Is it too theoretical how a hacker would do that? As in would it require some very rare 0-day vulnerability which might not exist currently? Or are there known ways how a hacker would be able to flash malware into these components such as the embedded controller or cam?
The reason I ask is because I've heard from people in cyber security saying two arguments: yes it's possible, no it's too theoretical or "way too unlikely". So which is it? No one has actually tried explaining their answer or linking to any source. Answers are always vague.
I think it's important to have these answer because when it comes to firmware security, it makes a huge different if all you need to do is to flash the boot rom to ensure your firmware is uncompromised. That would make security 1000 times easier. But if it's not enough then you would maybe have to Unfortunately throw away the computer if you think there's compromised firmware because you won't be able to get rid of it.
Don't forget to explain your answer. Please give link to source and further reading about this.
Just because something is possible doesn't mean it's likely that an attacker would burn a 0-day against you though.
If you want a case study, BlackLotus is a good starting point.
https://www.eset.com/au/about/newsroom/press-releases1/eset-...
I don't think there's a public working exploits (yet?), but it can "likely" in some cases (depending on the DIMMS you have installed) be done without hardware access, purely through software:
"In some cases, with certain DIMM models that don't adequately lock down the chip, the modification can likely be done through software."
https://arstechnica.com/information-technology/2024/12/new-b...
So yeah, it's possible for a hacker to flash malware onto your DIMMs...
(Whether that's a thing you need to care about is a good question. This isn't something a driveway script kiddie is gonna do after he p0wns your WordPress site with vulnerable plugins. But if you're running a dark web drug market on commercially hosted cloud servers and a powerful enough Three Letter Agency becomes intersted in you...)