Researcher: Skype for Mac has ‘dangerous’ vulnerability
Skype's Mac client has a serious zero-day vulnerability that the company is yet to fix, a security researcher has said. — Writing on the blog of security firm Pure Hacking, researcher Gordon Maddern said on Friday that the vulnerability means …
Context & Ripple Effects
Gordon Maddern of Sydney-based penetration-testing firm Pure Hacking published details on Friday of a zero-day vulnerability he calls 'dangerous' in Skype for Mac 5.x — and Skype's own security blog posted a same-day response confirming the vulnerability has been addressed. That turnaround matters: the relationship record shows Skype had not yet fixed the flaw when Maddern went public, so the disclosure effectively forced the fix rather than following it.
The episode lands amid an aggressive expansion stretch for Skype — advertising launched in the Home tab in March 2011 and video calling deals spanning all four major US carriers plus the completed Qik acquisition announced in February. It also echoes an older pattern: the 2007 QuickTime zero-day that threatened both Macs and PCs showed Mac clients are not exempt from cross-platform media-handling bugs.
First-order effects
- Mac users running Skype 5.x were exposed to whatever remote code path Maddern demonstrated until Skype shipped its fix, making an immediate client update the only real mitigation.
- Skype was pulled from routine product cadence into emergency incident response on the same day the research went public, with its brand now attached to a publicly documented unpatched window.
Second-order effects
- As Skype pushes video calling onto every major US carrier and folds in Qik, each expansion multiplies the attack surface auditors like Pure Hacking will test — carrier partners inherit exposure to flaws in the client they ship.
- The disclosure gives other security researchers a template for pressuring consumer VoIP vendors via public write-ups when private reporting stalls, raising the reputational cost of slow patch cycles.
Third-order effects
- If the pattern holds, consumer communication clients — not operating systems — become the recurring zero-day battleground, because they hold camera, microphone and contact access behind a single app.
- Repeated high-profile Mac client bugs chip away at the assumption that Mac users face materially lower malware risk, pushing security budgets toward application-layer testing regardless of platform.
The trend: Consumer voice-and-video clients are emerging as prime zero-day targets, with researcher disclosures increasingly setting the patch timetable for vendors like Skype.