A security report published in October 2020 described a physical-access attack against Intel Macs with Apple’s T2 Security Chip, using a Boot ROM exploit and a separate vulnerability to reach the T2 environment. The report called the issue “unpatchable” because it involved code stored in read-only chip ROM. That label does not mean every T2 Mac can be attacked remotely, or that the attack automatically decrypts a Mac’s files.
What the reported T2 vulnerability is
On October 6, 2020, MacRumors reported that security researcher Niels Hofmans described a chain combining checkm8, which targets Boot ROM, with another vulnerability credited to Pangu. According to that report, the second issue bypassed a check in DFU mode and allowed access to the T2 environment. These are claims attributed to the researcher through MacRumors, not an Apple confirmation. MacRumors’ October 2020 report
Apple’s Platform Security guide describes the T2 boot process: the chip starts from Boot ROM, verifies iBoot, checks T2 kernel and kernel-extension code, and verifies Intel UEFI firmware before the Intel processor continues its boot chain. Apple’s 2018 overview also describes the T2 as providing Secure Enclave functions, internal storage encryption, and secure boot. This architecture explains why access to the chip’s early boot environment matters, but Apple’s documentation does not confirm or remediate the specific reported exploit. Apple Platform Security: Boot process for a Mac with the Apple T2 Security Chip · Apple T2 Security Chip Security Overview
Is my T2 Mac vulnerable?
The 2020 report concerned Intel Macs equipped with the T2 Security Chip. It did not provide a complete model-by-model list, nor does the evidence cited here establish current exploitation rates or how often the attack succeeds. It should not be generalized to Macs without a T2 chip or to later Apple silicon generations.
#1 Best Overall
The attack described in the report required physical access and attached hardware; a malicious USB-C cable was given as an example of a possible component. It was not described as an internet-based remote exploit. MacRumors’ October 2020 report
Can this hack decrypt FileVault?
The report did not claim that the exploit directly decrypts FileVault 2 data. Instead, it said an attacker who had gained access could potentially capture a password when a user entered it at the keyboard to unlock the encrypted files. The distinction matters: the reported risk involved obtaining a credential through user input, not automatically breaking FileVault encryption. The report also said Activation Lock could be bypassed; that is a reported capability, not evidence of prevalence or remote access. MacRumors’ October 2020 report
Rank #2
Why was it called “unpatchable”?
MacRumors’ description of the attack said the relevant SepOS code was stored in read-only T2 ROM. Ordinary software updates can change installed software, but they are not shown in these sources to rewrite code fixed in the chip’s ROM. “Unpatchable” therefore characterizes the reported hardware-rooted flaw; it is not a claim that every attack succeeds or that all data is exposed. MacRumors’ October 2020 report
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Does restoring the Mac in DFU mode fix it?
Apple says that restoring a device after putting it in DFU mode returns it to a known-good state with unmodified Apple-signed code. That describes the restored software state. It does not say that a DFU restore changes the T2 Boot ROM or fixes the specific issue reported in 2020. The cited sources likewise do not establish that a routine macOS update or a particular cable or accessory patches the ROM issue. Apple Platform Security: Boot process for a Mac with the Apple T2 Security Chip
Quick Recap
Rank #4
What owners and administrators can take from the report
- Protect physical access. Since the described chain required hands-on access and attached hardware, prevent unauthorized access to the Mac and its connections. The cited sources do not establish a consumer setting or product that eliminates the reported ROM issue.
- Separate software recovery from a ROM fix. A restore can return software to Apple-signed code, but the cited Apple guidance does not claim it rewrites T2 ROM.
- Keep the scope precise. The report describes Intel Macs with T2, a physical-access chain, and possible credential capture—not a remote attack or direct FileVault decryption.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

