A developer has created a $5 device that can hack into screen-locked Macs and potentially other computers as long as a web browser is left running on the desktop.

Samy Kamkar made a YouTube video showing what happens when his creation hacks into a target computer. Called a "Poison Tap", the device runs on a Raspberry Pi Zero which plugs into a computer's USB port.

locked Mac hack
Once attached to the locked and password-protected Mac, it hijacks all web traffic by posing as a standard internet connection, after which it sets about siphoning and storing the user's HTTP cookies.

The attacker can then potentially use the stolen cookie data to access websites the user visited and log-in as them without having to enter username and password information.

Speaking to the BBC, Trend Micro security researcher Rik Ferguson said the device was a plausible threat to users who frequently left their computer unattended.

[In normal circumstances] Even when you are not using a web browser it is still making requests and communicating - due to updates or ads. Once the device is plugged in it exploits that communication and steals session cookies from the top one million websites.

Two-step verification would be susceptible to the same attack, explained Ferguson, because the device is able to intercept the cookies and pretend it is already in an open session. The only way to guard against such an attack would be for websites to use an encrypted connection such as HTTPS.

Otherwise, the best solution is for users to ensure they close their browser every time they leave their Mac unattended, or else close it down completely.

Top Rated Comments

dannys1 Avatar
120 months ago
It's ok, costs more that $5 for my computer as he'll need to buy a USB-C cable...

:D:p
Score: 29 Votes (Like | Disagree)
mazz0 Avatar
120 months ago
Well, this sounded quite concerning until I got to where it says it doesn't work for https connections. Still somewhat worrying though.

Mac exploits require a certain modicum of stupidity in order to work.
What exactly is stupid about leaving your computer locked with a browser open?
Score: 11 Votes (Like | Disagree)
kstotlani Avatar
120 months ago
Mac exploits require a certain modicum of stupidity in order to work.
Speaking with experience?
Score: 6 Votes (Like | Disagree)
arkitect Avatar
120 months ago
So basically this is nothing to worry about unless you have a habit of leaving your Mac unattended in a public area. I don't know about you, but I'm not leaving my MacBook unattended anywhere!

I'm not leaving my MacBook unattended while I go the bathroom at Starbucks or anywhere else!
So in a work situation where desktops (Not portables) are left on all night? Sometimes the Mac is busy overnight rendering etc… cleaners come in… The way I see it there is potential for a problem.
Score: 5 Votes (Like | Disagree)
arkitect Avatar
120 months ago
Mac exploits require a certain modicum of stupidity in order to work.
In this case your comment seems misplaced.
What is so stupid about leaving my screen locked Mac unattended?

Not being snarky, but I am curious why you think this.
Score: 4 Votes (Like | Disagree)
saudor Avatar
120 months ago
Mac exploits require a certain modicum of stupidity in order to work.
so basically anyone that uses the "sleep" function and not physically power it down.
Score: 4 Votes (Like | Disagree)

Popular Stories

iPhone Top Left Hole Punch Face ID Feature Purple

iPhone 18 Pro Launching Later This Year With These 12 New Features

Thursday January 15, 2026 10:56 am PST by
While the iPhone 18 Pro and iPhone 18 Pro Max are not expected to launch for another eight months, there are already plenty of rumors about the devices. Below, we have recapped 12 features rumored for the iPhone 18 Pro models, as of January 2026: The same overall design is expected, with 6.3-inch and 6.9-inch display sizes, and a "plateau" housing three rear cameras Under-screen Face ID...
Apple MacBook Pro M4 hero

These 5 Apple Products Will Reportedly Be Upgraded With OLED Displays

Friday January 16, 2026 7:07 pm PST by
Apple plans to upgrade the iPad mini, MacBook Pro, iPad Air, iMac, and MacBook Air with OLED displays between 2026 and 2028, according to DigiTimes. Bloomberg's Mark Gurman previously reported that the iPad mini and MacBook Pro will receive an OLED display as early as this year, but he does not expect the MacBook Air to adopt the technology until 2028 at the earliest. A new iPad Air is...
2024 iPhone Boxes Feature

Apple Adjusts Trade-In Values for iPhones, Macs, and More

Thursday January 15, 2026 11:19 am PST by
Apple today updated its trade-in values for select iPhone, iPad, Mac, and Apple Watch models. Trade-ins can be completed on Apple's website, or at an Apple Store. The charts below provide an overview of Apple's current and previous trade-in values in the United States, according to the company's website. Most of the values declined slightly, but some of the Mac values increased. iPhone ...
Apple Wallet ID Illinois

Apple Plans to Expand iPhone Driver's Licenses to These 7 U.S. States

Friday January 16, 2026 12:12 pm PST by
In select U.S. states, residents can add their driver's license or state ID to the Apple Wallet app on the iPhone and Apple Watch, and then use it to display proof of identity or age at select airports and businesses, and in select apps. The feature is currently available in 13 U.S. states and Puerto Rico, and it is expected to launch in at least seven more in the future. To set up the...
iOS 27 Mock Quick

iOS 27 Will Add These 8 New Features to Your iPhone

Sunday January 18, 2026 3:51 pm PST by
iOS 27 is still many months away, but there are already plenty of rumors about new features that will be included in the software update. The first beta of iOS 27 will be released during WWDC 2026 in June, and the update should be released to all users with a compatible iPhone in September. Bloomberg's Mark Gurman said that iOS 27 will be similar to Mac OS X Snow Leopard, in the sense...