Apple Laptop Batteries Hacked By Researcher

  /     /     /  
Publicated : 22/11/2024   Category : security


Apple Laptop Batteries Hacked By Researcher


Attackers could use a password weakness to render your laptops battery useless--or overcharge it to start a fire, researcher warns.



(click image for larger view)
Slideshow: Building The Mac Office
Attackers could turn your laptops battery into a useless brick, or worse, overcharge it to the point where it starts a fire.
That warning comes by way of security expert Charlie Miller, who said that hes successfully reverse-engineered Apple laptop smart batteries, enabling him to reprogram their embedded controllers. Miller, whos a researcher at consultancy Accuvant, plans to document his research at next months
Black Hat conference
in Las Vegas.
According to Millers Black Hat
talk description
, being able to control the working smart battery and smart battery host may be enough to cause safety issues, such as overcharging or fire. Notably, when the lithium-ion batteries used in laptops overheat, they can rupture,
causing injuries
. On the other hand, well-manufactured batteries also include
numerous safety features
, such as the ability to shut down in the event of overheating, as well as circuit interrupters designed to prevent overcharging or undercharging.
In his forthcoming talk, Miller plans to will demonstrate how to modify the firmware used by Apple smart batteries, disable their anti-tampering checksum, and reprogram the battery firmware using a simple API, which he plans to release publicly. While Millers research focused on MacBook, MacBook Pro, and MacBook Air laptops from Apple--with whom hes already shared the results of his research--he suspects that Windows laptop batteries would be susceptible to firmware attacks.
Miller reverse-engineered Apples battery firmware after the company issued a related firmware update in 2009. From there, he discovered the default password used to secure batteries, and from there, he learned how to read the values from that firmware and alter how the battery firmware interacts with the laptop. To date, Miller said hes successfully bricked seven Mac laptops via battery firmware hacks.
Interestingly, however, reprogramming the battery firmware could also allow an attacker to introduce persistent malware into the laptop. You could put a whole hard drive in, reinstall the software, flash the BIOS, and every time it would reattack, Miller
told Forbes.com
. There would be no way to eradicate or detect it other than removing the battery.
Despite the apparent threat vector, battery firmware offers essential functionality, providing giving users precise readings of a laptops remaining charge, operating time, and estimated recharge time, while also allowing the battery to control the voltage and current being provided by a charger.
But how feasible are attacks against battery firmware? Offering some perspective, Paul Ducklin, head of technology for Sophos in the Asia Pacific region, said in a
blog post
that when it comes to reprogramming controllers with field-updatable firmware, laptop batteries arent the only option. Indeed, an attacker could also target the motherboard itself, your wireless card, your 3G modem, network card,
graphics device
, storage devices, and much more, he said.
To address the Apple laptop battery firmware vulnerability, Miller plans to release a utility called Caulkgun that will allow Apple users to change their laptop battery passwords. On the upside, the utility would prevent an attacker from exploiting an Apple battery packs embedded controller. On the downside, it would block any Apple patches, performance enhancements, or security updates from updating the batterys firmware, unless the user first restored the batterys default password.
The vendors, contractors, and other outside parties with which you do business can create a serious security risk. Heres how to keep this threat in check. Also in the new, all-digital issue of Dark Reading: Why focusing solely on your own companys security ignores the bigger picture.
Download it now
. (Free registration required.)

Last News

▸ New threat discovered: Mobile phone ownership compromised. ◂
Discovered: 23/12/2024
Category: security

▸ Some DLP Products Vulnerable to Security Holes ◂
Discovered: 23/12/2024
Category: security

▸ Scan suggests Heartbleed patches may not have been successful. ◂
Discovered: 23/12/2024
Category: security


Cyber Security Categories
Google Dorks Database
Exploits Vulnerability
Exploit Shellcodes

CVE List
Tools/Apps
News/Aarticles

Phishing Database
Deepfake Detection
Trends/Statistics & Live Infos



Tags:
Apple Laptop Batteries Hacked By Researcher