Tag

Bootrom

All articles tagged with #bootrom

Legacy iPhones face unpatchable boot ROM flaw, prompting upgrade caution
technology2 months ago

Legacy iPhones face unpatchable boot ROM flaw, prompting upgrade caution

Security researchers revealed a ROM-based vulnerability called usbliter8 in iPhones with A12/A13 chips (including XS/XS Max/XR, iPhone 11 family, and iPhone SE 2nd gen) and some iPads/Apple Watches. Because the flaw is in the boot ROM, it can’t be patched with software updates; exploitation requires physical access and can’t be triggered remotely, though user data remains protected. Affected devices will carry the vulnerability for their lifetime, so upgrading to newer hardware is the recommended mitigation when possible.

Unpatchable bootROM Flaw Hits iPhone XS to iPhone 11 via USB Exploit
technology2 months ago

Unpatchable bootROM Flaw Hits iPhone XS to iPhone 11 via USB Exploit

Security researchers reveal usbliter8, the first unpatchable iPhone bootROM exploit in years, affecting A12 (iPhone XS), A13 (iPhone 11) and related USB-controller hardware in Apple Watch Series 4/5 and HomePod mini. Exploitation requires physical access and a Raspberry Pi due to a USB controller data-packet flaw that exposes SRAM data; software updates cannot patch it, while A14+ chips are safe. The iPhone 11 remains supported for now, but the vulnerability persists on older hardware.

Unpatchable BootROM flaw targets Apple A12/A13 devices with USB code execution
technology2 months ago

Unpatchable BootROM flaw targets Apple A12/A13 devices with USB code execution

Researchers disclosed usbliter8, an unpatchable BootROM exploit affecting devices with Apple A12/A13 chips that enables arbitrary code execution by sending specially crafted USB data while the device is in DFU mode. The vulnerability does not touch the Secure Enclave, but requires physical access and cannot be patched on affected hardware; Apple coordinated disclosure and a GitHub PoC is available. Affected devices include iPhone XR/XS/XS Max, iPhone 11 series, iPad 9, iPad Air 3, iPad mini 5, second-gen Apple TV 4K, Apple Watch Series 4/5, HomePod mini, and Studio Display, with possible A12X/Z support; upgrading to newer hardware remains the recommended mitigation.

Unpatchable BootROM Flaw in iPhone A12/A13 Enables USB-Based Exploitation
technology2 months ago

Unpatchable BootROM Flaw in iPhone A12/A13 Enables USB-Based Exploitation

Security researchers have detailed a BootROM vulnerability, usbliter8, affecting Apple's A12 and A13 chips that can be exploited via a specific USB sequence at startup to gain code execution and boot unsigned software; because BootROM resides in hardware, software updates cannot patch it, leaving affected devices vulnerable for life. A12 is easier to exploit, A13 requires bypassing PAC, A11 is unaffected and A14+ are safe; Apple was notified and a full PoC was published.