'usbliter8' Exploit Creates Permanent, Unpatchable Vulnerability in Millions of iPhones and iPads

Unpatchable 'usbliter8' BootROM Exploit Released for Apple A12/A13 Chips

HIGH
June 20, 2026
5m read
VulnerabilityMobile Security

Impact Scope

People Affected

Millions of device users

Related Entities

Organizations

Apple Paradigm ShiftSynopsys

Products & Tech

A12 BionicA13 BionicSecure Enclave

Other

usbliter8checkm8

Full Report

Executive Summary

A permanent and unpatchable BootROM vulnerability, named usbliter8, has been publicly disclosed for Apple devices equipped with A12, A13, S4, and S5 System-on-Chips (SoCs). The exploit was released by security research firm Paradigm Shift and affects millions of devices, including the iPhone XS, 11, and SE (2nd gen) families. The flaw exists in the SecureROM—code physically etched into the chip's silicon—making it impossible for Apple to patch via software or firmware updates. The exploit allows an attacker with physical possession of a device to bypass the secure boot chain and execute arbitrary code at the earliest boot stage. While this requires physical access and does not compromise the Secure Enclave directly, it represents a significant and permanent security degradation for these device generations, akin to the 'checkm8' exploit for older chips.

Vulnerability Details

The usbliter8 exploit is a hardware-based vulnerability resulting from a combination of two issues:

  1. Hardware Bug: A buffer underflow flaw in the Synopsys DWC2 USB controller, a third-party component used by Apple in these chips.
  2. Firmware Flaw: An incorrect configuration of Apple's IOMMU (Input-Output Memory Management Unit), known as DART, which fails to properly isolate the USB controller's memory access.

An attacker can exploit this by connecting a target device in Device Firmware Update (DFU) mode to a specialized microcontroller. By sending carefully crafted USB control requests, the attacker can trigger the buffer underflow, which allows them to write data to arbitrary memory locations. Because this occurs during the BootROM execution phase—the very first code that runs on the chip—it allows the attacker to gain code execution before any of Apple's signature checks or security mechanisms are loaded. This constitutes a full bypass of the secure boot chain, a foundational element of iOS security.

Affected Systems

The vulnerability affects a wide range of popular Apple products. Any device using the following SoCs is vulnerable:

  • A12 Bionic: iPhone XS, XS Max, XR; iPad Air (3rd gen), iPad mini (5th gen), iPad (8th gen)
  • A13 Bionic: iPhone 11, 11 Pro, 11 Pro Max; iPhone SE (2nd gen); iPad (9th gen); Studio Display
  • S4: Apple Watch Series 4
  • S5: Apple Watch Series 5, Apple Watch SE (1st gen), HomePod mini

Exploitation Status

The exploit and a proof-of-concept were publicly released on June 18, 2026. There is no evidence of widespread malicious use in the wild. However, its public availability means that it can now be leveraged by law enforcement, digital forensics firms, security researchers, and potentially sophisticated threat actors for targeted attacks. The primary barrier to entry is the requirement for physical access to the device and specialized hardware to trigger the exploit.

Impact Assessment

The usbliter8 exploit has several significant implications:

  • Permanent Jailbreak: It enables the development of permanent, unpatchable jailbreaks for affected devices, allowing users to run modified versions of iOS.
  • Digital Forensics: Law enforcement and forensic investigators can use the exploit to bypass security measures and extract data from locked or disabled devices. However, it does not defeat passcode encryption or data protected by the Secure Enclave.
  • Targeted Attacks: High-value targets could be physically compromised by sophisticated adversaries (e.g., state-sponsored actors) to install persistent spyware that survives reboots and software updates.
  • Security Research: It provides researchers with deep access to the iOS boot process and hardware, which could lead to the discovery of further vulnerabilities.

The most critical aspect of this vulnerability is its permanence. Unlike software bugs, a BootROM flaw cannot be fixed. Every device in the affected generations will remain vulnerable for its entire lifespan.

Cyber Observables — Hunting Hints

Detection of this exploit is not feasible through conventional remote monitoring, as it requires physical access and occurs before the main OS loads and logging begins. The primary indicators would be physical, not digital.

Detection Methods

Detecting a successful usbliter8 exploit on a device is extremely difficult for the average user or enterprise. Since the exploit allows for booting a custom, modified OS, the malicious code could be designed to hide its own presence. Advanced forensic analysis might be able to identify discrepancies in the device's software or firmware, but this is beyond the capabilities of standard security tools.

Remediation Steps

There is no remediation for the BootROM vulnerability itself. The flaw is burned into the hardware. The only true mitigation is to replace the affected hardware with a newer, non-vulnerable device (e.g., devices with A14 chips or later).

For users and organizations with affected devices, the focus must be on mitigating the risks associated with physical access:

  1. Physical Security: Implement strong physical security controls to prevent unauthorized access to devices, especially for high-risk employees. This is the most critical defense.
  2. Strong Passcodes: Use a strong, alphanumeric passcode. While the exploit bypasses the secure boot chain, it does not break the passcode encryption protecting user data at rest within the Secure Enclave.
  3. Disable USB Accessories: In iOS settings, ensure the 'USB Accessories' toggle is off when locked. This prevents new USB devices from connecting while the device is locked for more than an hour, adding a small barrier to the exploit setup. This is a partial mitigation under M1034 - Limit Hardware Installation.

Timeline of Events

1
September 27, 2019
The 'checkm8' BootROM exploit for Apple A5-A11 chips is publicly released, setting a precedent for unpatchable hardware flaws.
2
June 18, 2026
The 'usbliter8' exploit for Apple A12 and A13 chips is publicly disclosed by Paradigm Shift.
3
June 20, 2026
This article was published

MITRE ATT&CK Mitigations

This mitigation is what the exploit bypasses. On unaffected devices, boot integrity checks prevent this attack.

Mapped D3FEND Techniques:

While not a complete fix, iOS settings to disable USB accessories when locked provide a minor barrier to exploitation.

Mapped D3FEND Techniques:

D3FEND Defensive Countermeasures

Since the usbliter8 exploit is unpatchable and requires a physical USB connection, the only software-based mitigation available is to restrict IO port functionality. On affected iPhones and iPads, navigate to Settings > Face ID & Passcode (or Touch ID & Passcode) and ensure the 'USB Accessories' toggle is turned OFF. This setting prevents new USB accessories from establishing a data connection if the device has been locked for more than an hour. While a determined attacker can wait out this timer or find ways around it, this setting provides a meaningful obstacle to 'evil maid' style attacks or quick forensic acquisitions. This hardening step makes it more difficult for an attacker to connect the specialized hardware needed to trigger the DFU mode exploit, increasing the time and complexity required for a successful attack.

Timeline of Events

1
September 27, 2019

The 'checkm8' BootROM exploit for Apple A5-A11 chips is publicly released, setting a precedent for unpatchable hardware flaws.

2
June 18, 2026

The 'usbliter8' exploit for Apple A12 and A13 chips is publicly disclosed by Paradigm Shift.

Article Author

Jason Gomes

Jason Gomes

• Cybersecurity Practitioner

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.

Threat Intelligence & AnalysisSecurity Orchestration (SOAR/XSOAR)Incident Response & Digital ForensicsSecurity Operations Center (SOC)SIEM & Security AnalyticsCyber Fusion & Threat SharingSecurity Automation & IntegrationManaged Detection & Response (MDR)

Tags

usbliter8AppleBootROMExploitUnpatchableVulnerabilityiPhoneA12A13Jailbreak

📢 Share This Article

Help others stay informed about cybersecurity threats

🎯 MITRE ATT&CK Mapped

Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.

🧠 Enriched & Analyzed

Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.

🛡️ Actionable Guidance

Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.

🔗 STIX Visualizer

Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.

Sigma Generator

Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.