Security experts from Paradigm Shift shocked the tech world today by publishing details of a newly discovered critical vulnerability in the BootROM (also known as SecureROM) for processors Apple A12 Bionic and A13 Bionic. Along with a detailed description, they also published a fully functional exploit concept called “usbliter8”. Pro Apple This is an extremely serious problem. BootROM is the very first code that the iPhone processor runs when it is turned on. Since it is “burned” into the chip during manufacturing, any errors found in it can never be fixed by any software update. Affected devices will therefore remain vulnerable for the rest of their “life”.
The successor to the legendary checkm8
The last such massive attack on iPhone hardware was the legendary “checkm8” exploit from 2019, which permanently opened the gates of all devices from the iPhone 4S to iPhone X. The new usbliter8 builds on this history and pushes the vulnerability limit a generation further. It concerns the chips powering the iPhone XS, XR series, and also the iPhone 11.
The exploit exploits a specific hardware flaw in the USB controller integrated directly into Apple chips. When iPhone During boot, the controller receives data via USB, and stores it in a buffer. The analysis showed that by sending a specific sequence of unusually small packets, an internal hardware pointer can be manipulated so that it starts moving backwards in memory. This allows an attacker to write data to locations that they should never have access to. The researchers emphasize that this is a hardware flaw, not a software flaw Appyou.
Older A11 chips (iPhone X) are safe because their USB driver manually resets the pointer after each packet. A14 and later chips are also immune because they have properly configured memory protection already at the BootROM level. ProThe A12 and A13 cesors were thus left in the unprotected center.
Permanent system signing and "PWND" signal
While running custom code is relatively straightforward with the A12 chips, the A13 generation (series iPhone 11) the experts had a much more difficult time. Apple Here, it implemented strong hardware protection called PAC (Pointer Authentication Codes), which detects and blocks memory manipulation. Bypassing it required a complex, multi-step process.
Once the attacker gains control of the processor, the exploit installs its own code that survives a reboot of the device. This can then temporarily lower the iPhone's security settings and run any unverified and unsigned software. As a clear proof of a successful breach, the exploit also injects the traditional text string "PWND" directly into the iPhone's USB serial number, a famous convention carried over from the checkm8 exploit.
You might be interested in
Paradigm Shift adds that although usbliter8 does not directly attack the secure coprocessor Secure Enclave, compromising the BootROM greatly facilitates future attacks on even this most guarded place in the iPhone. The security agency informed everyone in advance Apple and worked with the company to release the details. However, the complete code has now been published on the ps.tc website, which will undoubtedly cause a huge wave of activity in the jailbreak community.