OS X 10.10.2 Includes Fix for 'Thunderstrike' Hardware Exploit Affecting Macs

Apple is readying a fix in OS X 10.10.2 for the so-called "Thunderstrike" hardware exploit targeting Macs equipped with Thunderbolt ports, iMore has learned. According to the report, Apple patched the vulnerability by making code changes in the upcoming software update that prevent a Mac's bootrom from being replaced or rolled back to a previous state in which it could be attacked.

To secure against Thunderstrike, Apple had to change the code to not only prevent the Mac's boot ROM from being replaced, but also to prevent it from being rolled back to a state where the attack would be possible again. According to people with access to the latest beta of OS X 10.10.2 who are familiar with Thunderstrike and how it works, that's exactly the deep, layered process that's been completed.

Thunderstrike is a serious vulnerability discovered earlier this year by security researcher Trammell Hudson, enabling an attacker to replace a Mac's bootrom with malicious code without a user knowing. Since the malicious code is stored in a low level inaccessible to the user, the problem would remain even if the bootrom was replaced.

macbook_air_pro_yosemite
The proof-of-concept attack is limited in scope, however, as an attacker would require physical access to the Mac or savvy social engineering skills in order to trick a user into attacking his or her Mac themselves. Apple has already addressed the issue in its latest hardware, including the iMac with Retina 5K Display and new Mac mini.

OS X 10.10.2 has been in pre-release testing for over two months and should be made available to the public in the coming days. The most recent OS X 10.10.2 beta was seeded to developers for testing last Wednesday. In addition to the Thunderstrike fix, the upcoming software update addresses security vulnerabilities exposed by Google's Project Zero security team last week.

According to 9to5Mac, the latest OS X Yosemite release will also add iCloud Drive in Time Machine and resolve issues related to Wi-Fi, VoiceOver and security. In particular, a recently identified glitch causing Spotlight on OS X to expose system information to spammers through remote content loading will reportedly be patched. Safari will also gain improved performance and security.

No public instances of Thunderstrike attacks have yet to be reported.

Related Forum: OS X Yosemite

Popular Stories

M4 iMac With Magic Accessories

Apple Announces iMac With M4 Chip, Upgraded Camera, Nano-Texture Display Option, and More

Monday October 28, 2024 8:01 am PDT by
Apple today announced that it has updated the 24-inch iMac with the M4 chip, which debuted in the iPad Pro earlier this year. This upgrade comes around one year after the previous iMac with the M3 chip was released. Subscribe to MacRumors on YouTube for more videos! As expected, the M4 chip in the iMac is available with up to a 10-core CPU and up to a 10-core GPU. Apple says the iMac with the ...
m3 mbp space black

What to Expect From Apple's 'Exciting Week of Announcements'

Thursday October 24, 2024 10:36 am PDT by
Apple's marketing chief Greg Joswiak today teased that the company has an "exciting week of announcements" planned next week. Joswiak said to "Mac" your calendars, and the post includes an animated icon for the Finder app on the Mac, so it is clear that at least some of next week's announcements will be related to the Mac. Subscribe to MacRumors on YouTube for more videos! Below, we have...
apple wallet drivers license feature iPhone 15 pro

Apple Says iPhone Driver's Licenses Coming to These U.S. States Next

Wednesday October 23, 2024 1:41 pm PDT by
In select U.S. states, residents can add their driver's license or state ID to the Wallet app on the iPhone and Apple Watch, providing a convenient and contactless way to display proof of identity or age at select airports and businesses, and in select apps. Below, we outline which U.S. states offer the feature, and additional states that have committed to rolling it out in the feature in...
maxresdefault

Apple Releases iOS 18.1 and iPadOS 18.1 With Apple Intelligence

Monday October 28, 2024 8:07 am PDT by
Apple today released iOS 18.1 and iPadOS 18.1, the first major updates to the iOS 18 and iPadOS 18 updates that came out in September. iOS 18.1 and iPadOS 18.1 come six weeks after the release of iOS 18 and iPadOS 18. Subscribe to the MacRumors YouTube channel for more videos. The new software can be downloaded on eligible iPhones and iPads over-the-air by going to Settings > General >...
apple oct 2024 mac tease

Apple Teases M4 Mac Announcements Next Week

Thursday October 24, 2024 9:19 am PDT by
Apple's Greg Joswiak today made it clear that Apple plans to reveal new products next week, teasing refreshed Macs. In a social media post, Joswiak said to "Mac your calendars" because there's an exciting week of announcements that start on Monday morning. With Joswiak's announcement, it appears that there will not be a dedicated October event for Macs this year, with Apple instead...
M4 iMac With Magic Accessories

Apple Updates Magic Mouse, Magic Keyboard, and Magic Trackpad With USB-C Ports

Monday October 28, 2024 8:02 am PDT by
Alongside the new iMac, Apple announced updated versions of the Magic Mouse, Magic Keyboard, and Magic Trackpad. The accessories are now equipped with USB-C charging ports, whereas the previous models used Lightning. Apple includes the Magic Mouse and Magic Keyboard in the box with the iMac, and the Magic Trackpad is an optional upgrade. "Every iMac comes with a color-matched Magic Keyboard...
iPhone SE 4 Thumb 1

iPhone SE 4 Mass Production Timeframe Revealed as Launch Gets Closer

Wednesday October 23, 2024 9:38 am PDT by
Apple suppliers will begin mass production of the fourth-generation iPhone SE in December, supply chain analyst Ming-Chi Kuo said today in a blog post. The fourth-generation iPhone SE is expected to have a similar design as the base iPhone 14, with rumored features including a 6.1-inch OLED display, Face ID, a newer A-series chip, a USB-C port, a single 48-megapixel rear camera, 8GB of RAM...
apple oct 2024 mac tease

Apple Promises Two More Mac Announcements This Week Following New iMac Today

Monday October 28, 2024 11:18 am PDT by
Apple introduced a new iMac today with the M4 chip and more, but that's not all, as it still has two more Mac announcements planned this week. "This is a huge week for the Mac, and this morning, we begin a series of three exciting new product announcements that will take place over the coming days," said Apple's hardware engineering chief John Ternus, in a video announcing the new iMac....

Top Rated Comments

steve333 Avatar
127 months ago
Apple had better improve performance to at least where my Mini was under mavericks.
Safari stinks as well under Yosemite.
Start-up time is 10 times longer than before as well
Closed system under Apple is supposed to prevent stuff like this from happening and until Yosemite it was pretty much true.

Keep Ivy away from the Operating System!
After seeing what he did to the Mini I wouldn't mind seeing him take a long hike permanently
Score: 5 Votes (Like | Disagree)
redheeler Avatar
127 months ago
EXCELLENT. I've been hoping I would eventually be able to go to a cloud based backup.

I'd rather see them increase the free storage amount to 10 GB to be more in line with other cloud backup services. Not everyone has the incentive or need to pay for more storage.
Score: 5 Votes (Like | Disagree)
zombiecakes Avatar
127 months ago
just release it already, Im so sick of the wifi disconnects
Score: 4 Votes (Like | Disagree)
citi Avatar
127 months ago

To what extent have you tried to solve this problem?

[LIST=1]
* Have you switched to a 5GHz network?
* Have you ensured only essential wireless networks are set up in your home? (ie. Turn off any that aren't needed)

Come on now, these are all things that you shouldn't have to do. I have dozens of devices, all types of macs (meaning non-yosemite) macs that haven't had a single problem. Don't blame the user....
Score: 3 Votes (Like | Disagree)
MacsRgr8 Avatar
127 months ago
We salute .........Apple

For Those About to Update.... We Salute You! :cool:
Score: 3 Votes (Like | Disagree)
Daalseth Avatar
127 months ago
the latest OS X Yosemite release will also add iCloud Drive in Time Machine

EXCELLENT. I've been hoping I would eventually be able to go to a cloud based backup.
Score: 3 Votes (Like | Disagree)