logo

New iPhone BootROM Vulnerability Exposes Apple SoCs to Full Chain-of-Trust Compromise

ID: 904b45e5-7a92-5324-b391-1e76f65a9e1b

STIX ID: report--904b45e5-7a92-5324-b391-1e76f65a9e1b

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2026-06-18

Date Updated: 2026-06-18

Author: Guru Baran

...
...

Paradigm Shift disclosed "usbliter8", a BootROM-level vulnerability in the Synopsys DWC2 USB controller on Apple A12, A13 and S4/S5 SoCs that enables a DMA-based buffer underflow and arbitrary memory writes; researchers produced a proof-of-concept exploit that achieves SecureROM/EL1 code execution, disables signature verification to boot unsigned iBoot images, and cannot be patched in affected BootROM silicon—migration to A14+ hardware is the only effective mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.