Tag

Usbliter8

All articles tagged with #usbliter8

Unfixable boot-level flaw strikes seven iPhone models; upgrade advised
technology2 months ago

Unfixable boot-level flaw strikes seven iPhone models; upgrade advised

Cybersecurity firm Paradigm Shift flags an unfixable hardware-level flaw, named usbliter8, in the USB controller/firmware that affects seven iPhone models (A12/A13 era: iPhone 11 family, XR, XS/XS Max, and second-gen iPhone SE) and some iPad/Apple Watch devices. The flaw can be exploited with physical access to override the startup process before iOS loads, enabling unauthorized software or data access. Since it’s a hardware design issue, there is no software update to fix it; the advised mitigation is upgrading to newer hardware.

Unpatchable bootROM Flaw Hits iPhone XS to iPhone 11 via USB Exploit
technology2 months ago

Unpatchable bootROM Flaw Hits iPhone XS to iPhone 11 via USB Exploit

Security researchers reveal usbliter8, the first unpatchable iPhone bootROM exploit in years, affecting A12 (iPhone XS), A13 (iPhone 11) and related USB-controller hardware in Apple Watch Series 4/5 and HomePod mini. Exploitation requires physical access and a Raspberry Pi due to a USB controller data-packet flaw that exposes SRAM data; software updates cannot patch it, while A14+ chips are safe. The iPhone 11 remains supported for now, but the vulnerability persists on older hardware.

Unpatchable BootROM flaw targets Apple A12/A13 devices with USB code execution
technology2 months ago

Unpatchable BootROM flaw targets Apple A12/A13 devices with USB code execution

Researchers disclosed usbliter8, an unpatchable BootROM exploit affecting devices with Apple A12/A13 chips that enables arbitrary code execution by sending specially crafted USB data while the device is in DFU mode. The vulnerability does not touch the Secure Enclave, but requires physical access and cannot be patched on affected hardware; Apple coordinated disclosure and a GitHub PoC is available. Affected devices include iPhone XR/XS/XS Max, iPhone 11 series, iPad 9, iPad Air 3, iPad mini 5, second-gen Apple TV 4K, Apple Watch Series 4/5, HomePod mini, and Studio Display, with possible A12X/Z support; upgrading to newer hardware remains the recommended mitigation.

USBLITER8: Unpatchable USB flaw hits Apple devices with A12/A13 chips
technology2 months ago

USBLITER8: Unpatchable USB flaw hits Apple devices with A12/A13 chips

A Paradigm Shift report warns of 'usbliter8', a hardware/firmware USB flaw that affects Apple devices with A12/A13 and S4/S5 chips (including iPhone XR through iPhone 11 lineup, iPad Air 3/mini 5/8, Apple TV 4K gen 2, Studio Display, and Apple Watch Series 4–SE) and is described as unpatchable. In DFU mode, a USB data sequence can force the controller to write to the wrong memory, letting an attacker inject code before iOS boots and bypass signature checks, while the Security Enclave remains safe. Apple reportedly worked with researchers on a fix, but the safest defense is upgrading to a newer device; older A11 devices do not appear affected.

Unpatchable BootROM Flaw in iPhone A12/A13 Enables USB-Based Exploitation
technology2 months ago

Unpatchable BootROM Flaw in iPhone A12/A13 Enables USB-Based Exploitation

Security researchers have detailed a BootROM vulnerability, usbliter8, affecting Apple's A12 and A13 chips that can be exploited via a specific USB sequence at startup to gain code execution and boot unsigned software; because BootROM resides in hardware, software updates cannot patch it, leaving affected devices vulnerable for life. A12 is easier to exploit, A13 requires bypassing PAC, A11 is unaffected and A14+ are safe; Apple was notified and a full PoC was published.