As elaborated, the Zoom video conferencing software for Mac can allow an attacker to control the webcam of a user via a malicious invite URL. A potential attacker can send the URL to any Mac user via any means. When the recipient opens the URL in the browser, the Zoom client opens up on the device.
This way, the attacker can exploit the vulnerability by forcibly joining a Zoom call. As stated by the researcher,
This vulnerability allows any website to forcibly join a user to a Zoom call, with their video camera activated, without the user's permission.Even if the user has uninstalled the Zoom app, the attack can still happen due to the presence of a local web server that continues to run even after uninstalling the app. This web server reinstalls the Zoom client when triggered without user interaction or permission.
Thus, an attacker can exploit this feature for any malicious activity.
This could be embedded in malicious ads, or it could be used as a part of a phishing campaign.Moreover, an attacker can also exploit this flaw to create a denial-of-service state on the target system.
This new signature or token is embedded in a new parameter called confid.
Yet, it still remains possible to bypass this ‘fix’. Thus, the simple solution to avoid this vulnerability, as recommended by the researcher, is to disable the video feature entirely when joining a call.
Let us know your thoughts in the comments.