It sounds like unsigned Option ROMs are an even bigger problem. If anything, UEFI provides an effective defense via Secure Boot. Sadly, Apple doesn't currently implement this feature -- at a minimum, they'd need to upgrade from EFI 1.10 to UEFI 2.3 to even be able to consider it.