Here's the latest security bug your computer could be exposed by

A newly discovered firmware vulnerability could leave countless Windows and Mac computers at risk from a hack, according to security researchers from Duo Labs. The vulnerability could be used by malware to gain deep access to systems.

The bug involves the extensible firmware interface, or EFI, which is the first bit of code that runs when you hit the power button - part of its responsibilities include validating the software that's running on the machine.

Based on tests on 74,000 Apple Macs, the Duo Labs team found that the EFI firmware was not always being updated at the same time as the operating system, leaving a security hole that could potentially be exploited. The vulnerability could also affect Windows PCs, the researchers say.

Risk assessment

The good news is that a hack taking advantage of the EFI vulnerability would need to be quite a complex one, and it's only really worth the trouble if you've got some pretty important data locked away on your machine.

What's more, Duo Labs says it hasn't spotted anyone actively making use of this security loophole yet - it's working with Apple and other computer makers to get the bug patched. "For most people in most situations, the risk is currently not severe," the researchers say.

If you're on a Mac machine, updating to the latest version of the software (macOS High Sierra) is enough to squash the vulnerability. For more details about how the security vulnerability works and how to guard against an attack, see the Duo Labs blog.

  • Risk less by shelling out for one of the cheap laptops we’ve found
David Nield
Freelance Contributor

Dave is a freelance tech journalist who has been writing about gadgets, apps and the web for more than two decades. Based out of Stockport, England, on TechRadar you'll find him covering news, features and reviews, particularly for phones, tablets and wearables. Working to ensure our breaking news coverage is the best in the business over weekends, David also has bylines at Gizmodo, T3, PopSci and a few other places besides, as well as being many years editing the likes of PC Explorer and The Hardware Handbook.

Latest in Computing Security
Dark Web monitoring
How users benefit from Dark Web monitoring
The X logo next to a silhouette of Elon Musk
Who was really behind the massive X cyberattack? Here’s what experts say about Elon Musk’s claims
A person holding a phone looking at a scam text with warning signs around
A massive SMS toll fee scam is sweeping the US – here’s how to stay safe, according to the FBI
View on National Assembly building in Paris, France, with French and European flags flying.
France rejects controversial encryption backdoor provision
ensure data security for your business
The complete data protection system for your business
ignal messaging application President Meredith Whittaker poses for a photograph before an interview at the Europe's largest tech conference, the Web Summit, in Lisbon on November 4, 2022.
"We will not walk back" – Signal would rather leave the UK and Sweden than remove encryption protections
Latest in News
Open AI
OpenAI unveiled image generation for 4o – here's everything you need to know about the ChatGPT upgrade
Apple WWDC 2025 announced
Apple just announced WWDC 2025 starts on June 9, and we'll all be watching the opening event
Hornet swings their weapon in mid air
Hollow Knight: Silksong gets new Steam metadata changes, convincing everyone and their mother that the game is finally releasing this year
OpenAI logo
OpenAI just launched a free ChatGPT bible that will help you master the AI chatbot and Sora
NetSuite EVP Evan Goldberg at SuiteConnect London 2025
"It's our job to deliver constant innovation” - NetSuite head on why it wants to be the operating system for your whole business
Monster Hunter Wilds
Monster Hunter Wilds Title Update 1 launches in early April, adding new monsters and some of the best-looking armor sets I need to add to my collection