Unpatchable 'usbliter8' Exploit Breaks Apple A12 and A13 SecureROM Boot Chain
Security researchers have published a working exploit that allows arbitrary code execution inside the SecureROM of Apple's A12 and A13 chips, which are not affected by software updates.
Intelligence analysis by Qwen 2.5 (3B)

Security researchers have discovered an unpatchable exploit for Apple's A12 and A13 chips. The flaw affects SecureROM and requires physical access to execute code.
Imagine your phone has a special locked-down area where only trusted apps can run. But someone found a way to trick the system and make it let in bad guys who shouldn't be there.
Analysis
{"# Hardware Flaw":"The root issue is a hardware flaw in the Synopsys DWC2 USB controller. The controller stores incoming USB Setup packets via DMA, leading to buffer underflow issues that can be exploited.","# Exploit Path":"The exploit requires physical possession of the device and DFU mode connection. It bypasses security measures like Pointer Authentication (PAC) and allows execution at EL1, a privileged mode inside SecureROM.","# Impact on Security":"If exploited, the attacker gains control over USB serial strings, can temporarily demote production modes, or boot unsigned iBoot images without signature checks, potentially compromising Apple's chain of trust."}
Key points
- The exploit targets Apple's A12 and A13 chips which are not affected by software updates
- It requires physical access and DFU mode connection to execute the code
- The attacker gains control over USB serial strings, can temporarily demote production modes or boot unsigned iBoot images
As researchers continue to study this exploit, they may find ways to mitigate its impact or develop new security measures to prevent similar attacks.
Until proper patches are released, users of affected devices must be extremely cautious and avoid connecting their phones to untrusted USB ports or hosts.



