(Of course the owner of the system might still want to secure their system e.g. by digital signatures. Open source does not mean open write access.)
Citation needed, open source can just have as problematic security problems as closed source even when they are high profile.
Nobody said that open source has no security bugs. No software that does something useful is bug-free.
"Our proprietary UEFI code appears to have been leaked by a third party. We do not believe this exposes any new security vulnerabilities as we do not rely on obfuscation of information as a security measure. This code is covered under our bug bounty program within the Project Circuit Breaker campaign, and we encourage any researchers who may identify potential vulnerabilities to bring them our attention through this program. We are reaching out to both customers and the security research community to keep them informed of this situation." — Intel spokesperson.
It is almost as if they are expecting some major holes to exist and just per-emptively attempt to defuse it.
This is according to user @hardenedlinux on Twitter.
The GitHub repository that refers to has since been removed.