Vulnerabilità · 99 giorni fa
La premessa che SecureROM e la boot chain firmata chiudano davvero il perimetro di fiducia non regge più su questi chip. Se un attaccante ottiene il dispositivo in custodia fisica e lo porta in DFU mode, il limite di trust può essere superato prima che parta il sistema operativo; a quel punto, una patch non può più rimuovere il difetto perché il bug vive nel boot ROM.
Paradigm Shift ha pubblicato un proof of concept funzionante, usbliter8, per l'esecuzione di codice arbitrario in SecureROM su Apple A12, A13, S4 e S5. Il bug sta nella gestione dei pacchetti USB in DFU mode e colpisce dispositivi come iPhone XS, XR e 11, Apple Watch Series 4 e 5, HomePod mini e altri prodotti basati su quegli SoC; A11 non è colpito e A14 e successivi risultano fuori portata.
Per chi gestisce flotte Apple, il rischio non è un incidente software da correggere al prossimo rilascio. È un problema di custodia persistente: se un dispositivo finisce nelle mani sbagliate, anche per poco, il suo trust root può risultare compromesso per tutta la vita utile dell'hardware.
4 fonti che coprono questa storia
A new unpatchable flaw in Apple chips opens the door to an iPhone jailbreak | TechCrunch
European offensive cybersecurity company Paradigm Shift released details of a flaw and a technique to exploit it that opens the door for hackers to unlock and break into older iPhones.
Unpatchable BootROM Flaw Impacts Apple A12, A13 Chips
Apple BootROM exploit exposes unpatchable USB flaw on A12 and A13 devices
New Exploit Bypasses Apple’s Boot Defenses, Affects Millions of iPhones
The vulnerability exploited by the Usbliter8 exploit cannot be patched and a PoC exploit has been released by researchers.
Unpatchable 'usbliter8' Exploit Breaks Apple A12 and A13 SecureROM Boot Chain
Paradigm Shift’s usbliter8 exploit targets Apple A12 and A13 SecureROM via USB DFU mode, creating an unpatchable hardware risk.
Part of the PlainSec briefing for 2026-06-22