Researchers demo plugging a modified USB-C cable into a Mac to hack T2 chip; Apple has debuted six Mac models with T2 chips since the checkm8 flaw became public
The T2 exploit team who found a way to take over the security chip in modern Macs has demonstrated a way to do so without user intervention …
Context & Ripple Effects
A week after researchers disclosed that Macs with Apple's T2 security chip are vulnerable to an unpatchable variant of checkm8, they have now shown the attack working end-to-end: a modified USB-C cable takes over the chip with no user interaction required. The demonstration lands awkwardly for Apple, which has debuted six new T2-equipped Mac models since the underlying checkm8 flaw became public.
The story also fits a longer arc in this coverage: back in 2015 a researcher showed Mac firmware could be rewritten over Thunderbolt, and leaked documents later revealed that T2 Macs must pass Apple-internal diagnostics after repair or be rendered nonfunctional — meaning the same chip that locks down repairs is now the one exposed to takeover.
First-order effects
- Anyone with brief physical access to a T2 Mac — a shared office, a repair bench, a border crossing — can compromise the security chip using only a modified cable, with no click or password prompt from the user.
- The six T2 Mac models Apple shipped after checkm8 went public inherit the exposure at purchase time, since the flaw sits below the patchable software layer.
Second-order effects
- Enterprise IT buyers weighing T2 Macs against PCs face a parallel decision to the one raised by the unpatchable Thunderbolt flaw in PCs: physical-port access becomes the threat model that firmware-based security cannot answer.
- Apple's repair-locking architecture built on the T2 now doubles as a liability — the chip that enforces diagnostics-gated service is the same chip attackers can seize, pressuring Apple to separate its security and servicing roles in future designs.
Third-order effects
- If the pattern holds — T2 in 2020, then the M-series key-extraction flaw four years later — Apple's custom silicon will keep carrying unpatchable hardware-level vulnerabilities, shifting Mac security assumptions toward 'physical access defeats the chip' regardless of generation.
- Hardware vendors industry-wide may face growing pressure to treat debug and peripheral ports as permanent attack surface, designing chips so that port-level compromise cannot reach root of trust — a structural change rather than a firmware fix.
The trend: Security-critical silicon keeps shipping with unpatchable hardware flaws that physical access can exploit, making port-level attacks a recurring structural problem across chip generations rather than a one-off bug.