Chips & Hardware
Apple chip vulnerability enables potential iPhone jailbreaks
Paradigm Shift has disclosed an unpatchable vulnerability in Apple’s A12 and A13 chips, potentially enabling jailbreaks on older iPhone models.
On Friday, Barcelona-based offensive cybersecurity company Paradigm Shift published a blog post disclosing a new vulnerability in Apple chips that can potentially help hackers unlock older iPhones. The firm dubbed the vulnerability “usbliter8” and released details of the exploit, including a proof of concept showing how to exploit it. This security flaw specifically affects iPhones powered by Apple-made A12 and A13 chips, which the technology company released in 2018 and 2019. These chips are used in older iPhone models, specifically the XS, XR, and up to the iPhone 11.
The security flaw resides in the iPhone’s Boot ROM, which is the first piece of code that runs when an iPhone is turned on and serves as its first line of defense. Because this code is burned directly into the hardware, it is immutable and cannot be patched by software updates. To exploit this vulnerability, a hacker requires physical access to the target phone, meaning they must have the ability to connect a cable to the device. Once connected, the vulnerability opens the door to a potential iPhone jailbreak, which is a technique to hack into Apple’s mobile operating system and remove restrictions. This release opens the door for other researchers, such as those working for governments or their contractors, to develop effective hacks if they can find additional vulnerabilities to chain together with this one. Because the flaw cannot be fixed, Paradigm Shift advised that “as these vulnerabilities reside in immutable code, affected users should be aware that migrating to newer hardware remains the most effective mitigation.”
The disclosure is highly relevant to security researchers, but it also highlights the broader market for mobile forensics. Companies like Cellebrite and Magnet Forensics sell systems to hack iPhones seized by authorities, often relying on hardware-level exploits to bypass device security. While the usbliter8 vulnerability provides a potential entry point for jailbreaking older devices, hackers still need to incorporate other techniques to access the user data stored in the phone. For security researchers, jailbreaking is often the first step to finding other vulnerabilities on the system, though they have few incentives to release such information publicly as Apple would quickly fix those subsequent flaws.
Why it matters
The disclosure of the usbliter8 vulnerability underscores the permanent security risks inherent in hardware-level flaws, which cannot be fixed via software updates and necessitate hardware replacement for full mitigation.