Skip to main content
  1. Home
  2. Computing
  3. News

Apple rolls out a silent Mac update that removes Zoom’s local web server

Add as a preferred source on Google
sotck photo of Macbook Pro
Craig Adderley/Pexels

A security researcher recently discovered that the Zoom app has a pretty troubling security flaw for those who use the app on Macs. According to a Medium post published on Monday, July 8, by security researcher Jonathan Leitschuh, the Mac version of the Zoom app has a vulnerability that lets websites launch video calls (and turn on your webcam) without your permission.

But as of Wednesday, July 10, Apple decided to address Zoom’s security issue with a solution of its own: A silent Mac update that removes a problematic localhost web server that comes with the Mac version of the popular video conferencing app, TechCrunch reports.

Recommended Videos

Zoom is well-known and used by countless companies precisely because of its ease of use. (Users can join video calls with just a shared link and a click.) But it turns out that that particular easy-to-use feature is the source of the vulnerability. According to Leitschuh’s post, the installation of the Zoom client for Mac doesn’t just come with the video calling app itself; it also comes with a localhost web server that is also installed. This local server is what allows Mac users to have one-click access to a Zoom video call. But as Leitschuh notes, the local server feature “really hadn’t been implemented securely.”

In fact, the server is so vulnerable that it allows other, potentially malicious websites, access to Mac webcams to “forcibly join a user to a Zoom call” and turn on their webcams without permission. In addition, the server’s security flaw (for older versions of Zoom) also would have let websites complete a DoS (Denial of Service) attack on Macs “by repeatedly joining a user to an invalid call.” Leitschuh also noted that the DoS security flaw was patched in version 4.4.2 of the Zoom client.

Users can’t just uninstall Zoom to fix the problem either. Leitschuh’s report also mentioned that the local web server stays on your Mac even after uninstalling Zoom. Plus, that server can still reinstall Zoom without your permission. And it appears, at least according to Leitschuh’s version of events, that Zoom, while aware of the flaw, hadn’t fully fixed the security issue at the time.

Zoom initially said it wouldn’t fix the issue, but eventually said it would release a patch Tuesday that would eliminate the bug, according to Wired.

Despite Zoom’s newly released patch, Apple has now provided its own fix for Zoom’s webcam security issue. According to TechCrunch, the (automatic) silent Mac update is expected to remove the local server that had been installed along with Zoom’s video conferencing app. The silent update will also contain a feature that asks Mac users if they want to open the Zoom app, instead of just opening the app automatically.

Apple shed a little light on the reasoning behind the creation of this silent Mac update and telling TechCrunch that the update was intended to help protect past and present users of the Zoom app for Mac from the app’s vulnerability while preserving the functionality of the app.

Updated on July 11, 2019: Apple released a Mac update that removes Zoom’s local web server.

Anita George
Anita George has been writing for Digital Trends' Computing section since 2018. So for almost six years, Anita has written…
Withings brings AI-powered heart and lung checks to your home with BeamO
A free one month trial comes with new and existing devices.
Withings-beamO-StethO-Sense

Your heart doesn't always announce when something's off. A murmur can quietly persist for years without you ever noticing, and by the time it turns up at a checkup, you've missed plenty of chances to deal with it.

That's exactly why Withings just gave BeamO owners a new way to listen in. Announced at IFA 2026, the company's new AI feature called StethO Sense turns recorded heart and lung sounds into instant AI analysis.

Read more
Boya’s new AI notetaker gets the Neo treatment and a much lower price
The tiny recorder can pick up voices from five meters away and transcribe conversations in more than 140 languages
BOYA Notra Neo AI notetaker launched at IFA 2026

Boya has just launched a more affordable version of its Notra AI notetaker at IFA 2026. The latest from the brand is Note Neo. Obviously, the name takes inspiration from the latest trend of slapping a "Neo" moniker on devices that cost less and offer more. The MacBook Neo. Acer Swift Neo. Boya Notra Neo. See the pattern?

Regardless of the naming debate, the Boya Notra Neo retains the same design language as the pricier Boya Nitro. This one costs $79.99 and comes in four color options. The regular Boya Notra, for comparison, will set you back $125.99. Coming to the practical perks, Boya is touting the dual ual MEMS microphones and the in-house AI noise cancellation tech to deliver 360-degree voice pickup from a distance of up to five meters.

Read more
Lexar made a card-thin portable SSD for shooting 4K ProRes on your iPhone
Its designed to sit magnetically on the back of an iPhone while handling demanding 4K ProRes recording
Lexar Muse portable SSD launched at IFA 2026

Lexar just launched what it calls the world's thinnest SSD at IFA 2026. And at first sight, it looks like a massive evolution in the design of storage devices. The Lexar Muse looks almost like a card that attaches magnetically to the back of your phone and doesn't even have a USB-C port. Instead, it relies on a PogoPin-to-USB-C magnetic connection, just like the current wave of card-like AI note-takers such as the Plaud Note.

How does Lexar make an SSD this thin?

Read more