Zulip Desktop before 5.0.0 allows attackers to perform recording via the webcam and microphone due to a missing permission request handler.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
https://blog.zulip.com/2020/04/01/zulip-desktop-5-0-0-security-release/ | release notes vendor advisory |