Skip to main content

A brand-new Mac can be hacked remotely during its first Wi-Fi connection

Apple MacBook-review-lid
Bill Roberson/DIgital Trends

If you’re using a company-issued Mac running a version of Apple’s operating system prior to MacOS High Sierra 10.13.6, you will want to tell your system administrator to upgrade your OS to the latest version. At the Black Hat security conference in Las Vegas, researchers demonstrated a method where a malicious actor could remotely take control of a new Mac due to vulnerabilities with Apple’s corporate Device Enrollment Program (DEP) and Mobile Device Management (MDM) tools.

A new Mac could be compromised when it connects to a Wi-Fi network, security officer Jesse Endahl from Fleetsmith and Dropbox staff engineer Max Belanger discovered. Apple has since patched the security flaw last month when it released the MacOS 10.13.6 software update, so companies will want to migrate their Mac fleet to the latest software and not issue employees a Mac with a prior version of the OS out of the box.

Recommended Videos

“We found a bug that allows us to compromise the device and install malicious software before the user is ever even logged in for the very first time,” Endahl told Wired. “By the time they’re logging in, by the time they see the desktop, the computer is already compromised.”

Please enable Javascript to view this content

Typically, when you begin setting up a Mac, the device communicates with Apple’s servers to identify itself. If Apple’s server recognizes that the Mac’s serial number is registered with the DEP, it will initiate an MDM configuration sequence. Most companies hire a Mac management firm, like Fleetsmith, to help facilitate MDM provisioning to allow Macs to download the necessary programs required by the company. For security, Apple employs certificate pinning to identify web servers, but when the MDM hands off to the Mac App Store to download enterprise apps, “the sequence retrieves a manifest for what to download and where to install it without pinning to confirm the manifest’s authenticity,” Wired reported.

This opens up a vulnerability where a malicious hacker could replace the original manifest with a malicious one. When this happens, the computer could be instructed to download malware, like keyloggers, spyware, cryptojacking software, or software that could monitor the corporate network and spread itself to other devices. “And once a hacker has set up the attack, it could target every single Apple computer a given company puts through the MDM process,” Wired said.

Though the attack cannot be easily pulled off, it still represents a dangerous vulnerability given that hackers can just target one Mac to gain entry into an entire corporate network. “The attack is so powerful that some government would probably be incentivized to put in the work to do it,” Endahl said.

Chuong Nguyen
Silicon Valley-based technology reporter and Giants baseball fan who splits his time between Northern California and Southern…
Apple’s M4 MacBook Air combines power and portability for $999
M4 MacBook Air

Apple has just launched a new MacBook Air equipped with its M4 chip, bringing improved performance and efficiency to one of the company’s best MacBooks. The long-rumored update means that all of Apple’s laptops now come with the M4 chip.

As expected, the M4 MacBook Air is more of an evolution than a revolution. The M4 chip means a slight improvement in terms of performance compared to the previous M3 version, but there are few changes elsewhere. According to Apple, the M4 MacBook Air can perform tasks like video editing and photo editing up to 2x faster than its M1 counterpart -- so upgrading could be worth it for M1 owners.

Read more
Tim Cook just teased the M4 MacBook Air, and it’s coming this week
MacBook air graphic teaser video.

Apple CEO Tim Cook just posted a teaser to X with the caption "This week." and a six-second video showing the words "There's something in the AIR." We've been expecting the M4 MacBook Air announcement for a couple of weeks now, and with the iPhone 16e reveal out of the way, it looks like this is the week.

https://x.com/tim_cook/status/1896589954517701057

Read more
MacBook Air refresh with M4 silicon might arrive within a week
Apple's 15-inch MacBook Air seen from above and the side.

A new version of MacBook Air powered by Apple’s M4 processor is right around the corner, it seems, and might be launched within a week. “Apple is preparing to make a Mac-related announcement as early as this coming week,” reports Bloomberg, adding that the reveal is imminent.

The current-gen MacBook Air with M3 silicon was announced in the first week of March in 2024, and it seems Apple is sticking with its refresh schedule rather strictly for its popular entry-level laptop. The machine will likely arrive in 13-inch and 15-inch formats, just like its predecessor.

Read more