BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Apple A12/A13 SecureROM Flaw Unpatchable

Unpatchable Apple chip exploit achieves permanent SecureROM jailbreak via USB.

  • A working exploit achieves arbitrary code execution within the SecureROM of Apple’s A12 and A13 chips, a flaw burned into the silicon.
  • Affected devices, including iPhone XS through iPhone 11 models and various iPads and Apple Watches, cannot be patched with any software update.
  • The attack requires physical access and DFU mode, and a proof of concept was made public on June 18, 2026.

Security researchers at Paradigm Shift have published a functional hardware exploit targeting Apple’s A12 and A13 chips, achieving code execution before the signed boot chain loads. This vulnerability, detailed in a technical write-up and a public proof of concept on June 18, 2026, permanently affects a range of devices due to a silicon-level flaw.

- Advertisement -

Consequently, millions of iPhones, iPads, and Apple Watches containing these chips cannot receive a software fix. The exploit, dubbed usbliter8, extends the permanent jailbreak condition previously seen in older chips to newer hardware generations.

The root cause is a hardware bug in the Synopsys DWC2 USB controller combined with an insecure configuration of Apple’s DART IOMMU. This combination allows carefully crafted USB packets to underflow a DMA buffer and overwrite critical memory inside SecureROM.

Gaining control requires overwriting a saved link register on the A12 or bypassing Pointer Authentication on the A13. After exploitation, attackers can demote the SoC’s production mode or boot unsigned iBoot images, stepping outside Apple’s chain of trust entirely.

However, the research team notes this does not demonstrate a compromise of the Secure Enclave processor. “BootROM-level control may open new routes for attacking it,” the Paradigm Shift report warns.

- Advertisement -

Meanwhile, the public release of the exploit code means the technique is now available as a tool. For most users, the practical risk remains low as the attack requires physical possession, DFU mode, and specific hardware.

For high-security environments, this becomes a hardware-retirement issue. Organizations are advised to inventory and prioritize refreshing affected A12, A13, S4, and S5 devices to newer, unaffected models like the A14.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

WhiteBIT Gets MiCA License in Austria for EU Services

WhiteBIT has secured a MiCA license from Austria, allowing it to offer regulated crypto...

Sonic Appoints New CEO, Leadership After Board Resigns

Sonic Labs founders Andre Cronje, Michael Kong, and David Richardson resign from board, handing...

Bitcoin Credit Products Sink in Leverage Liquidation Wipeout

Strive CEO Matt Cole labeled Thursday as the "most difficult day ever" for digital...

Arthur Hayes: AI Credit Event Could Crash Bitcoin To $1 Million

Bitcoin fell toward $60,000 as MicroStrategy's convertible note fell to a record low, pressuring...

Andrew Tate Loses $100,000 In High-Stakes Bitcoin Bets

Andrew Tate's wallet balance on the Hyperliquid exchange plummeted from $100,000 to about $14,000...

Must Read

The Ultimate Guide on How to Understand a Cryptocurrency White Paper

Today, cryptocurrency is a popular buzzword. We hear about it on the news, we read about it on the Internet. Yet, people are reluctant to...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading