Skip to main content
  1. Home
  2. Computing
  3. Apple
  4. News

A brand-new Mac can be hacked remotely during its first Wi-Fi connection

Add as a preferred source on Google
Apple MacBook-review-lid
Bill Roberson/DIgital Trends

If you’re using a company-issued Mac running a version of Apple’s operating system prior to MacOS High Sierra 10.13.6, you will want to tell your system administrator to upgrade your OS to the latest version. At the Black Hat security conference in Las Vegas, researchers demonstrated a method where a malicious actor could remotely take control of a new Mac due to vulnerabilities with Apple’s corporate Device Enrollment Program (DEP) and Mobile Device Management (MDM) tools.

A new Mac could be compromised when it connects to a Wi-Fi network, security officer Jesse Endahl from Fleetsmith and Dropbox staff engineer Max Belanger discovered. Apple has since patched the security flaw last month when it released the MacOS 10.13.6 software update, so companies will want to migrate their Mac fleet to the latest software and not issue employees a Mac with a prior version of the OS out of the box.

Recommended Videos

“We found a bug that allows us to compromise the device and install malicious software before the user is ever even logged in for the very first time,” Endahl told Wired. “By the time they’re logging in, by the time they see the desktop, the computer is already compromised.”

Typically, when you begin setting up a Mac, the device communicates with Apple’s servers to identify itself. If Apple’s server recognizes that the Mac’s serial number is registered with the DEP, it will initiate an MDM configuration sequence. Most companies hire a Mac management firm, like Fleetsmith, to help facilitate MDM provisioning to allow Macs to download the necessary programs required by the company. For security, Apple employs certificate pinning to identify web servers, but when the MDM hands off to the Mac App Store to download enterprise apps, “the sequence retrieves a manifest for what to download and where to install it without pinning to confirm the manifest’s authenticity,” Wired reported.

This opens up a vulnerability where a malicious hacker could replace the original manifest with a malicious one. When this happens, the computer could be instructed to download malware, like keyloggers, spyware, cryptojacking software, or software that could monitor the corporate network and spread itself to other devices. “And once a hacker has set up the attack, it could target every single Apple computer a given company puts through the MDM process,” Wired said.

Though the attack cannot be easily pulled off, it still represents a dangerous vulnerability given that hackers can just target one Mac to gain entry into an entire corporate network. “The attack is so powerful that some government would probably be incentivized to put in the work to do it,” Endahl said.

Chuong Nguyen
Silicon Valley-based technology reporter and Giants baseball fan who splits his time between Northern California and Southern…
Google brings its best AI music model Lyria 3.5 to the Gemini app
Developers get full API access through Google AI Studio.
Google-gemini-lyria-3.5

Google has added Lyria 3.5, its most advanced music generation model yet, to the Gemini app. Previously available through Google's AI filmmaking tool Flow, the model is now rolling out to all Gemini users, making it easier to generate polished songs, instrumentals, and soundtracks from simple text prompts or even photos.

Lyria 3.5 makes AI-generated music sound more natural

Read more
AMD’s new workstation packs 576GB of GPU memory and enough horsepower for trillion-parameter AI models
AMD just built a desktop workstation with more raw memory than most small data centers had a decade ago.
People, Person, Performer

AMD just built a desktop that really has no business sitting on an actual desk. At IFA 2026, the company unveiled the Threadripper Halo Station.

As the name probably already suggests, it is a liquid-cooled machine that can run AI models with more than a trillion parameters without touching the cloud even once. If you don't already know, those numbers are reserved for server shelves, not someone's personal desk.

Read more
Why doesn’t DDR5 memory always perform the way you expect?
Electronics, Hardware, Computer Hardware

This post is brought to you in paid partnership with ASUS.

DDR5 memory doesn't always perform the way you'd expect because so much of its behavior is shaped by the platform it's running on, not the memory kit alone. A motherboard is one of the few PC components that continues to influence your system long after you've finished building it. Even after you've chosen your processor, graphics card, and memory, it continues to shape which upgrades are possible, how well new hardware behaves, and whether your PC evolves gracefully or starts showing its age before the rest of the system does.

Read more