Thunderbolt bugs can expose your PC if you leave it alone with a hacker

Most modern laptops are affected.
 By 
Stan Schroeder
 on 
Thunderbolt bugs can expose your PC if you leave it alone with a hacker
Thunderbolt is practical, but problematic from a security standpoint. Credit: Dustin drankoski/mashable

Thunderbolt ports may put your PC in jeopardy, but only if you leave it alone with a capable and well-prepared hacker.

That's according to security researcher Björn Ruytenberg from the Eindhoven University of Technology, who outlined seven vulnerabilities in Thunderbolt, collectively called Thunderspy, in a recent paper (via Wired). The vulnerabilities are serious — a hacker who knows what they are doing could gain full access to data on a laptop that's locked and encrypted.

Laptops made before 2019 with Thunderbolt ports running Windows and Linux are vulnerable. Macs built before 2019 are a little safer, as an attacker would have to use another attack in conjunction with Thunderspy to gain access. The researcher claims the bugs cannot be fixed via a software update.


You May Also Like

Pulling off the attack isn't easy, though. The hacker needs physical access to the machine, so they can unscrew it and attach a device to it (see Ruytenberg's video below).

Thunderbolt is a practical hardware interface as it allows for high-speed data transfer as well as charging, and it's compatible with USB-C. It was first introduced on Apple's MacBook Pro in 2011.

Thunderbolt is Intel's standard, and the company issued a response Sunday, claiming that a new security scheme called Kernel Direct Memory Access (DMA) has been implemented since 2019, protecting from these types of attacks. In his paper, Ruytenberg says that "systems supporting Kernel DMA Protection in place of Security Levels, released from 2019 onward, are currently subject to further investigation."

Thunderbolt came under scrutiny in 2019, when security experts outlined a number of security vulnerabilities under the collective name Thunderclap, which also allow attackers with physical access to a PC to compromise its security. It's worth noting that Microsoft's recently launched Surface devices do not support Thunderbolt, allegedly due to security concerns.

Topics Cybersecurity

Stan Schroeder
Stan Schroeder
Senior Editor

Stan is a Senior Editor at Mashable, where he has worked since 2007. He's got more battery-powered gadgets and band t-shirts than you. He writes about the next groundbreaking thing. Typically, this is a phone, a coin, or a car. His ultimate goal is to know something about everything.

Mashable Potato

Recommended For You

Huge shakeup at Xbox as CEO and president both leave
Xbox Series X console and controller

Save over $15 on the Lego Ideas The Insect Collection right now at Walmart
lego ideas the insect collection set against a pink and purple patterned background

Hacker says he accidentally breached 7,000 DJI robot vacuums with a PS5 controller
DJI Romo robot vacuum driving toward dock, tinted blue and red

Apple responds to DarkSword spyware, the hacker tool targeting iPhones
Apple logo on iPhone

Trending on Mashable
NYT Connections hints today: Clues, answers for April 3, 2026
Connections game on a smartphone

Wordle today: Answer, hints for April 3, 2026
Wordle game on a smartphone

NYT Connections hints today: Clues, answers for April 4, 2026
Connections game on a smartphone

Google launches Gemma 4, a new open-source model: How to try it
Google Gemma

Wordle today: Answer, hints for April 4, 2026
Wordle game on a smartphone
The biggest stories of the day delivered to your inbox.
These newsletters may contain advertising, deals, or affiliate links. By clicking Subscribe, you confirm you are 16+ and agree to our Terms of Use and Privacy Policy.
Thanks for signing up. See you at your inbox!