By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Unpatchable 'usbliter8' Exploit Breaks Apple A12 and A13 SecureROM Boot Chain
Security researchers at Paradigm Shift have developed a new exploit named 'usbliter8' that allows for arbitrary code execution within the SecureROM of Apple's A12 and A13 chips. This exploit targets the SecureROM, which is a read-only memory component permanently embedded in the silicon during manufacturing, making it impossible to patch through software updates. Consequently, any device equipped with an A12 or A13 chip will remain vulnerable to this exploit for its entire operational lifespan. The researchers specified that 'usbliter8' is not a remote attack vector and requires physical access or a specific hardware interface to be initiated. The exploit leverages a vulnerability in the USB boot process, enabling attackers to gain control at the earliest stage of the device's boot sequence. This level of access bypasses all software-based security measures, including the operating system and any installed security software. The implications of this exploit are significant, as it could potentially allow for the installation of persistent malware or the extraction of sensitive data directly from the hardware. Paradigm Shift has indicated that they will release further technical details and a proof-of-concept demonstration in the near future, though they have not yet provided a specific date for this release. The affected chipsets are found in a wide range of Apple devices, including the iPhone XS, iPhone XR, iPhone 11 series, and various iPad models released between 2018 and 2019.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.