Skip to main content

A brand-new Mac can be hacked remotely during its first Wi-Fi connection

Apple MacBook-review-lid
Bill Roberson/DIgital Trends

If you’re using a company-issued Mac running a version of Apple’s operating system prior to MacOS High Sierra 10.13.6, you will want to tell your system administrator to upgrade your OS to the latest version. At the Black Hat security conference in Las Vegas, researchers demonstrated a method where a malicious actor could remotely take control of a new Mac due to vulnerabilities with Apple’s corporate Device Enrollment Program (DEP) and Mobile Device Management (MDM) tools.

A new Mac could be compromised when it connects to a Wi-Fi network, security officer Jesse Endahl from Fleetsmith and Dropbox staff engineer Max Belanger discovered. Apple has since patched the security flaw last month when it released the MacOS 10.13.6 software update, so companies will want to migrate their Mac fleet to the latest software and not issue employees a Mac with a prior version of the OS out of the box.

“We found a bug that allows us to compromise the device and install malicious software before the user is ever even logged in for the very first time,” Endahl told Wired. “By the time they’re logging in, by the time they see the desktop, the computer is already compromised.”

Typically, when you begin setting up a Mac, the device communicates with Apple’s servers to identify itself. If Apple’s server recognizes that the Mac’s serial number is registered with the DEP, it will initiate an MDM configuration sequence. Most companies hire a Mac management firm, like Fleetsmith, to help facilitate MDM provisioning to allow Macs to download the necessary programs required by the company. For security, Apple employs certificate pinning to identify web servers, but when the MDM hands off to the Mac App Store to download enterprise apps, “the sequence retrieves a manifest for what to download and where to install it without pinning to confirm the manifest’s authenticity,” Wired reported.

This opens up a vulnerability where a malicious hacker could replace the original manifest with a malicious one. When this happens, the computer could be instructed to download malware, like keyloggers, spyware, cryptojacking software, or software that could monitor the corporate network and spread itself to other devices. “And once a hacker has set up the attack, it could target every single Apple computer a given company puts through the MDM process,” Wired said.

Though the attack cannot be easily pulled off, it still represents a dangerous vulnerability given that hackers can just target one Mac to gain entry into an entire corporate network. “The attack is so powerful that some government would probably be incentivized to put in the work to do it,” Endahl said.

Editors' Recommendations

Chuong Nguyen
Silicon Valley-based technology reporter and Giants baseball fan who splits his time between Northern California and Southern…
Major leak reveals every secret Mac Apple is working on
Apple's John Ternus stands next to an image of the 15-inch MacBook Air at Apple's Worldwide Developers Conference (WWDC) in June 2023.

At Apple’s Worldwide Developers Conference (WWDC) in early June, the focus was almost entirely on the company’s Vision Pro headset. But Apple has plenty more up its sleeve, according to a new report, which has spilled the beans on every single Mac we can expect to see in the coming months.

The report comes from journalist Mark Gurman, who accurately predicted a plethora of details about the Vision Pro before it was announced. Now, he says Apple has a few surprise Mac announcements in store for late 2023 or early 2024.

Read more
There’s a MacBook that Apple has no right to continue selling
A stack of MacBooks is pictured from the top down.

With the launch of the new 15-inch MacBook Air, Apple has solidified its most fleshed-out Mac lineup in recent memory. There's a MacBook for almost every conceivable budget and use case, ranging from the $999 M1 MacBook Air up to the upper echelons of the 16-inch MacBook Pro.

Considering how well the 15-inch MacBook Air has been received in early reviews, there doesn't appear to be a bad choice in the mix. That is, until you stumble upon the MacBook hidden in the lineup that Apple has continued to sell for absolutely no reason. I'm referring to the 13-inch MacBook Pro, of course.

Read more
There’s great news if you want to buy Apple’s 15-inch MacBook Air
Apple's John Ternus stands next to an image of the 15-inch MacBook Air at Apple's Worldwide Developers Conference (WWDC) in June 2023.

When Apple launched the 15-inch MacBook Air at its Worldwide Developers Conference (WWDC), it seemed like there wasn’t too much separating it from its 13-inch sibling. Yet a new set of tests has shown that the larger model pulls ahead in some key ways, making it a much more attractive purchase if you want maximum performance in a slimline laptop.

The testing was conducted by YouTuber Max Tech, who pitted the 15-inch MacBook Air against Apple’s smaller 13-inch version. Both laptops had the M2 chip and 256GB of storage, so you might think the only difference would be found in the size of the displays. Yet that’s not how the testing played out at all.

Read more