Researchers find alarming number of Macs remain vulnerable to stealthy hacks due to outdated EFI firmware; Windows and Linux PCs are also likely at risk
Even With Updated Software Bryan Clark / The Next Web : Report: Countless PCs vulnerable to newly discovered firmware attack [Update] Paul Wagenseil / Tom's Guide : Many Macs Can Be Hacked by Firmware Attacks Buster Hein / Cult of Mac : Your up-to-date Mac might be vulnerable to firmware attacks AJ Dellinger / International Business Times : Mac Firmware Attack: Out Of Date Machines Vulnerable To Attack Laura Hautala / CNET : Apple computers are at risk from flawed updates, researchers find Jeff Butts / The Mac Observer : Your Mac's EFI Might Be Outdated John Keefer / Neowin : Report: Unupdated firmware in 4% of Macs means security issues Mohit Kumar / The Hacker News : Millions of Up-to-Date Apple Macs Remain Vulnerable to EFI Firmware Hacks Kevin Townsend / SecurityWeek : Mac Firmware Updates Are Failing and Leaving Systems Vulnerable: Report Brett Williams / Mashable : New study finds small percentage of Macs are running insecure firmware Greg Synek / TechSpot : Thousands of Mac computers are still vulnerable to EFI hacks Duo-Labs / GitHub : duo-labs/EFIgy — Join GitHub today … Clone or download … BBC : Apple Macs and PCs at risk from boot bug John Leyden / The Register : Apple Mac fans told: Something smells EFI in your firmware Kinsey Grant / TheStreet : Some Apple Macs Vulnerable to ‘Malicious Firmware’ Attacks: Duo Security Jack Purcher / Patently Apple : A Security Firm Report Claims that older Macs are still vulnerable to ‘Firmware’ Attacks Joe Rossignol / MacRumors : Study Finds Significant Number of Macs Running Out-of-Date Firmware Susceptible to Critical Exploits MacDailyNews : EFI firmware in millions of Macs don't get the most critical elements of Apple's updates … Ben Lovejoy / 9to5Mac : Study shows 4.2% of Macs running insecure firmware; High Sierra addresses issue Robert Hackett / Fortune : Apple Mac Firmware Updates Are Quietly Failing and No One Knows Why Andy Greenberg / Wired : Critical Code in Millions of Macs Isn't Getting Apple's Updates Evan Selleck / iPhone Hacks : Study Shows a High Percentage of Macs Are Running Insecure Firmware Ian Barker / BetaNews : Failed updates leave Mac computers at risk from targeted attacks on firmware Michael Mimoso / Threatpost : Macs Not Receiving EFI Firmware Security Updates as Expected Tweets: Barton Gellman / @bartongellman : Great work. How about a brief how-to for users who want to check and update firmware? Even in your full paper it's not all spelled out. http://twitter.com/... Duo Security / @duosec : .@duo_labs new research explores 73k+ real-world Macs, highlighting why firmware security is an industrywide issue: http://duo.sc/... http://twitter.com/... @wired : Apple doesn't appear to notify users when a firmware update fails, leaving key security vulnerabilities untended to http://www.wired.com/... Jon Oberheide / @jonoberheide : Apple: “We appreciate Duo's work on this industry-wide issue and noting Apple's leading approach to this challenge.” http://duo.com/...
Context & Ripple Effects
The firmware-rootkit problem on Macs was flagged over two years ago, when researchers showed that a vulnerability in Macs from mid-2014 and earlier let attackers install persistent malware with no physical access (older Mac firmware rootkit vulnerability). What Duo Labs adds now is the why-it-persists: Apple's EFI firmware updates are reportedly failing to install on many machines, so owners who believe they are fully patched are not.
That makes this an update-delivery story rather than a new-bug story — and Duo Labs' warning that Windows and Linux PCs are likely exposed too means the finding generalizes past Apple to the whole PC fleet.
First-order effects
- Mac owners running current macOS but carrying stale EFI remain silently exploitable by firmware-resident malware that survives OS reinstalls, and Apple's own update mechanism is the point of failure.
- Security teams auditing Mac fleets can no longer treat 'OS is patched' as evidence of a clean machine; they must verify firmware versions machine-by-machine.
Second-order effects
- Windows and Linux OEMs face pressure to prove their firmware update chains actually land on endpoints, since Duo Labs explicitly flags those platforms as likely at risk from the same class of attack.
- Endpoint-security vendors gain a selling point for firmware-scanning and attestation tooling aimed at enterprises that just learned their patch compliance numbers were overstated.
Third-order effects
- If firmware keeps proving to be the layer where patching breaks down, the industry shifts toward hardware-verified update and boot chains — a structural move below the OS that vendors like Apple cannot fix through software releases alone.
- The pattern echoes other below-the-OS exposures such as the later-reported unpatchable Thunderbolt flaw requiring physical access, suggesting firmware and silicon become the durable battleground between attackers and defenders.
The trend: PC security is migrating below the operating system into firmware, where failed update delivery — not missing patches — becomes the dominant source of unfixable exposure.