-use feature is the source of the vulnerability. According to Leitschuh’s post, the installation of the Zoom client for Mac doesn’t just come with the video calling app itself; it also comes with a localhost web server that is also installed. This local server is what allows Mac users to have one-click access to a Zoom video call. But as Leitschuh notes, the local server feature “really hadn’t been implemented securely.”

In fact, the server is so vulnerable that it allows other, potentially malicious websites, access to Mac webcams to “forcibly join a user to a Zoom call” and turn on their webcams without permission. In addition, the server’s security flaw (for older versions of Zoom) also would have let websites complete a DoS (Denial of Service) attack on Macs “by repeatedly joining a user to an invalid call.” Leitschuh also noted that the DoS security flaw was patched in version 4.4.2 of the Zoom client.

Users can’t just uninstall Zoom to fix the problem either. Leitschuh’s report also mentioned that the local web server stays on your Mac even after uninstalling Zoom. Plus, that server can still reinstall Zoom without your permission. And it appears, at least according to Leitschuh’s version of events, that Zoom, while aware of the flaw, hadn’t fully fixed the security issue at the time.

Zoom initially said it wouldn’t fix the issue, but eventually said it would release a patch Tuesday that would eliminate the bug, according to Wired.

Despite Zoom’s newly released patch, Apple has now provided its own fix for Zoom’s webcam security issue. According to TechCrunch, the (automatic) silent Mac update is expected to remove the local server that had been installed along with Zoom’s video conferencing app. The silent update will also contain a feature that asks Mac users if they want to open the Zoom app, instead of just opening the app automatically.

Apple shed a little light on the reasoning behind the creation of this silent Mac update and telling TechCrunch that the update was intended to help protect past and present users of the Zoom app for Mac from the app’s vulnerability while preserving the functionality of the app.

Updated on July 11, 2019: Apple released a Mac update that removes Zoom’s local web server.

Anita George
Former Digital Trends Contributor
Anita George has been writing for Digital Trends' Computing section since 2018. So for almost six years, Anita has written…
My Mac Pro hopes have been dashed, and Apple can’t save it this year
A person uses an Apple Mac Pro alongside three monitors and an editing console in a darkened room.

Last week, Apple revealed a new Mac Studio equipped with M4 Max and M3 Ultra chips. No, that’s not a typo -- the company really did launch a new Mac with chips from two different generations, where the less powerful chip is from the newer iteration. As I’ve written before, it’s a confusing, ridiculous situation, and one that must be driving Apple’s marketing division mad.

But at first, it seemed like there was a glimmer of reasoning behind the decision: Apple could save the rumored M4 Ultra chip for the Mac Pro and bring back some proper differentiation to the Mac lineup. Instead of having the Mac Studio and the Mac Pro offer the same maximum performance (as we have now), the Mac Pro would finally get a sizeable boost to tempt power-hungry pro users.

Read more
10 years ago today, Apple launched a revolutionary MacBook that failed spectacularly
An Apple 12-inch MacBook on a desk.

Ten years ago today, Apple unveiled the 12-inch MacBook to the world, claiming it had “reinvented the notebook” for the better. The laptop almost instantly divided opinion, with fans and detractors at each other’s throats from the start. And sure, it was by no means perfect, but look a little closer and I think you’ll find a device that has had a monumental impact on the world of computing -- not just on Apple, but on the industry as a whole.

The 12-inch MacBook is often seen as a flop and as a product emblematic of the excesses of Apple’s Jony Ive era, where the design guru’s penchant for thinness and lightness ruled all. The fact that this MacBook was discontinued after just four years is seen as proof of this idea.

Read more
Want Apple’s best Mac Studio? Prepare to pay over $14,000
The new Apple Mac Studio next to a monitor.

Apple just launched its new Mac Studio alongside the latest MacBook Air. The new Studio comes equipped with either an M4 Max or an M3 Ultra chip, and while it sounds mighty powerful and fully capable of rivaling some of the best Macs, it's also crazy expensive. If you want to configure it with all the bells and whistles Apple offers, you'll have to pay over $14,500 -- a huge increase over the previous generation.

The new Mac Studio is certainly nothing to turn your nose up at. The M4 Max configuration starts with a 14-core CPU, 32-core GPU, and a 16-core neural engine. You're also getting 36GB of unified memory and 512GB of SSD storage. This will set you back $1,999, which is the same as the last-gen Mac Studio that came equipped with the M2 Max and the M2 Ultra chips, so we're all good.

Read more