Vulnerabilities in Thunderbolt has been disclosed by security researchers, with “Thunderclap” allowing a device connecting over Thunderbolt to acquire sensitive data from the host Mac, an issue that affects almost all Macs released since 2011.
Revealed at the Network and Distributed Systems Security Symposium on Tuesday, Thunderclap is a set of vulnerabilities that take advantage of issues with the way Thunderbolt operates. By misusing how Thunderbolt functions, a malicious device has the capability to access system memory without any oversight from operating systems.
The main way Thunderclap works is due to how Thunderbolt peripherals and accessories are effectively considered to be trusted components of a computer, complete with direct memory access that can bypass operating system security policies, according to security researcher Theo Markettos. Thunderbolt offers devices “more privilege than regular USB devices,” giving them more freedom and access to potentially sensitive information.
Practically all hardware with some form of Thunderbolt connection is affected, including those with USB Type-C ports and those with older Mini DisplayPort connections. In the case of Apple, a dedicated Thunderclap website notes “all Apple laptops and desktops produced since 2011 are vulnerable, with the exception of the 12-inch Macbook.”
Read more at AppleInsider.com
