Home / Software & Gaming / Security / Study finds that 4.2% of Macs were running vulnerable firmware, issue fixed in High Sierra

Study finds that 4.2% of Macs were running vulnerable firmware, issue fixed in High Sierra

Just a few days ago, a password stealing vulnerability was discovered in macOS just as the latest version began rolling out. Apple is already addressing this but it seems that a new security issue has also come to light, after a study found that 4.2 percent of Macs were running the wrong firmware, leaving them open to exploits.

Duo Security conducted a study of 73,000 Macs running out in the wild, finding that 4.2 percent, or just over 3000 of them, were running the wrong firmware version. This leaves them open to Thunderstrike, an attack that can be used to rewrite macOS firmware using a malware ridden Thunderbolt device. The attacker would need physical access to the Mac in order to achieve this, so it isn’t necessarily a concern for regular consumers, but it could be more concerning for enterprise or even government agency users.

Apple regularly rolls out security updates for Macs but for some reason, it seems firmware versions weren’t always updated as they should have been. Here is what the paper says: “At least 16 models received no EFI updates at all. EFI updates for other models were inconsistently successful, with the 21.5-inch iMac released in late 2015 topping the list, with 43 percent of those sampled running the wrong version.”

In a statement given to ArsTechnica, Apple said that High Sierra should fix this issue entirely, as weekly firmware checks have been implemented with the latest update. With that in mind, Mac users wanting to remain secure should update to the latest version as soon as possible.

KitGuru Says: Apple tends to be very diligent when it comes to user security. We are still unsure why old Mac models were unsuccessful in updating their firmware with new patches, but it seems the High Sierra update should fix that for everyone going forward. Are any of you using macOS at the moment? Have you tried the High Sierra update yet?

Become a Patron!

Check Also

Chinese Steam

Valve confirms Steam has not suffered a data breach

This week, someone claimed to have breached Valve's Steam servers, coming away with account information for over 89 million users. Something seemed a bit fishy about the claim at the time, but now, Valve has confirmed that no data breach has taken place.

We've noticed that you are using an ad blocker.

Thank you for visiting KitGuru. Our news and reviews teams work hard to bring you the latest stories and finest, in-depth analysis.

We want to be as informative as possible – and to help our readers make the best buying decisions. The mechanism we use to run our business and pay some of the best journalists in the world, is advertising.

If you want to support KitGuru, then please add www.kitguru.net to your ad blocking whitelist or disable your adblocking software. It really makes a difference and allows us to continue creating the kind of content you really want to read.

It is important you know that we don’t run pop ups, pop unders, audio ads, code tracking ads or anything else that would interfere with the KitGuru experience. Adblockers can actually block some of our free content, such as galleries!