Lead story
usbliter8: The Unpatchable iPhone Exploit That Will Never Get a Patch
Security researchers at Paradigm Shift have published a working exploit called usbliter8 that achieves arbitrary code execution inside the SecureROM of Apple's A12 and A13 chips — the ones inside the iPhone XS through iPhone 11 family. If that sounds familiar, it should: this is the same class of vulnerability as checkm8, the 2019 BootROM exploit that still haunts every A10-era device in service today.
The critical detail is in the word "burned." SecureROM code is written into the silicon at manufacture. Apple cannot update it remotely, push a fix, or issue a patch. Every affected device will carry this flaw until it's decommissioned. That's tens of millions of handsets globally — many still actively used by individuals, businesses, and government agencies.
What it actually takes to exploit it. This is not a remote attack. The exploit requires physical USB access to the device, which significantly limits casual mass exploitation. Think targeted scenarios: border searches, device seizure, physical theft, or a charging cable left somewhere interesting. The jailbreak community will also have a field day, which is a secondary consequence rather than a threat.
Why it still matters. "Physical access required" is not the same as "nothing to worry about." Law enforcement and intelligence agencies routinely use physical-access BootROM exploits for device forensics — tools like GrayKey are built on exactly this kind of vulnerability. The public release of a working exploit means that capability, previously in the hands of a small number of well-resourced actors, is now available to anyone with the technical inclination to use it.
For enterprises and government agencies, the calculus is straightforward: any A12/A13 device that contains sensitive data and could plausibly end up in an adversary's hands is now a higher-risk device than it was 48 hours ago. The Australian Signals Directorate's advice on device disposal and mobile device management policies becomes newly relevant here — especially for agencies running older iPhone fleets that haven't yet been refreshed.
What Apple can do. Not much, directly. Apple has reportedly acknowledged the research. Future hardware won't be affected — A14 and later chips don't share this BootROM code. The practical mitigations are organisational: enforce full-disk encryption (already default on iOS), ensure strong alphanumeric passcodes rather than six-digit PINs, enable Lockdown Mode on high-risk devices, and accelerate device refresh cycles for sensitive roles.
The broader pattern. BootROM exploits have a long tail. checkm8, disclosed in 2019, is still being actively used in forensic tools and jailbreaks today. usbliter8 will likely follow the same trajectory — quietly becoming infrastructure for a decade's worth of targeted attacks on devices that will never see a fix.
The lesson for anyone managing a device fleet: "end of software support" and "end of security risk" are not the same date, and they never have been.
