BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Apple A12/A13 SecureROM Flaw Unpatchable

Unpatchable Apple chip exploit achieves permanent SecureROM jailbreak via USB.

  • A working exploit achieves arbitrary code execution within the SecureROM of Apple’s A12 and A13 chips, a flaw burned into the silicon.
  • Affected devices, including iPhone XS through iPhone 11 models and various iPads and Apple Watches, cannot be patched with any software update.
  • The attack requires physical access and DFU mode, and a proof of concept was made public on June 18, 2026.

Security researchers at Paradigm Shift have published a functional hardware exploit targeting Apple’s A12 and A13 chips, achieving code execution before the signed boot chain loads. This vulnerability, detailed in a technical write-up and a public proof of concept on June 18, 2026, permanently affects a range of devices due to a silicon-level flaw.

- Advertisement -

Consequently, millions of iPhones, iPads, and Apple Watches containing these chips cannot receive a software fix. The exploit, dubbed usbliter8, extends the permanent jailbreak condition previously seen in older chips to newer hardware generations.

The root cause is a hardware bug in the Synopsys DWC2 USB controller combined with an insecure configuration of Apple’s DART IOMMU. This combination allows carefully crafted USB packets to underflow a DMA buffer and overwrite critical memory inside SecureROM.

Gaining control requires overwriting a saved link register on the A12 or bypassing Pointer Authentication on the A13. After exploitation, attackers can demote the SoC’s production mode or boot unsigned iBoot images, stepping outside Apple’s chain of trust entirely.

However, the research team notes this does not demonstrate a compromise of the Secure Enclave processor. “BootROM-level control may open new routes for attacking it,” the Paradigm Shift report warns.

- Advertisement -

Meanwhile, the public release of the exploit code means the technique is now available as a tool. For most users, the practical risk remains low as the attack requires physical possession, DFU mode, and specific hardware.

For high-security environments, this becomes a hardware-retirement issue. Organizations are advised to inventory and prioritize refreshing affected A12, A13, S4, and S5 devices to newer, unaffected models like the A14.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Microsoft Entra ID bug gets perfect 10.0 CVSS score

Microsoft disclosed a critical remote code execution vulnerability in its Entra ID cloud identity...

Adviser: Agencies ‘Locked and Loaded’ if CLARITY Act Fails

White House crypto adviser Patrick Witt warned that federal agencies are "locked and loaded"...

Micron vs AMD: Cheaper Valuation Makes It Better AI Buy

Micron stock valuation sits well below AMD, creating a compelling entry point for AI...

TRUMP, ZEC Hit ‘Extremely Bullish’ Zone, POL Eyes $0.12 Breakout

Official Trump (TRUMP) led the rally with a nearly 94% weekly gain, peaking at...

Crypto Rally Erased: $550M in Longs Liquidated in 60 Minutes

The cryptocurrency market saw nearly $550 million in long liquidations within 60 minutes on...

Must Read

Best Metaverse Tokens to Buy on Binance for 10X Gains

Ever since Facebook renamed their company to Meta, as well as their plans to build a metaverse where we can travel into using Virtual...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading