Thunderclap hack makes Macs and PCs with Thunderbolt ports vulnerable

Thunderclap
Image Credit: TechRadar

If you’ve bought a recently released MacBook, Windows laptop or really any PC equipped with a Thunderbolt port, there’s a new vulnerability you should watch out for.

The new vulnerability has been dubbed Thunderclap and it could leave computers open to serious attacks such as running malicious code on your system. This is on top of the usual, unwarranted access to important data like passwords, encryption keys and any other sensitive data stored on your system.

It’s really bad news mainly because Thunderbolt’s protocols are designed with OS-level access and direct-memory access (DMA) to support high-speed data transfer, video out and its other myriad features. This vulnerability takes advantage of all that high-level access to do more harm.

According to the group of researchers that announced Thunderclap at the Network and Distributed System Security Symposium in San Diego, the Thunderclap vulnerability won’t just affect the latest machines equipped with Thunderbolt 3, but older devices that provide Thunderbolt connectivity through DisplayPort instead of USB-C. 

Thunderclap will specifically affect “all Apple laptops and desktops produced since 2011 are vulnerable, with the exception of the 12-inch MacBook. Many laptops, and some desktops, designed to run Windows or Linux produced since 2016 are also affected." 

How to stay protected from Thunderclap

Now the good news is the team of researchers discovered the problem in 2016 and have been working with manufacturers to develop fixes ever since. 

MacBooks and other Apple computers running at least macOS 10.12.4 should be partially protected from the bug and newer updates should provide even better protection. Meanwhile, Windows 10 version 1803 provides firmware level protection for devices.

The best way to protect yourself from being Thunderclap-ped is to immediately update any computers you have with the latest version of their respective operating systems. Users who want that extra layer of protection can also disable Thunderbolt protocols in your computer's BIOS or UEFI settings.

For the most part, this probably won’t be a vulnerability that will affect most users as it can only be introduced directly through a device’s Thunderbolt port. Most users should be safe just by being vigilant about what they plug into their devices. 

Via The Verge

TOPICS
Kevin Lee

Kevin Lee was a former computing reporter at TechRadar. Kevin is now the SEO Updates Editor at IGN based in New York. He handles all of the best of tech buying guides while also dipping his hand in the entertainment and games evergreen content. Kevin has over eight years of experience in the tech and games publications with previous bylines at Polygon, PC World, and more. Outside of work, Kevin is major movie buff of cult and bad films. He also regularly plays flight & space sim and racing games. IRL he's a fan of archery, axe throwing, and board games.

Latest in Cyber Crime
A person scanning a QR code on a smartphone
Quishing is the new QR code scam you need to watch out for – here's how to stay safe
Ransomware on the rise: how small and medium-sized businesses can achieve cyber resilience during turbulent times
Ransomware on the rise: how small and medium-sized businesses can achieve cyber resilience during turbulent times
Text Phishing Scams
Do not fall for this dangerous Amazon shopping scam
Cyber-security
Safeguarding against next-gen cyber risks
The North Face jacket
Thousands of North Face customers accounts hacked, personal data stolen
Smartphone hacked with data flow in the background
9 signs your phone has been hacked
Latest in News
iPad Air M3
Apple makes one hardware change to the iPad Air that might be the best indicator of its true lightweight tablet intentions
An operator fires a saw blade from a weapon
Call of Duty: Black Ops 6 Season 3 gets two-week delay, will now release in April
Apple iPad A16
Apple's new entry-level iPad ups the performance for the same price, but doesn't support Apple Intelligence
iPad Air M3
Apple updates iPad Air with powerful M3 chip and pairs it with Pro-level Magic Keyboard
Samsung Galaxy Z Flip 6 in blue
The Samsung Galaxy Z Flip 7 might improve on its predecessor in one crucial way
Nvidia RTX 5070 Founders Edition GPU shown against a green and black backdrop
Nvidia RTX 5070 early pricing hints at plenty of GPUs at the MSRP – but I’ll believe it when I see it