Public PoC Turns Apple Boot Trust into Custody Risk

Physical possession now matters more than software state on affected Apple chips. On A12, A13, S4, and S5 devices, brief access in DFU mode can reach SecureROM before the signed boot chain starts, so the trust root itself is what breaks and no update can remove it. Paradigm Shift released a working public proof of concept for the usbliter8 exploit on June 18, 2026. The flaw sits in the Synopsys DWC2 USB controller’s packet handling and can be driven through USB DFU mode to achieve arbitrary code execution inside SecureROM on affected hardware, including iPhone XS, XS Max, XR, iPhone 11, Apple Watch Series 4 and 5, and HomePod mini. A11 is not affected, and A14 and later appear out of reach for this path. The forward risk is persistent. Any device that changes hands, enters repair, or is left briefly unattended can carry a trust-root compromise that survives normal patching and changes how fleets should think about custody and resale.

Part of the PlainSec briefing for 2026-06-22

Sources