Report: Vulnerability in firmware of Macs from mid-2014 and earlier allows hackers to install rootkit malware, does not require physical access to exploit
Dan Goodin / Ars Technica :
Context & Ripple Effects
Dan Goodin's report lands at the start of what became a defining run of Mac firmware research in 2015: within weeks, security researchers demonstrated the first firmware worm capable of attacking Macs, turning the vulnerability described here into proof that EFI infections could spread on their own rather than requiring targeted deployment.
The longer arc matters just as much. A separate zero-day in Apple's fully patched OS X reported two months later showed that even current software couldn't shield users, and by late 2017 researchers found an alarming number of Macs still vulnerable through outdated EFI firmware — with Windows and Linux machines likely exposed too — indicating the patching problem was never solved.
First-order effects
- Owners of Macs sold mid-2014 or earlier face a class of compromise that survives OS reinstalls: a rootkit written into firmware persists invisibly beneath the operating system, defeating standard cleanup steps.
- Apple comes under pressure to deliver firmware fixes through its normal software-update channel, since most users never manually flash EFI updates.
Second-order effects
- Antivirus and endpoint-security vendors find their products structurally blind to these attacks, because scanning happens above the compromised firmware layer — forcing the security industry to look at integrity checks below the OS.
- The demonstrated firmware worm escalates the threat model from targeted intrusion to something that can propagate between machines, raising the stakes for every Mac fleet operator.
Third-order effects
- If the pattern holds — and the 2017 finding that Macs remained unpatched suggests it did — the industry shifts toward cryptographically signed, automatically delivered firmware updates, making firmware a first-class attack surface alongside the OS for all PC vendors, not just Apple.
The trend: Firmware is emerging as the durable battleground of endpoint security, where OS-level patching proves insufficient unless vendors automate and verify low-level updates.