top of page

Unpatchable hardware vulnerability in Apple chips: New opportunities for legacy iPhone jailbreaking

In the tech world, Apple is renowned for its stringent security ecosystem. However, a recent discovery by cybersecurity experts has revealed a critical vulnerability embedded directly within the hardware of legacy iPhone models. This flaw not only enables researchers to achieve deep system access but is also entirely unpatchable via software updates from the manufacturer.

Recently, Paradigm Shift, a cybersecurity firm based in Barcelona, Spain, published detailed findings along with a proof-of-concept (PoC) exploit for a vulnerability dubbed usbliter8. According to the research, this flaw affects Apple A12 and A13 Bionic chips, which power widely used legacy devices including the iPhone XS, iPhone XR, and iPhone 11.

Targeting the iPhone's first line of defense

The most notable aspect of usbliter8 is that it directly targets the Boot ROM - the foundational code and the very first component executed when an iPhone boots up.

To put it simply, the Boot ROM acts as the initial gatekeeper in Apple's secure boot chain. Its role is to verify and validate the integrity of subsequent software layers before the core operating system (iOS) is loaded. If this gatekeeper is compromised, attackers can easily bypass a multitude of security barriers designed to protect the device.

Boot ROM is the foundational code and acts as the initial gatekeeper in Apple's secure boot chain
Boot ROM is the foundational code and acts as the initial gatekeeper in Apple's secure boot chain

However, exploiting this vulnerability is far from simple. An attacker must have physical access and connect a cable directly to the target iPhone. Once control over the Boot ROM is established, it provides a stepping stone to chain this flaw with other vulnerabilities to gain deeper control over the system.

Paving the way for jailbreaking techniques

The emergence of usbliter8 does not mean anyone can easily hack an iPhone. Nevertheless, for bug bounty hunters, defense contractors, and exploit developers, it represents an invaluable piece of the puzzle.

By chaining usbliter8 with other vulnerabilities in the iOS operating system, security researchers and developers can rebuild Jailbreak tools.

Jailbreaking is a deep-level modification technique used to bypass the restrictions enforced by Apple, allowing users to customize the system, install applications outside the official App Store, or gain elevated administrative privileges that are otherwise restricted.

Why Apple is completely powerless against this vulnerability

Typically, when a security flaw is discovered, Apple promptly rolls out iOS updates to patch it. However, with usbliter8, that scenario is impossible.

Apple is completely powerless against this vulnerability and cannot release iOS updates to patch it
Apple is completely powerless against this vulnerability and cannot release iOS updates to patch it

Paradigm Shift explained that this flaw resides in the read-only memory (ROM) code hardcoded directly into the silicon during the manufacturing phase. Unlike operating systems or software that can be modified remotely, chip hardware is immutable. Once a device leaves the factory floor and reaches consumers, the flaw within the Boot ROM remains permanently, rendering software patches ineffective.

Researchers emphasize that due to the unchangeable nature of this code, the only way to completely eliminate the security risk is for users to upgrade to newer generations of Apple hardware.

Should everyday users be worried?

While this discovery has sent shockwaves through the cybersecurity community, the actual risk to everyday users currently remains low due to two main reasons:

  • Physical access required: Threat actors cannot attack devices remotely over the internet; they must have physical possession of the iPhone and connect it via a cable.

  • Data remains protected: Gaining control over the Boot ROM is merely the first step and does not grant immediate access to stored data. Attackers would still need to chain additional vulnerabilities to access personal information.

In reality, digital forensics firms like Cellebrite or Magnet Forensics, which provide data extraction solutions for law enforcement, may have discovered and utilized similar techniques long ago to unlock evidence devices.

A reminder on the myth of absolute security

Over the years, Apple has elevated its security barriers to unprecedented heights, making the once-common iPhone jailbreaking tools extremely rare today. However, the exposure of usbliter8 serves as clear evidence that no fortress is completely impenetrable.

For users and organizations alike, this incident is a pragmatic reminder: information security is an endless race between those building the walls and those trying to scale them. Currently, Paradigm Shift has remained quiet and has not offered further commentary regarding the real-world exploitability of this vulnerability.

Reference: TechCrunch - A new unpatchable flaw in Apple chips opens the door to an iPhone jailbreak

Comments


follow ipsip vietnam.png
40051abd5a76713af8f015988fc6780e-blue-phone-icon-with-a-wave-on-it.webp
whatsapp-mobile-software-icon-png-image_6315991.png
pngtree-minimal-calendar-icon-vector-png-image_21233134.png
IPSIP logo transparent.png

IPSIP VIETNAM ONE MEMBER LIMITED LIABILITY COMPANY (IPSIP VIETNAM OMLLC)

Tax code: 0313859600

🏢 SH05.01, B4 Street, Saritown Area, An Khanh Ward, Ho Chi Minh City, Vietnam

​☎  +84 918 397 489

  • Linkedin
  • Facebook
  • TikTok
  • Email liên hệ
png-clipart-iso-iec-27001-information-security-management-iso-iec-27002-international-orga
soc 2 type ii

Our Services

Sign up to receive in-depth cybersecurity documents and news from IPSIP Vietnam.

bottom of page