A security researcher has found a vulnerability in the Zoom installer for macOS that could allow an attacker to gain root access to the system. The vulnerability is due to a bug in the installer's auto-update function, which can be exploited to run malicious code with elevated privileges. Zoom has issued a patch, but the researcher says it is incomplete and the vulnerability is still exploitable. The researcher reported the vulnerability to Zoom in December, but the company took several months to issue a fix.