‘Zero Click’ Zoom Vulnerability Could Expose Calls

[ad_1]

Most hackers need The victim clicks the wrong link or opens the wrong attachment.But as the so-called Zero Click Vulnerability– the goal does nothing – yes increasingly exploited, Natalie Silvanovich of Google’s Zero Vulnerability Hunt team has been working hard to find new examples and fix them before attackers can use them.her list now includes zoom, and until recently lurked two shocking, non-interactive flaws.

Although now fixed, the two vulnerabilities could be exploited without any user involvement to take over a victim’s device and even compromise the Zoom servers that handle many user communications in addition to the original victim. Zoom users can choose to turn on end-to-end encryption for their calls on the platform, which will prevent attackers with access to the server from monitoring their communications. But hackers can still use the access to intercept calls that users don’t have that protection enabled.

“This project took me a few months, and I didn’t even fully complete the attack, so I think it’s only available to well-funded attackers,” Silvanovich said. “But I wouldn’t be surprised if that’s what the attackers were trying to do.”

Silvanovich found zero-click vulnerabilities and other flaws in multiple communication platforms, including facebook messenger, Signal, Apple’s FaceTime, Google Duo, and Apple’s iMessage. She said she never considered evaluating Zoom because the company has added so many pop-up notifications and other protections over the years to ensure users don’t inadvertently join calls.But she said she was inspired to work on the platform with the help of two researchers Demonstrates zooming with zero clicks Vulnerabilities in the April 2021 Pwn2Own hackathon.

Silvanovich, who initially disclosed her findings to Zoom in early October, said the company was very responsive to her work and supported her. Zoom fixed the server-side vulnerability and released an update for user devices on December 1. The company has issued a security bulletin and told WIRED that users should download the latest version of Zoom.

Most mainstream videoconferencing services are based at least in part on open-source standards, which makes them easier for security researchers to review, Silvanovich said. But Apple’s FaceTime and Zoom are both completely proprietary, making it harder to examine their inner workings and potentially find flaws.

“The barriers to doing this research on Zoom are very high,” she said. “But I find serious bugs, and sometimes I wonder if part of the reason I find them and others don’t is a huge barrier to entry.”

You might join a Zoom call by receiving a meeting link and clicking it. But Silvanovich noticed that Zoom actually provides a broader platform where people can mutually agree to be “Zoom contacts” and then message or call each other over Zoom, just like calling or texting someone the same phone number. The two vulnerabilities discovered by Silvanovich can only be used in a no-interaction attack if the Zoom contacts of the two accounts have each other. This means that the primary targets of these attacks are active Zoom users, either individually or through their organizations, and are accustomed to interacting with Zoom contacts.

[ad_2]

Source link