Researchers disclosed a hardware-level exploit that can break the secure boot process on older iPhones using Apple A12 and A13 chips. The exploit, called usbliter8, affects SecureROM (the BootROM code burned into the device) on iPhone XS, XR, 11, and 11 Pro models and other A12/A13 devices. It abuses a flaw in the Synopsys DesignWare USB controller during Device Firmware Update (DFU) mode to corrupt memory and run unsigned code; no CVE was cited, and exploitation requires physical access and DFU mode.
Why it matters: Owners of affected devices will not get a software fix because the bug is in chip-level code, so these phones remain vulnerable for life. The risk is mainly to people facing physical-device seizure or forensic access rather than mass remote attacks, and the practical mitigation is to replace affected hardware if this threat model matters.
Eduard Kovacs
2026.06.22
98% relevant
This article adds mainstream reporting details on the same Usbliter8 disclosure, including affected iPhone XS/XR/11 and Apple Watch S4/S5 models, the physical USB attack requirement, and the researchers' note that the exploit bypasses SecureROM signature checks but does not directly compromise the Secure Enclave Processor.
info@thehackernews.com (The Hacker News)
2026.06.19
97% relevant
This article appears to describe the same underlying event: disclosure of the unpatchable 'usbliter8' BootROM/SecureROM exploit affecting Apple A12 and A13 devices, adding another report and framing it as a break of the SecureROM boot chain.
2026.06.19
100% relevant
This article appears to be the initial reporting of a newly disclosed BootROM exploit for Apple A12 and A13 devices, and it does not match any existing tracked story about this same underlying event.
← Back to all stories