Unpatchable BootROM Vulnerability in Apple A12 and A13 Chips (infosecurity-magazine.com)
0xBASE INTEL BRIEF
- Paradigm Shift researchers discover 'usbliter8' exploit targeting Apple A12 and A13.
- Hardware bug in USB controller enables code execution with physical access.
- Affects iPhone XS/XR, iPhone 11 series, and Apple Watch Series 4/5.
- Apple A14 and later are not impacted due to proper DART configuration.
- No software update can fix the issue; device replacement recommended.
"Researchers at Paradigm Shift have discovered an unpatchable BootROM vulnerability in Apple A12, S4/S5, and A13 systems-on-chips. Dubbed 'usbliter8', the flaw exploits a hardware bug in the USB controller combined with a SecureROM firmware misconfiguration, allowing code execution with physical access. The issue cannot be fixed via software update because BootROM code is immutable after manufacture. Affected devices will carry the vulnerability for their lifetime; upgrading to newer hardware is the only effective mitigation."
no comments yet.