Blog

Thunderbolt Vulnerability Could Allow Hackers Access

By Mersad • March 29, 2019

A new vulnerability was revealed to the world at the 2019 NDSS security conference. It's a grim one with the potential to impact FreeBSD, Linux, Windows and Mac systems worldwide.


Dubbed 'Thunderclap,' the flaw can be exploited to impact the way that Thunderbolt-based peripherals connect and interact with a target system.


If you're not familiar with Thunderbolt, it's a hardware interface jointly designed by Intel and Apple that allows users to connect peripherals like chargers, keyboards, video projectors (and the like) to computers. The interface was originally available only in the Apple ecosystem, but subsequent generations of Thunderbolt expanded its reach. These days, Thunderbolt has hooks in every major OS in use today.


At a high level, Thunderclap is nothing more than a union of various security flaws found in the interface. The main flaw stems from the fact that OS's tend to implicitly trust any newly connected device, granting it access to all system memory. A hacker attacking a system using this exploit can even bypass a system's IOMMU (Input-Output Memory Management Unit), which is specifically designed to counter such threats.


Research conducted jointly at the University of Cambridge, SRI International, and Rice University discovered Thunderclap in late 2016. They have been quietly sounding the alarm since. Unfortunately, the companies that design and sell operating systems have been slow to act, in a classic case of passing the buck. The most common reason for failing to act is that the OS vendors say the responsibility lies on the peripheral side and vice versa.


The issue is finally getting the attention it deserves, but to date, none of the OS development companies have published a timeframe for when they'll be issuing a patch to cover the security flaw. Until that happens, the best thing you can do is to disable Thunderbolt ports via your system's BIOS.


Used with permission from Article Aggregator

Related Posts

By BayPointe Technology • October 7, 2026
Learn what secure remote IT support requires, from trusted help requests and controlled access to device standards, session records, and onsite escalation.
By BayPointe Technology • September 30, 2026
Find out whether your business backups can support recovery. Plan restore tests, measure results, and address gaps before an outage disrupts work.
By BayPointe Technology • September 23, 2026
Help employees recognize phishing emails, verify unusual requests, and report concerns with a practical process for Northeast Ohio businesses.
Stressed man at desk with hand on face, holding glasses near a computer and moving boxes
By BayPointe Technology • September 16, 2026
Recurring IT issues, growing support demands, or unclear security responsibilities? Learn when your Northeast Ohio business should consider managed IT services.
Blue illuminated curved metal structure with repeating ribbed arches
By BayPointe Technology • September 9, 2026
Plan office-move IT tasks, including internet installation, cabling, phones, equipment, vendor coordination, and opening-day readiness checks.

Contact Information

1035 Medina Rd, Suite #800

Medina, OH 44256