Skip to main content

A brand-new Mac can be hacked remotely during its first Wi-Fi connection

Apple MacBook-review-lid
Bill Roberson/DIgital Trends

If you’re using a company-issued Mac running a version of Apple’s operating system prior to MacOS High Sierra 10.13.6, you will want to tell your system administrator to upgrade your OS to the latest version. At the Black Hat security conference in Las Vegas, researchers demonstrated a method where a malicious actor could remotely take control of a new Mac due to vulnerabilities with Apple’s corporate Device Enrollment Program (DEP) and Mobile Device Management (MDM) tools.

A new Mac could be compromised when it connects to a Wi-Fi network, security officer Jesse Endahl from Fleetsmith and Dropbox staff engineer Max Belanger discovered. Apple has since patched the security flaw last month when it released the MacOS 10.13.6 software update, so companies will want to migrate their Mac fleet to the latest software and not issue employees a Mac with a prior version of the OS out of the box.

“We found a bug that allows us to compromise the device and install malicious software before the user is ever even logged in for the very first time,” Endahl told Wired. “By the time they’re logging in, by the time they see the desktop, the computer is already compromised.”

Typically, when you begin setting up a Mac, the device communicates with Apple’s servers to identify itself. If Apple’s server recognizes that the Mac’s serial number is registered with the DEP, it will initiate an MDM configuration sequence. Most companies hire a Mac management firm, like Fleetsmith, to help facilitate MDM provisioning to allow Macs to download the necessary programs required by the company. For security, Apple employs certificate pinning to identify web servers, but when the MDM hands off to the Mac App Store to download enterprise apps, “the sequence retrieves a manifest for what to download and where to install it without pinning to confirm the manifest’s authenticity,” Wired reported.

This opens up a vulnerability where a malicious hacker could replace the original manifest with a malicious one. When this happens, the computer could be instructed to download malware, like keyloggers, spyware, cryptojacking software, or software that could monitor the corporate network and spread itself to other devices. “And once a hacker has set up the attack, it could target every single Apple computer a given company puts through the MDM process,” Wired said.

Though the attack cannot be easily pulled off, it still represents a dangerous vulnerability given that hackers can just target one Mac to gain entry into an entire corporate network. “The attack is so powerful that some government would probably be incentivized to put in the work to do it,” Endahl said.

Editors' Recommendations

Chuong Nguyen
Silicon Valley-based technology reporter and Giants baseball fan who splits his time between Northern California and Southern…
The MacBook Air 15 vs. MacBook Pro 14: the easy way to decide
Apple's 15-inch MacBook Air placed on a desk with its lid closed.

Picking out a new MacBook isn't as easy as it used to be.

The hardest choice in the lineup might be between the 15-inch MacBook Air and the 14-inch MacBook Pro. Both are now offered with the same M3 chip, despite there being a $300 difference in the base models. But when similarly configured, there's actually only a $100 difference between these two laptops.

Read more
I needed to buy a new MacBook. Here’s why I bought a power bank instead
Baseus Blade 2 65W power bank for laptops kept on a green couch.

I rely on a 13-inch MacBook Pro from 2020 for most of my work. Despite its age and being a base variant model, it continues to stack up well against my expectations for all these years.

Since MacBooks are known for longevity, the fact that my MacBook Pro still holds up well a few years later shouldn't sound surprising. However, the first signs of aging recently arrived in the form of a warning about the battery's plummeting health. I was already dreading the idea of having to replace what was otherwise a perfectly good laptop.

Read more
Why gaming on the M3 MacBook Air has left me impressed
Baldur's Gate 3 being played on the M3 MacBook Air.

Upon getting the new MacBook Air M3 in my possession, I had one major question: Can you play games on it?

That might sound like a silly first thought for a laptop of this type. After all, it's not marketed as a gaming laptop -- it's an incredibly thin, fanless laptop. Not exactly something even meant for any high-performance tasks.

Read more