Got a tip for us? Share it...

Security Vulnerability Discovered in Skype for Mac, Latest Update Includes Patch


Earlier today, security researcher Gordon Maddern of Pure Hacking reported on a security vulnerability he accidentally discovered in Skype's software for Mac OS X, a vulnerability that he said he disclosed to the company a month ago and had yet to be patched.

I notified them on the security vulnerabilitity and I was given the standard:

"Thank you for showing an interest in skype security, we are aware of this issue and will be addressing it in the next hotfix"

That was over a month ago and there still has not been a fix released. The long and the short of it is that an attacker needs only to send a victim a message and they can gain remote control of the victims Mac. It is extremely wormable and dangerous.

Skype quickly responded on its security blog, noting that the company was already aware of the issue by the time Maddern reported it and had in fact issued a fix for it as part of a minor update to Skype for Mac released on April 14th. But because exploits for the vulnerability had not been reported in the wild, the company opted not to prompt existing users to apply the update.

Skype says that another update for the company's Mac software is set to launch early next week, and users will be prompted to update at that time. But in the meantime, Skype does recommend that users aware of the issue simply manually check for updates to get the current patched version.

This new update will include some additional updates and bug fixes. When it is released, we will notify all Skype for Mac users of the need to update their software (the client will prompt the user to update). In the meantime, we recommend you update your software with the fix made available on April 14th, just click on Skype -> Check for Updates or you can download the software here.

The vulnerability affects only the Mac OS X version of Skype, and thus clients for other platforms such as Windows and Linux will not require an update.

Top Rated Comments

(View all)

14 months ago

skype is disgusting!

I heard they record conversations with out users knowing, as well as locations and access other info, whats really disgusting is the fact that everyone is collecting information becuase they can use it against innocent people!


Put your tinfoil hat away, there's no proof or motive of this. Besides, Skype is Peer to Peer, which means recording a conversation is next to impossible, because it doesn't go through a central server. If Skype clients were uploading recordings, people would notice.
Rating: 3 Positives / 0 Negatives
14 months ago

It's on Page 2: Security Vulnerability Discovered in Skype for Mac, Latest Update Includes Patch


Yeah we know "where" it is. He's saying it should be front and center on Page 1.

But I guess security stories aren't as important as a new ambient light sensor.

-Kevin
Rating: 2 Positives / 0 Negatives
14 months ago
Don't use skype that much atm but i really hope they improve the interface soon :p
Rating: 2 Positives / 0 Negatives
14 months ago
so does anyone know if the vulnerability is in 2.8 or only in 5?

also -- apple has a role here: "control of victim's mac" shouldn't be possible without at least a password prompt


A possible workaround I suppose would be: allow chats from - only people in my contact list
Rating: 2 Positives / 0 Negatives
14 months ago
So I'm now forced to upgrade from 2.8.good.ui to 5.1.trash.ui ?
Rating: 2 Positives / 0 Negatives
14 months ago
Why would anyone ever install Skype 5 over 2.8? :eek:

I do wish they'd fix their stupid hideous software :(
Rating: 2 Positives / 0 Negatives
14 months ago

So I'm now forced to upgrade from 2.8.good.ui to 5.1.trash.ui ?


Only Skype 5 is vulnerable. Skype 2.8 is not affected:
http://www.pcworld.com/article/227382/skypes_dangerous_exploit_what_you_need_to_know.html

Another reason to stick to Skype 2.8:
http://mac.oldapps.com/skype.php?old_skype=37
Rating: 1 Positives / 0 Negatives
14 months ago



This should be Page 1.


Yeah seriously. But then again Page 1 is usually saved for those important Apple Market Share vs Android reports :D

-Kevin
Rating: 1 Positives / 0 Negatives
14 months ago
We couldn't get v5 to recognise our iSight camera which would seem to me an even bigger problem. Video calls without er... Video :(
Rating: 1 Positives / 0 Negatives
14 months ago
Absolutely unacceptable. Skype has no idea what the hell they are doing.

Really? ONE MESSAGE is all it would take to take control of OS X? And they decided not to fix it quickly because there were no reports of the exploit in the wild?

They are the stupidest, most useless developers. I hope they get bought out and either shut down or dramatically improved. And fire all of the current programmers/designers.

"What? People loosing their job? You're so cruel"

No. They can't do their jobs so why should they keep it? Allowing all of their OS X users to be wide open to a massive security hole like that... ugh. Not to mention the massive cluster of fail that is Skype 5.

Letting something that severe fester is the most lazy crooked thing ever. Besides the fact to even not notice it in the first place... and not be intelligent enough not to write the code in a way that would allow it.
Rating: 1 Positives / 0 Negatives

[ Read All Comments ]