Vulnerabilities · 84 days ago
Physical possession now matters more than software state on affected Apple chips. On A12, A13, S4, and S5 devices, brief access in DFU mode can reach SecureROM before the signed boot chain starts, so the trust root itself is what breaks and no update can remove it.
Paradigm Shift released a working public proof of concept for the usbliter8 exploit on June 18, 2026. The flaw sits in the Synopsys DWC2 USB controller’s packet handling and can be driven through USB DFU mode to achieve arbitrary code execution inside SecureROM on affected hardware, including iPhone XS, XS Max, XR, iPhone 11, Apple Watch Series 4 and 5, and HomePod mini. A11 is not affected, and A14 and later appear out of reach for this path.
The forward risk is persistent. Any device that changes hands, enters repair, or is left briefly unattended can carry a trust-root compromise that survives normal patching and changes how fleets should think about custody and resale.
4 sources covering this story
A new unpatchable flaw in Apple chips opens the door to an iPhone jailbreak | TechCrunch
European offensive cybersecurity company Paradigm Shift released details of a flaw and a technique to exploit it that opens the door for hackers to unlock and break into older iPhones.
Unpatchable BootROM Flaw Impacts Apple A12, A13 Chips
Apple BootROM exploit exposes unpatchable USB flaw on A12 and A13 devices
New Exploit Bypasses Apple’s Boot Defenses, Affects Millions of iPhones
The vulnerability exploited by the Usbliter8 exploit cannot be patched and a PoC exploit has been released by researchers.
Unpatchable 'usbliter8' Exploit Breaks Apple A12 and A13 SecureROM Boot Chain
Paradigm Shift’s usbliter8 exploit targets Apple A12 and A13 SecureROM via USB DFU mode, creating an unpatchable hardware risk.
Part of the PlainSec briefing for 2026-06-22