/>
X
Business

Adobe fixes webcam hijack Flash flaw

Researcher documents a variation of the clickjacking technique that could be used to turn on a webcam and microphone direct from a web site without the user's knowledge or consent.
ryan-naraine.jpg
Written by Ryan Naraine on

Adobe has fixed a privacy invasion flaw in Flash that allowed remote spies to turn on a computer user's webcam via a rigged web site.

The vulnerability, discovered and documented by researcher Feross Aboukhadijeh, is a variation of the clickjacking technique and could be used to turn on a webcam and microphone direct from a web site without the user's knowledge or consent.

In this video, Aboukhadijeh documents the attack scenario:

Adobe says the issue is now fixed:

Adobe is aware of a report describing a clickjacking issue related to the online Flash Player Settings Manager. We have resolved the issue with a change to the Flash Player Settings Manager SWF file hosted on the Adobe website. No user action or Flash Player product update are required.

If, like me, you are paranoid about these kinds of bugs activating your webcam, do the smart thing and put a sticky over the camera.  Matter solved.

Editorial standards

Related

How to use your phone to diagnose your car's 'check engine' light
BlueDriver Bluetooth dongle

How to use your phone to diagnose your car's 'check engine' light

Elon Musk drops details about Tesla's humanoid robot
tesla-humanoid

Elon Musk drops details about Tesla's humanoid robot

For $2, you can finally give your Mac an incredibly useful feature Windows has always had
cleanshot-2022-08-16-at-22-34-232x

For $2, you can finally give your Mac an incredibly useful feature Windows has always had