logo

usbliter8 Brings Unpatchable BootROM Exploit to Apple A12 and A13 Devices

ID: 181ebbb4-061d-53de-b91b-bc74847388b5

STIX ID: report--181ebbb4-061d-53de-b91b-bc74847388b5

Feed Name: Security Affairs

Threat Score
75/100

Date Published: 2026-06-22

Date Updated: 2026-06-22

Author: Pierluigi Paganini

...
...

usbliter8 is an unpatchable BootROM exploit published June 18, 2026, that leverages a DMA buffer underflow in the Synopsys DWC2 USB controller to achieve arbitrary code execution in SecureROM on Apple A12/A13 (and some S4/S5) devices. The attack requires physical access, DFU mode, a USB connection and a dedicated microcontroller; Paradigm Shift published a working proof-of-concept that can demote production mode or boot unsigned iBoot images, effectively breaking Apple’s boot chain of trust for affected devices. Affected models include iPhone XS/11/SE(2nd gen), certain iPads, Apple Watch Series 4/5, and HomePod mini; mitigations recommended are inventory/refresh to A14+, strict DFU/USB policies, and treating physical custody as a security control.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.