TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Mac EFI Update 2015-001: malicious root app may be able to modify EFI flash

1 pointsby SchizoDuckiealmost 10 years ago

1 comment

SchizoDuckiealmost 10 years ago
Related CVE:<p><a href="http:&#x2F;&#x2F;www.kb.cert.org&#x2F;vuls&#x2F;id&#x2F;577140" rel="nofollow">http:&#x2F;&#x2F;www.kb.cert.org&#x2F;vuls&#x2F;id&#x2F;577140</a><p>Applies to (at least) some DELL computers as well.<p>TLDR: There&#x27;s a bug in some UEFI BIOSes that don&#x27;t set the read-only flag when a computer comes back from sleep, thus allowing a malicious program to silently reflash the BIOS<p>More detailed analysis: <a href="https:&#x2F;&#x2F;reverse.put.as&#x2F;2015&#x2F;05&#x2F;29&#x2F;the-empire-strikes-back-apple-how-your-mac-firmware-security-is-completely-broken&#x2F;" rel="nofollow">https:&#x2F;&#x2F;reverse.put.as&#x2F;2015&#x2F;05&#x2F;29&#x2F;the-empire-strikes-back-ap...</a>