Close Menu
    What's Hot

    The Best Fitness Trackers of 2026: Garmin, Google Fitbit, and More

    Tower Research Capital muscles in on fast-growing fixed-income ETFs

    US Open: LIV Golf’s Joaquin Niemann surprised by ‘serious misconduct’ penalty for throwing golf club at Shinnecock Hills | Golf News

    Facebook X (Twitter) Instagram
    Trending
    • The Best Fitness Trackers of 2026: Garmin, Google Fitbit, and More
    • Tower Research Capital muscles in on fast-growing fixed-income ETFs
    • US Open: LIV Golf’s Joaquin Niemann surprised by ‘serious misconduct’ penalty for throwing golf club at Shinnecock Hills | Golf News
    • Luka Vuskovic: Brighton make improved £45m bid for Tottenham defender | Football News
    • Today’s best bets: USMNT World Cup opener, MLB and more on Friday
    • Researchers say one childhood vaccine is preventing hundreds of cancer deaths
    • The US-Australia face-off that isn’t happening – Live Updates
    • The politician who kicked his way to power – Live Updates
    interluknewsinterluknews
    • Home
    • Business
      • Corporate News
      • Industry Insights
      • Startups & Entrepreneurship
      • Technology & Innovation
    • Economy
      • Economic Policy
      • Financial Analysis
      • Inflation & Interest Rates
      • Trade & Markets
    • Global
      • Conflicts & Security
      • Diplomacy
      • Global Trends
      • International Affairs
    • Lifestyle
      • Fashion
      • Food & Dining
      • Personal Development
      • Travel
    • Opinion
      • Columns
      • Editorials
      • Expert Opinions
      • Reader Voices
    • More
      • Politics
        • Elections
        • Government & Policy
        • International Relations
        • Political Analysis
      • Sports
        • Cricket
        • Football / Soccer
        • International Sports
        • Local Sports
      • Technology
        • Artificial Intelligence
        • Cybersecurity
        • Gadgets & Reviews
        • Tech News
      • South Africa News
    Facebook X (Twitter) Instagram
    interluknewsinterluknews
    Cybersecurity

    Unpatchable ‘usbliter8’ Exploit Breaks Apple A12 and A13 SecureROM Boot Chain

    adminBy adminJune 19, 2026No Comments4 Mins Read
    Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
    Unpatchable ‘usbliter8’ Exploit Breaks Apple A12 and A13 SecureROM Boot Chain
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Unpatchable ‘usbliter8’ Exploit Breaks Apple A12 and A13 SecureROM Boot Chain

    Security researchers at Paradigm Shift have published a working exploit, dubbed usbliter8, that achieves arbitrary code execution inside the SecureROM of Apple’s A12 and A13 chips.

    That code is burned into the silicon at manufacture. No software update can reach it. Affected devices will carry this flaw for as long as they stay in use.

    This is not a remote attack. It requires physical possession of the device, which must be in DFU mode and connected via USB to a dedicated RP2350-based microcontroller board. With that setup, the exploit finishes in under two seconds, before Apple’s signed boot chain loads.

    The full technical write-up and a working proof of concept went public on June 18, 2026, following coordinated disclosure with Apple Product Security.

    Affected Devices

    The public PoC supports A12, A13, S4, and S5 SoCs. A12X and A12Z support is described as theoretically possible but not yet implemented.

    Cybersecurity

    Device families in that range include the iPhone XS, XS Max, and XR; the iPhone 11, 11 Pro, 11 Pro Max; the iPhone SE (2nd generation); the iPad Air 3rd gen, iPad mini 5th gen, and iPad 8th gen; Apple Watch Series 4 and 5; the first-generation Apple Watch SE; the HomePod mini; and other Apple products built on those chips. A11 is not affected. A14 and later appear to be out of reach for this exploit path.

    The Bug

    The root issue is a hardware flaw in the Synopsys DWC2 USB controller.

    The controller stores incoming USB Setup packets via DMA, buffers up to three, then resets its write pointer on the fourth by decrementing it by a fixed 24 bytes. It also accepts smaller-than-standard packets, incrementing the pointer only by the actual bytes written. That mismatch accumulates into a repeatable buffer underflow, stepping the write pointer backwards through memory 12 bytes at a time.

    What makes this exploitable on A12 and A13 is how Apple configures the USB DART (Device Address Resolution Table, the chip’s IOMMU) inside SecureROM. On affected devices, it runs in bypass mode, so the underflowing DMA pointer can reach and overwrite arbitrary SRAM.

    A11 is not affected because its USB driver manually resets the DMA address after every packet, so the mismatch never accumulates. A14 and later appear to configure DART correctly, which Paradigm Shift says makes the vulnerability unexploitable on newer hardware.

    Getting Code Execution

    On A12, the DMA buffer sits adjacent to the USB task’s stack on the heap. Overwriting a saved link register hands the attacker program counter control on the next context switch.

    A13 is harder. Pointer Authentication (PAC) protects stack-stored return addresses. Paradigm Shift bypassed it in stages. Corrupting DART-related heap structures created limited write primitives. Overwriting the panic depth counter made the chip loop on errors instead of rebooting. Careful DMA write timing avoided clobbering the USB task’s saved registers.

    The final step overwrote the USB interrupt handler pointer in BSS. The next USB interrupt then ran attacker-supplied code. Either path ends with execution at EL1, the chip’s privileged mode, inside SecureROM.

    What an Attacker Gets

    Post-exploitation, usbliter8 injects a custom USB request handler and stamps PWND:[usbliter8] into the device’s USB serial string. From there, an attacker can temporarily demote the SoC’s production mode or boot a raw, unsigned iBoot image with no signature checks, stepping outside Apple’s chain of trust entirely.

    The research does not show a Secure Enclave compromise. Apple’s Secure Enclave is designed as a separate protection boundary, isolated from the application processor. Paradigm Shift warns that BootROM-level control may open new routes for attacking it.

    No Software Patch

    The closest public precedent is checkm8, the 2019 SecureROM exploit that permanently put A5-through-A11 devices outside Apple’s patch authority.

    Cybersecurity

    Like checkm8, usbliter8 requires physical access and DFU mode and cannot be closed with a firmware update. usbliter8 extends that condition to the next chip generation.

    As of June 19, 2026, no CVE, CVSS score, Apple security advisory, or CISA alert had been issued, and no in-the-wild exploitation had been publicly reported.

    For most users, the practical risk is low: an attacker needs the physical device, the right cable, and the knowledge to force DFU mode. For high-security environments, this is now a hardware-retirement and device-custody problem.

    If a device runs one of the affected chips, the physical boundary is permanently gone; safety depends on controlling when and where the device can be plugged in. Inventory A12, A13, S4, and S5 hardware in sensitive roles, prioritize refreshes toward A14 or newer, and avoid DFU mode over untrusted USB cables or hosts.

    The code is public. That is usually how exploit research stops being a demo and starts being someone else’s tool.

    A12 A13 Apple boot breaks Chain Exploit SecureROM Unpatchable usbliter8
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous ArticleThe soccer boss in Mark Carney’s ear – Live Updates
    Next Article Wyndham Clark sets 36-hole Shinnecock record for U.S. Open
    admin
    • Website

    Related Posts

    AutoJack Attack Lets One Web Page Hijack AI Agent for Host Code Execution

    June 19, 2026

    Operation Endgame Disrupts SocGholish Servers, Cleans 14,971 WordPress Sites

    June 19, 2026

    The AI Shift That’s Redefining Threat Management

    June 19, 2026
    Leave A Reply Cancel Reply

    Demo
    Latest Posts

    The Best Fitness Trackers of 2026: Garmin, Google Fitbit, and More

    Tower Research Capital muscles in on fast-growing fixed-income ETFs

    US Open: LIV Golf’s Joaquin Niemann surprised by ‘serious misconduct’ penalty for throwing golf club at Shinnecock Hills | Golf News

    Luka Vuskovic: Brighton make improved £45m bid for Tottenham defender | Football News

    Latest Posts

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Advertisement
    Demo

    We are a digital news platform delivering timely, accurate, and insightful coverage of politics, global affairs, business, economy, sports, and more. Our mission is to keep readers informed with reliable news, clear analysis, and stories that truly matter.
    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.

    Powered by
    ...
    ►
    Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
    None
    ►
    Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
    None
    ►
    Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
    None
    ►
    Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
    None
    ►
    Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    None
    Powered by