Skip to content

A12 & A13 Apple devices face an unpatchable SecureROM vulnerability

Security researchers have published a new unpatchable SecureROM exploit for Apple’s A12 and A13 chips, extending public BootROM exploitation beyond the devices affected by checkm8.

Blue iPhone standing upright on a wooden surface, showing its rear camera and Apple logo, with a white smart speaker and small warm lights blurred in the backgroundiPhone XR

Security firm Paradigm Shift disclosed the unpatched exploit, called usbliter8, on June 18. It achieves code execution through a flaw in Apple’s USB boot process.

The vulnerability affects devices powered by Apple’s A12 and A13 chips, including the iPhone XS, iPhone XS Max, iPhone XR, and iPhone 11 lineup. Several iPad models and Apple Watch devices powered by S4 and S5 chips are affected as well.

Usbliter8 combines a hardware flaw in a USB controller with the way security protections are configured on affected devices. The attack works through Device Firmware Update mode, better known as DFU mode.

Continue Reading on AppleInsider | Discuss on our Forums