Apple’s MacBook line is generally praised for its refined hardware and long period of software support. Although Apple does not officially give a binding software support schedule for MacBooks, a review of past trends shows that the company offers approximately five to eight years of macOS updates for new MacBooks. This is a perfectly safe time to use your MacBook because you benefit from new features, bug fixes, and security patches. But what happens after Apple announces a new version of macOS, like macOS 27 Golden Gate, and your MacBook no longer receives the latest operating system updates? Is it still safe to continue using your MacBook? Well, generally speaking, yes, it is largely safe, but only for a limited period of time and with one caveat.
Once Apple stops delivering new features and operating system updates to MacBooks, it doesn’t completely abandon support for them. The company still releases security patches for the previous two or three versions of macOS, even after a newer version launches. This security support typically lasts about two more years, after which most MacBooks won’t receive anything. However, in some cases, Apple released security patches in the third year. For example, MacBooks running macOS Monterey were receiving security patches well over two years after macOS Ventura was released. Even so, nothing beyond the official support window for a particular version of macOS is guaranteed.
What makes a MacBook unsafe after it no longer receives security patches?
One of the main reasons to avoid using a MacBook after it has stopped receiving security patches is that it is at risk of being targeted by malware or other actions by bad actors. In one notable example from 2021, a probable state-sponsored attack targeted visitors to Hong Kong political and media websites using an XNU kernel privilege escalation flaw in macOS Catalina and Mojave. The same flaw was not present in macOS Big Sur. However, for users of older versions at the time, it was a problem because their MacBooks were no longer supported and did not receive the new version. Although Apple patched the flaw after Google’s Threat Analysis Group (TAG) reported it, MacBooks with Catalina and Mojave remained at risk until the patch was deployed.
Attackers can also sometimes monitor zero-day vulnerabilities patched in newer versions of macOS, then use these vulnerabilities to target older versions that don’t receive patches. These are called N-day vulnerabilities. Even in the case of the previously mentioned Hong Kong attack, an N-day vulnerability was used.
All of this makes it quite dangerous to continue using a completely unsupported MacBook. Additionally, while you may be safer if your MacBook still receives security patches after the support period, there is a small risk during the period between when a serious vulnerability is actively exploited and Apple fixes it. Depending on your risk tolerance and risk profile, you can choose to upgrade to a new MacBook immediately after it no longer receives major versions of macOS or wait until it no longer receives security patches.
