Security researcher rewrites Mac firmware over Thunderbolt, says most Intel Thunderbolt Macs vulnerable
A security researcher speaking at the Chaos Computer Congress in Hamburg demonstrated a hack that rewrites an Intel Mac's firmware using a Thunderbolt device with attack code in an option ROM.
Context & Ripple Effects
This talk is the opening move in a long arc of physical-access firmware attacks against Macs. A researcher at the Chaos Computer Congress showed that a Thunderbolt device carrying attack code in its option ROM can rewrite a Mac's firmware directly — below the operating system, where antivirus and reinstalling macOS never reach — and claimed most Intel Thunderbolt Macs share the exposure.
The pattern kept compounding: within months came reports of a firmware worm attacking Macs and a rootkit installable through older Mac firmware, and by 2020 researchers were demonstrating a modified USB-C cable that hacks the T2 chip and a checkm8 variant hitting T2-equipped Macs. The through-line is that the port itself became the attack surface.
First-order effects
- Most Intel Macs with Thunderbolt ports are exposed to an attacker with brief physical access, who gains firmware-level persistence that survives OS wipes and defeats endpoint security.
- Apple inherits a class of vulnerability it cannot patch in software alone, since the compromise lives in firmware written by the peripheral's option ROM.
Second-order effects
- Apple's eventual answer — dedicated security silicon like the T2 chip — becomes the counter-move, yet coverage shows even that layer later fell to checkm8 variants and cable-based attacks, forcing successive redesigns rather than a one-time fix.
- PC makers face the same Thunderbolt exposure: a related finding showed PCs with Thunderbolt ports carry an unpatchable flaw exploitable with physical access, making peripheral-port security a shared industry problem rather than a Mac-only one.
Third-order effects
- If the pattern holds, trust migrates away from firmware and peripherals toward hardened silicon: security features get baked into custom chips because anything loaded over an expansion bus can be rewritten.
- Physical access becomes formally recognized as a first-class threat model for laptops, reshaping how enterprises treat lost devices, shared workspaces, and supply-chain integrity for docks and cables.
The trend: Peripheral ports keep proving to be an unpatchable attack surface, steadily pushing Apple and PC makers to move platform security from firmware into dedicated silicon.