OS X 10.10.2 Includes Fix for 'Thunderstrike' Hardware Exploit Affecting Macs

Apple is readying a fix in OS X 10.10.2 for the so-called "Thunderstrike" hardware exploit targeting Macs equipped with Thunderbolt ports, iMore has learned. According to the report, Apple patched the vulnerability by making code changes in the upcoming software update that prevent a Mac's bootrom from being replaced or rolled back to a previous state in which it could be attacked.

To secure against Thunderstrike, Apple had to change the code to not only prevent the Mac's boot ROM from being replaced, but also to prevent it from being rolled back to a state where the attack would be possible again. According to people with access to the latest beta of OS X 10.10.2 who are familiar with Thunderstrike and how it works, that's exactly the deep, layered process that's been completed.

Thunderstrike is a serious vulnerability discovered earlier this year by security researcher Trammell Hudson, enabling an attacker to replace a Mac's bootrom with malicious code without a user knowing. Since the malicious code is stored in a low level inaccessible to the user, the problem would remain even if the bootrom was replaced.

macbook_air_pro_yosemite
The proof-of-concept attack is limited in scope, however, as an attacker would require physical access to the Mac or savvy social engineering skills in order to trick a user into attacking his or her Mac themselves. Apple has already addressed the issue in its latest hardware, including the iMac with Retina 5K Display and new Mac mini.

OS X 10.10.2 has been in pre-release testing for over two months and should be made available to the public in the coming days. The most recent OS X 10.10.2 beta was seeded to developers for testing last Wednesday. In addition to the Thunderstrike fix, the upcoming software update addresses security vulnerabilities exposed by Google's Project Zero security team last week.

According to 9to5Mac, the latest OS X Yosemite release will also add iCloud Drive in Time Machine and resolve issues related to Wi-Fi, VoiceOver and security. In particular, a recently identified glitch causing Spotlight on OS X to expose system information to spammers through remote content loading will reportedly be patched. Safari will also gain improved performance and security.

No public instances of Thunderstrike attacks have yet to be reported.

Top Rated Comments

(View all)
Avatar
75 months ago
Apple had better improve performance to at least where my Mini was under mavericks.
Safari stinks as well under Yosemite.
Start-up time is 10 times longer than before as well
Closed system under Apple is supposed to prevent stuff like this from happening and until Yosemite it was pretty much true.

Keep Ivy away from the Operating System!
After seeing what he did to the Mini I wouldn't mind seeing him take a long hike permanently
Score: 5 Votes (Like | Disagree)
Avatar
75 months ago

EXCELLENT. I've been hoping I would eventually be able to go to a cloud based backup.


I'd rather see them increase the free storage amount to 10 GB to be more in line with other cloud backup services. Not everyone has the incentive or need to pay for more storage.
Score: 5 Votes (Like | Disagree)
Avatar
75 months ago
just release it already, Im so sick of the wifi disconnects
Score: 4 Votes (Like | Disagree)
Avatar
75 months ago


To what extent have you tried to solve this problem?

[LIST=1]
* Have you switched to a 5GHz network?
* Have you ensured only essential wireless networks are set up in your home? (ie. Turn off any that aren't needed)


Come on now, these are all things that you shouldn't have to do. I have dozens of devices, all types of macs (meaning non-yosemite) macs that haven't had a single problem. Don't blame the user....
Score: 3 Votes (Like | Disagree)
Avatar
75 months ago

We salute .........Apple


For Those About to Update.... We Salute You! :cool:
Score: 3 Votes (Like | Disagree)
Avatar
75 months ago

the latest OS X Yosemite release will also add iCloud Drive in Time Machine


EXCELLENT. I've been hoping I would eventually be able to go to a cloud based backup.
Score: 3 Votes (Like | Disagree)

Top Stories

'A New iOS Update is Now Available' Popping Up Repeatedly in iOS 14 Beta [Fixed: New Beta Available]

Thursday October 29, 2020 6:11 pm PDT by
Many users running iOS 14 beta are reporting that they are seeing a dialog box pop up repeatedly asking them to update from the latest iOS 14 beta. Threads in our forums, Reddit, and Twitter are reporting the issue. The dialog has been appearing for a few days now, but as of tonight has started appearing more frequently, every time an iPhone is unlocked. There's been further discussion in...

Apple Seeds New iOS 14.2 Versions Which Stops 'New iOS Update Available' Alerts

Friday October 30, 2020 1:09 pm PDT by
Apple today seeded "Release Candidate" versions of upcoming iOS 14.2 and iPadOS 14.2 updates to developers and public beta testers, 10 days after seeding the fourth betas and a month and a half after releasing the iOS 14 and iPadOS 14 updates. iOS and iPadOS 14.2 can be downloaded by developers through the Apple Developer Center or over the air after the proper developer profile has been...

Apple One is Now Available: Save Money by Bundling Apple Music, iCloud Storage, Apple TV+, Apple Arcade, and More

Friday October 30, 2020 7:47 am PDT by
Apple One bundles are now available in the United States and over 100 other countries, allowing customers to subscribe to multiple Apple services through a single plan, including Apple Music, Apple TV+, Apple Arcade, iCloud, and more. To sign up for Apple One on an iPhone: Open Settings App Tap on Your Name at the top Tap on Subscriptions Tap on Apple One The prompt for Apple One...

Black Friday Spotlight: Best Buy Kicks Off a Month of Apple Deals and More

Friday October 30, 2020 10:02 am PDT by
We've begun tracking early Black Friday deals in our dedicated Black Friday Roundup, and in an effort to prepare our readers for the big shopping event we're highlighting sales store-by-store in the lead-up to November 27. Note: MacRumors is an affiliate partner with Best Buy. When you click a link and make a purchase, we may receive a small payment, which helps us keep the site running....

Apple Launches AirPods Pro Service Program for Crackling/Static Problems and ANC Issues

Friday October 30, 2020 3:03 pm PDT by
Apple today announced the launch of a new service program for AirPods Pro sound issues, which is designed to address AirPods Pro units experiencing static or crackling sounds or problems with Active Noise Cancellation. Faulty AirPods exhibit the following problems, according to Apple:Crackling or static sounds that increase in loud environments, with exercise or while talking on the phone ...

Apple CEO Tim Cook: 'More Exciting Things' in Store For This Year

Thursday October 29, 2020 2:20 pm PDT by
During today's earnings call for the fourth fiscal quarter of 2020 (third calendar quarter), Cook said that while he doesn't want to give too much away, "this year has a few more exciting things in store." Cook is likely speaking about the Apple Silicon Macs, as Apple has previously said the first Apple Silicon Mac will be coming before the end of 2020. There are rumors of a third fall event ...

Hands-On Comparison: iPhone 12 vs. iPhone 12 Pro

Friday October 30, 2020 2:29 pm PDT by
For those still trying to make a decision between an iPhone 12 or an iPhone 12 Pro, we picked up both models and in our latest YouTube video, did a hands-on comparison between them. Our video highlights the similarities and the differences so you can which one is the best fit for you and whether the iPhone 12 Pro is worth an extra $200. Subscribe to the MacRumors YouTube channel for more ...

Apple One Service Bundles Set to Launch Tomorrow, Fitness+ Coming This Quarter

Thursday October 29, 2020 1:39 pm PDT by
Apple in September announced Apple One, a new series of services bundles that will let Apple device customers purchase several services together in one package instead of separately, saving money for those who use multiple Apple service products. Ahead of Apple's earnings call, Apple CFO Luca Maestri told Bloomberg that Apple One is set to launch on Friday, October 30. Apple One Bundle...

PSA: Apple One Premier Bundle Only Available in US, UK, Canada, and Australia

Friday October 30, 2020 2:39 am PDT by
Apple's new Apple One series of services bundles launches on Friday in over 100 countries and regions, but the top Premier tier will be limited to the United States, the United Kingdom, Australia, and Canada. The limited rollout of the $29.95 Premier tier is down to the fact that Apple News+ is currently only available in the above countries. Apple News+ is exclusive to the Premier tier,...

Apple Says Record 2020 Mac Sales Attributed Primarily to MacBook Pro

Friday October 30, 2020 12:24 pm PDT by
Apple on Thursday reported its earnings for the fourth quarter of the 2020 fiscal year, including Mac revenue of $9 billion, a new quarterly record. Apple ended the year with annual Mac revenue of $28.6 billion, an all-time high. In its annual Form 10-K report [PDF], filed with the U.S. Securities and Exchange Commission today, Apple said increased Mac sales in fiscal 2020 compared to fiscal ...