230746 skype logo

Earlier today, security researcher Gordon Maddern of Pure Hacking reported on a security vulnerability he accidentally discovered in Skype's software for Mac OS X, a vulnerability that he said he disclosed to the company a month ago and had yet to be patched.

I notified them on the security vulnerabilitity and I was given the standard:

"Thank you for showing an interest in skype security, we are aware of this issue and will be addressing it in the next hotfix"

That was over a month ago and there still has not been a fix released. The long and the short of it is that an attacker needs only to send a victim a message and they can gain remote control of the victims Mac. It is extremely wormable and dangerous.

Skype quickly responded on its security blog, noting that the company was already aware of the issue by the time Maddern reported it and had in fact issued a fix for it as part of a minor update to Skype for Mac released on April 14th. But because exploits for the vulnerability had not been reported in the wild, the company opted not to prompt existing users to apply the update.

Skype says that another update for the company's Mac software is set to launch early next week, and users will be prompted to update at that time. But in the meantime, Skype does recommend that users aware of the issue simply manually check for updates to get the current patched version.

This new update will include some additional updates and bug fixes. When it is released, we will notify all Skype for Mac users of the need to update their software (the client will prompt the user to update). In the meantime, we recommend you update your software with the fix made available on April 14th, just click on Skype -> Check for Updates or you can download the software here.

The vulnerability affects only the Mac OS X version of Skype, and thus clients for other platforms such as Windows and Linux will not require an update.

Top Rated Comments

locust76 Avatar
132 months ago
skype is disgusting!

I heard they record conversations with out users knowing, as well as locations and access other info, whats really disgusting is the fact that everyone is collecting information becuase they can use it against innocent people!

Put your tinfoil hat away, there's no proof or motive of this. Besides, Skype is Peer to Peer, which means recording a conversation is next to impossible, because it doesn't go through a central server. If Skype clients were uploading recordings, people would notice.
Score: 3 Votes (Like | Disagree)
netnothing Avatar
132 months ago
It's on Page 2: Security Vulnerability Discovered in Skype for Mac, Latest Update Includes Patch (https://www.macrumors.com/2011/05/06/security-vulnerability-discovered-in-skype-for-mac-latest-update-includes-patch/)

Yeah we know "where" it is. He's saying it should be front and center on Page 1.

But I guess security stories aren't as important as a new ambient light sensor.

-Kevin
Score: 2 Votes (Like | Disagree)
ciTiger Avatar
132 months ago
Don't use skype that much atm but i really hope they improve the interface soon :p
Score: 2 Votes (Like | Disagree)
jdavtz Avatar
132 months ago
so does anyone know if the vulnerability is in 2.8 or only in 5?

also -- apple has a role here: "control of victim's mac" shouldn't be possible without at least a password prompt


A possible workaround I suppose would be: allow chats from - only people in my contact list
Score: 2 Votes (Like | Disagree)
techpr Avatar
132 months ago
So I'm now forced to upgrade from 2.8.good.ui to 5.1.trash.ui ?
Score: 2 Votes (Like | Disagree)
bmb012 Avatar
132 months ago
Why would anyone ever install Skype 5 over 2.8? :eek:

I do wish they'd fix their stupid hideous software :(
Score: 2 Votes (Like | Disagree)

Top Stories

iphone12protriplelenscamera

Apple's Orders for Key iPhone 13 Camera Component Expected to Outstrip Entire Android Market

Wednesday June 9, 2021 12:47 am PDT by
Major camera upgrades coming to the iPhone 13 series are putting increased pressure on suppliers to meet Apple's demand for key lens components, according to a new DigiTimes report. Apple has reportedly put Taiwan-based makers of voice coil motor (VCM) components on notice to increase their capacity by 30-40% in order to meet the company's demand, which is expected to outstrip the entire...
live text macos monterey

Several macOS Monterey Features Unavailable on Intel-Based Macs

Wednesday June 9, 2021 8:23 am PDT by
While there are many great new features in macOS Monterey, several of them are not available on Intel-based Macs, according to Apple. On the macOS Monterey features page, fine print indicates that the following features require a Mac with the M1 chip, including any MacBook Air, 13-inch MacBook Pro, Mac mini, and iMac model released since November 2020:Portrait Mode blurred backgrounds in...
m1x mbp tags feature

Apple Lists 'M1X MacBook Pro' in YouTube Tags for WWDC Keynote Video

Wednesday June 9, 2021 7:19 am PDT by
Before WWDC, rumors largely driven by leaker Jon Prosser suggested that Apple would announce redesigned 14-inch and 16-inch MacBook Pros during the conference. Those rumors, however, did not come to fruition. Interestingly, though, Apple lists "m1x MacBook Pro" as a tag for the WWDC keynote uploaded on YouTube. The tag, first spotted by Apple YouTuber Max Balzer on Twitter, is among other...
macos monterey setup assistant

macOS Monterey Allows You to Erase a Mac Without Needing to Reinstall the Operating System

Wednesday June 9, 2021 4:41 pm PDT by
It's been a few days since Apple announced macOS Monterey, and we continue to dig through new features that weren't mentioned during the WWDC keynote, including a much more convenient way of erasing a Mac. Following in the footsteps of the iPhone and iPad, the Mac has gained an "Erase All Content and Settings" option on macOS Monterey. The option allows you to erase all user data and...
apple repair service expansion iphone repair 07072020 big

Apple Agrees to Multimillion-Dollar Settlement After iPhone Repair Technicians Post Customer's Private Photos Online

Monday June 7, 2021 2:44 am PDT by
Apple has paid a 21-year-old millions of dollars in a legal settlement after photos and videos from the customer's iPhone, sent in for repair, were uploaded to Facebook, leading to "severe emotional distress," according to a new report from The Telegraph. The incident occurred in 2016 at a repair facility run by Apple supplier Pegatron in California. The 21-year-old college student sent her...
16 inch macbook pro m2 render

New MacBook Pro Shipments Forecasted to Begin in Third Quarter

Tuesday June 8, 2021 8:28 am PDT by
While leaker Jon Prosser claimed that a new MacBook Pro was coming at WWDC, Apple's keynote did not include any new hardware announcements. Instead, it is looking increasingly likely that redesigned 14-inch and 16-inch MacBook Pro models powered by a faster iteration of the M1 chip will be released in the third or fourth quarter of the year. A paywalled preview of a DigiTimes report today...
maxresdefault

Hands-On With iOS 15: See Apple's New Operating System Update in Action

Tuesday June 8, 2021 3:28 pm PDT by
Apple yesterday unveiled iOS 15, the newest version of the iOS operating system that runs on the iPhone (and the iPad with iPadOS 15). iOS 15 is a significant update that introduces many important new features, and we thought we'd give MacRumors readers a first look at the new software. Subscribe to the MacRumors YouTube channel for more videos. Not everything that was announced yesterday is...
imac macbook pro macos monterey

Newer Macs Can Use Another Mac as an External Display on macOS Monterey

Wednesday June 9, 2021 2:10 pm PDT by
One of the key new features of macOS Monterey is the ability to AirPlay content to a Mac from other Apple devices, such as an iPhone, iPad, or another Mac. According to the macOS Monterey features page, AirPlay to Mac works works both wirelessly or wired using a USB cable, with Apple noting that a wired connection is useful when you want to ensure that there's no latency or don't have access to a ...
Dark Sky App Featured

Dark Sky iOS App, Website, and API Now Scheduled to Remain Available Until End of 2022

Thursday June 10, 2021 7:34 am PDT by
Last year, Apple acquired the weather app Dark Sky, and shortly after its purchase, Apple shut down the app for Android. Despite the revamped iOS 15 Weather app taking heavy inspiration from Dark Sky, the weather's app standalone iOS app, web app, and API will remain available until the end of next year, compared to the end of this year, as previously planned. Dark Sky announced in an update ...
photos app remove from featured

iOS 15 Finally Lets You Block Your Exes From Ruining Your Photo Memories

Wednesday June 9, 2021 12:37 pm PDT by
With iOS 15, Apple is introducing more granular control over the people and places that show up in your Photos Memories, letting you fine tune just who makes random appearances in the Photos app and the Photos widget. In iOS 14, the option on the right was available, but in iOS 15, the person-specific option is new You've already been able to select "Suggest Fewer Memories Like This" when...