Linux Zoom client now reads everything you copy to the clipboard

Linux Zoom client proactively reading everything written to X11 clipboard

Simon Tatham discovered that the Linux Zoom client version 7.1.5 proactively reads everything written to the X11 clipboard. It detects new clipboard owners via the XFIXES extension and immediately requests a paste, which breaks one-shot paste tools and could expose passwords from password managers. The behavior is limited to the CLIPBOARD selection, not PRIMARY.

If you keep interesting secrets in your clipboard – particularly, if a password manager uses it as a means of getting the password to where it needs to be – this might be a thing you need to know about!
  1. rmellow

    Not the first time Zoom abuses privilege.

    A few years back, there was something about gaining root on MacOS via Zoom due to shady execution on their end.

    They've lost my trust since then, and I'll only run it sandboxed: https://gist.github.com/cielavenir/02f322e322a2a3555dbf2b38f...

    I always ask (1) why does an app require installation and (2) why would it require root?

    There are valid answers for both, but realistically, all a videoconferencing app should need (apart from audio and video and maybe screen sharing) is to store a config file.

    There's no legitimate use for it accessing privileged or private paths.

  2. mzajc

    Unrelated to Zoom, but

    > I noticed it because I make heavy use of a "one-shot paste" tool which fulfills a single paste request and then terminates. Handy for filling in lots of fields of a web form – queue up pastes of several different things, then go to each form field in turn and just hit paste, bam bam bam.

    This sounds very useful. Is the tool available anywhere? xclip -loops doesn't seem to do the trick, or maybe it just doesn't work that way on Wayland.

  3. Arbortheus

    Just run these things in your browser. Despite the dark design patterns that try to trick you into installing their desktop client, the web-based versions are fine.

  4. bytesandbits

    Zoom is malware, has always been.

  5. Throwthrowbob

    I remember a friend installing Zoom on a Linux computer through their software manager. Later, they removed it and found that when they visited the page in the software manager for Zoom, it automatically tried to install Zoom without interaction from them (ie, my friend did not click Install, but viewed the page and a password prompt for installing the package appeared).

    I'm not sure if this was behaviour that happened with the software manager on other packages, but was a concern for us.

  6. SubiculumCode

    University of California has licensed zoom accounts with privacy agreements. I install it in Linux. Now I will check if I can replicate this behavior. I am not sure if it is a violation of their agreement or not if they do, but I don't like it.

  7. ocd

    I miss ordinary conference calling being the norm. I like having a desktop IP phone.

  8. shevy-java

    That's so sad. These companies try to ruin Linux by spying on the user here.

More from this day

2026-09-12