Protecting Against Zoom Exploit Hijacking Webcams on MacOS

A current flaw in the Zoom app for Mac allows a website to open the webcam without user permission. Until this gets fully resolved, the instructions below remain the best solution. Disabling of the web server component of the Zoom app, as well as a small piece of tape or paper obstructing your device’s webcam are also suitable. This post is to educate our users on how they can prevent a current Zoom exploit from taking over their webcam on their Mac. Instructions for an interim solution are as follows:

Enabling the turn off video when joining a meeting setting in the Zoom app for Mac

Login to the Zoom app and click the blue Gear in the upper, right-hand corner. Then, click on “Video” on the left, and then tick the box for “Turn off my video when joining a meeting”.

If you have any questions, don’t hesitate to reach out to your normal IT Staff.

References

https://medium.com/@jonathan.leitschuh/zoom-zero-day-4-million-webcams-maybe-an-rce-just-get-them-to-visit-your-website-ac75c83f4ef5

https://www.theverge.com/2019/7/8/20687014/zoom-security-flaw-video-conference-websites-hijack-mac-cameras

https://alerts.it.ufl.edu/4419