Thunderbolt (Lightning) Port Security Flaw Exposed — Computers Made Before 2019, Beware

According to foreign media, security researchers recently discovered a new security vulnerability that could make millions of computers manufactured before 2019 easily susceptible to physical attack, targeting a common component: the Thunderbolt port. According to researcher Bjorn Ruytenberg, the so-called "Thunderclap" vulnerability exploits the direct memory access (DMA) granted by Thunderbolt peripherals to access the target device. Unless proper protections are in place, hackers can use this access to steal data, track files, and run malicious code. "Hackers can read and copy data on a PC within minutes, even when the computer is locked or sleeping."

According to foreign media, security researchers recently discovered a new security vulnerability that could make millions of computers manufactured before 2019 easily susceptible to physical attack, targeting a common component: the Thunderbolt port.

According to researcher Bjorn Ruytenberg, the so-called “Thunderclap” vulnerability exploits the direct memory access (DMA) granted by Thunderbolt peripherals to access the target device. Unless proper protections are in place, hackers can use this access to steal data, track files, and run malicious code. “Hackers can read and copy data on a PC within minutes, even when the computer is locked or sleeping,” Bjorn Ruytenberg said.

Bjorn Ruytenberg said all devices shipped between 2011 and 2020 with Thunderbolt are vulnerable. In addition, devices offering Kernel DMA Protection since 2019 all have this vulnerability.

On Macs and some Windows computers, the Thunderbolt port can be used to connect peripherals such as monitors, high-speed network adapters, ordinary hard drives, and larger storage arrays. Today Thunderbolt is common on high-end Windows laptops, and it shares the same design as the newer USB-C port. Every year the number of computers with Thunderbolt doubles, and now tens of millions have been sold. Intel said the number of Thunderbolt peripherals has also doubled at the same rate, with 450 certified products on the market.

Regarding the vulnerability, Bjorn Ruytenberg advised users to only connect their own Thunderbolt peripherals and never lend them to others. “Avoid leaving the system unattended while powered on, even in lock-screen state; avoid leaving your Thunderbolt peripherals unattended; when storing systems and any Thunderbolt device, ensure proper physical security, including Thunderbolt-powered monitors,” Bjorn Ruytenberg said.