/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Security researcher rewrites Mac firmware over Thunderbolt, says most Intel Thunderbolt Macs vulnerable

A security researcher speaking at the Chaos Computer Congress in Hamburg demonstrated a hack that rewrites an Intel Mac's firmware using a Thunderbolt device with attack code in an option ROM.

9to5Mac Ben Lovejoy

Context & Ripple Effects

This talk is the opening move in a long arc of physical-access firmware attacks against Macs. A researcher at the Chaos Computer Congress showed that a Thunderbolt device carrying attack code in its option ROM can rewrite a Mac's firmware directly — below the operating system, where antivirus and reinstalling macOS never reach — and claimed most Intel Thunderbolt Macs share the exposure.

The pattern kept compounding: within months came reports of a firmware worm attacking Macs and a rootkit installable through older Mac firmware, and by 2020 researchers were demonstrating a modified USB-C cable that hacks the T2 chip and a checkm8 variant hitting T2-equipped Macs. The through-line is that the port itself became the attack surface.

First-order effects

  • Most Intel Macs with Thunderbolt ports are exposed to an attacker with brief physical access, who gains firmware-level persistence that survives OS wipes and defeats endpoint security.
  • Apple inherits a class of vulnerability it cannot patch in software alone, since the compromise lives in firmware written by the peripheral's option ROM.

Second-order effects

  • Apple's eventual answer — dedicated security silicon like the T2 chip — becomes the counter-move, yet coverage shows even that layer later fell to checkm8 variants and cable-based attacks, forcing successive redesigns rather than a one-time fix.
  • PC makers face the same Thunderbolt exposure: a related finding showed PCs with Thunderbolt ports carry an unpatchable flaw exploitable with physical access, making peripheral-port security a shared industry problem rather than a Mac-only one.

Third-order effects

  • If the pattern holds, trust migrates away from firmware and peripherals toward hardened silicon: security features get baked into custom chips because anything loaded over an expansion bus can be rewritten.
  • Physical access becomes formally recognized as a first-class threat model for laptops, reshaping how enterprises treat lost devices, shared workspaces, and supply-chain integrity for docks and cables.

The trend: Peripheral ports keep proving to be an unpatchable attack surface, steadily pushing Apple and PC makers to move platform security from firmware into dedicated silicon.