Zoom for Mac users should update now to fix a massive security flaw

Zoom
(Image credit: Shutterstock)

Some existing versions of Zoom for Mac could be exposing parts of your computer’s controls to malicious attackers, and you may not even be aware, the company has warned.

The issue - which has been identified as CVE-2022-28762 - is thought to be present in macOS Zoom client versions 5.10.6 to 5.12.0 (excluded).

To check which version of the video conferencing platform you have, open the Zoom desktop client on a Mac and head to ‘zoom.us’ in the taskbar. From here, check your build number in ‘About Zoom’ and follow ‘Check for updates…’ if necessary.

Zoom bugs and updates

“When camera mode rendering context is enabled as part of the Zoom App Layers API by running certain Zoom Apps, a local debugging port is opened by the Zoom client," the company's advisory reads.

This means that a local malicious user is able to use the exposed debugging port to connect - and control - the macOS Zoom client.

The issue has been given a CVSS score of 7.3, rendering it of high severity. Zoom recommends that all users remain on the most up-to-date version of its software in order to protect themselves against such vulnerabilities. 

This isn’t the first time that Zoom has reported bugs in its macOS desktop client - and indeed its entire software package - which are all logged on the company’s Security Bulletin.

Despite some pretty serious mishaps in years gone by, Zoom remains an incredibly popular video conferencing platform and VoIP provider for many businesses and educational establishments, to the degree that it may be more popular than Microsoft Teams according to figures we saw, earlier this year.

TOPICS
Craig Hale

With several years’ experience freelancing in tech and automotive circles, Craig’s specific interests lie in technology that is designed to better our lives, including AI and ML, productivity aids, and smart fitness. He is also passionate about cars and the decarbonisation of personal transportation. As an avid bargain-hunter, you can be sure that any deal Craig finds is top value!

Read more
A person at a laptop with a cybersecure lock symbol floating above it.
Parallels Desktop has some worrying security flaws for Mac users
Apple Siri
Update your Apple device now: iOS 18.3.2 fixes a flaw that could be exploited by hackers
Apple's new "Share Item Location" feature for AirTags.
Apple security alert - zero-day patched, so update your devices now
Webex by Cisco banner on a Chromebook
Cisco warns some Webex users of worrying security flaw, so patch now
the YouTube logo on a screen in front of other YouTube logos covering a black background
Worrying YouTube security flaw exposed billions of user emails
Image of laptop infected with malware threat
This devious new macOS malware disguises itself as Chrome, Zoom installers
Latest in Software & Services
woman listening to computer
AWS vs Azure: choosing the right platform to maximize your company's investment
Autonomous finance
Quickbooks vs Quicken: what are the main strengths and weaknesses for your business
Group of people meeting
Zoom vs Google Meet: which is the best video conferencing tool for your business?
Person at laptop
Windows 11 vs Windows 365: which is the best choice for businesses?
A man sitting at his desk in the evening and using a desktop computer
Office 2021 vs Office 2024: is it time to upgrade?
Microsoft 365 Business app logos
Office 2024 LTSC vs Microsoft 365 Business: what are the differences?
Latest in News
Super Mario Odyssey
ChatGPT is the ultimate gaming tool - here's 4 ways you can use AI to help with your next playthrough
Brad Pitt looks over his right shoulder with 'F1' written behind him
Apple Original Films will take you behind-the-scenes of a racing cockpit in this new thrilling F1 movie trailer
AI writer
Coding AI tells developer to write it himself
Reacher looking down at another character from the Prime Video TV series Reacher
Reacher season 3 becomes Prime Video’s biggest returning show thanks to Hollywood’s biggest heavyweight
Finger Presses Orange Button Domain Name Registration on Black Keyboard Background. Closeup View
I visited the world’s first registered .com domain – and you won’t believe what it’s offering today
Image showing detail of the Leica D-Lux 8
Still can't get a Fujifilm X100VI? This premium Leica compact costs less, and it's in stock