logo

Unpatchable 'usbliter8' Exploit Breaks Apple A12 and A13 SecureROM Boot Chain

ID: 74b2b1b0-2878-5421-81de-5f8ff20e345c

STIX ID: report--74b2b1b0-2878-5421-81de-5f8ff20e345c

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2026-06-19

Date Updated: 2026-06-20

Author: [email protected] (The Hacker News)

...
...

Researchers released a public exploit called usbliter8 that leverages a hardware flaw in the Synopsys DWC2 USB controller and a SecureROM DART configuration to achieve arbitrary code execution on Apple A12/A13 (and some S4/S5) devices via DFU mode and a dedicated microcontroller; the PoC is public, the flaw is unpatchable by software, and affected devices retain the vulnerability for their lifetime, posing a significant risk for high-security environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.