
Security research firm Paradigm Shift has disclosed a new BootROM vulnerability, called “usbliter8,” affecting Apple’s A12 and A13 chips. Because the BootROM is burned into the chip during manufacturing, the flaw cannot be patched in software, leaving affected devices exposed for the remainder of their service life. The proof-of-concept code is available alongside the researcher’s write-up.
What Researchers Disclosed
Security research firm Paradigm Shift published details of a new BootROM vulnerability affecting Apple’s A12 and A13 chips, along with a working proof-of-concept exploit named “usbliter8.” The BootROM, also called SecureROM, is the first code an iPhone runs when it powers on. Because it is baked into the chip during manufacturing, any vulnerability found there cannot be addressed through a software update, which means affected devices will remain exposed for the rest of their service life.
Which Devices Are Affected?
The last publicly known BootROM exploit of this kind was “checkm8,” released in 2019, which affected devices ranging from the iPhone 4S through the iPhone X. usbliter8 extends that lineage to the next generation of Apple silicon, covering devices from the iPhone XS through the iPhone 11 series.
How Does the Exploit Work?
According to Paradigm Shift, the exploit takes advantage of a bug in the USB controller built into Apple’s chips. When an iPhone receives USB data during startup, the controller stores incoming packets in a memory buffer. The researchers found that sending a specific sequence of unusually small packets could manipulate an internal hardware pointer, causing it to walk backwards through memory and write data to locations it should never reach.
The researchers describe this as a bug in the USB controller hardware itself, rather than in Apple’s software.
Why Are A11, A14, and Later Chips Not Affected?
The A11 chip, used in the iPhone X, is not affected because its USB driver manually resets the pointer after each packet. A14 and later chips are also unaffected, because they configure a memory protection feature correctly at the BootROM level. The A12 and A13 sit between these two designs and inherit the vulnerable behavior.
How Do A12 and A13 Differ?
On A12 devices, gaining code execution is described as relatively straightforward. On A13 devices, the process is harder because Apple introduced Pointer Authentication Codes (PAC), a security feature that detects and blocks certain types of memory tampering. Paradigm Shift notes that working around PAC on the A13 required a lengthy multi-step process before the researchers could take control of the processor.
What Can an Attacker Do After Exploitation?
Once the exploit takes control of a device, it installs a custom handler that survives a restart. According to Paradigm Shift, this handler can temporarily lower the device’s security settings and boot unsigned software without verification checks. The exploit also injects the traditional “PWND” string into the iPhone’s USB serial number as a marker of compromise, a convention that carries over from checkm8 and earlier exploits.
What Are the Implications for the Secure Enclave?
Paradigm Shift notes that usbliter8 does not affect the Secure Enclave directly. However, the firm points out that a BootROM compromise of this kind opens wider avenues for attacking it. The researchers say they reported their findings to Apple Product Security before publication and worked with Apple on coordinated disclosure. The full proof-of-concept code is available alongside the write-up at the firm’s research site.
FAQ
What is the new BootROM exploit and which chips does it target?
Security research firm Paradigm Shift disclosed usbliter8, a BootROM vulnerability and proof-of-concept exploit targeting Apple’s A12 and A13 chips. Because the BootROM is baked into the chip during manufacturing, the flaw cannot be fixed with a software update.
Which iPhone models are affected by usbliter8?
usbliter8 affects devices from the iPhone XS through the iPhone 11 series, which use the A12 and A13 chips. The A11-based iPhone X and A14-based devices are not affected.
Can usbliter8 compromise the Secure Enclave?
Paradigm Shift states usbliter8 does not directly affect the Secure Enclave, but the firm notes that a BootROM compromise opens wider avenues for attacking it. The researchers disclosed their findings to Apple Product Security before publication.
Related coverage
Run a free scan to see your AI Visibility Score, SEO rating, and local citation accuracy.