Apple's A12 and A13 Chips Facing New Unpatchable Exploit - MacRumorsOpen MenuShow RoundupsShow Forums menuVisit ForumsOpen Sidebar
Skip to Content

Apple's A12 and A13 Chips Facing New Unpatchable Exploit

Security research firm Paradigm Shift today published details of a new BootROM vulnerability affecting Apple's A12 and A13 chips, along with a working proof-of-concept exploit named "usbliter8."

iPhone 11 Pro Feature Green
The BootROM, or SecureROM, is the first code an iPhone runs when it powers on. Because it is baked directly into the chip at manufacture, any vulnerability found there cannot be fixed with a software update, meaning affected devices will remain vulnerable for the rest of their lives.

The last publicly known BootROM exploit of this kind was "checkm8," released in 2019 which affected devices from the iPhone 4S through to the iPhone X. usbliter8 now extends that history to the next generation of chips, covering the iPhone XS through to the iPhone 11 series.

The exploit works by taking advantage of a bug in the USB controller built into Apple's chips. When an iPhone receives USB data during startup, the controller uses a memory buffer to store incoming packets. Paradigm Shift found that by sending a specific sequence of unusually small packets, they could manipulate an internal hardware pointer in a way that causes it to walk backwards through memory, allowing data to be written to locations it should never reach. The researchers say this appears to be a bug in the USB controller hardware itself, not in Apple's software.

The A11 chip, used in the iPhone X, is not affected because its USB driver manually resets the pointer after each packet. A14 and later chips are also safe, as they configure a memory protection feature correctly at the BootROM level. The A12 and A13 sit in a vulnerable middle ground between the two.

On A12 devices, gaining code execution is relatively straightforward. On A13 devices, things are considerably harder because Apple introduced a security feature called Pointer Authentication Codes (PAC), which detects and blocks certain types of memory tampering. Paradigm Shift says working around PAC on the A13 required a lengthy multi-step process before the researchers could finally take control of the processor.

Once in control, the exploit installs a custom handler that survives a device restart and adds two capabilities: temporarily lowering the device's security settings, and booting unsigned software without any verification checks. It also injects the traditional "PWND" string into the iPhone's USB serial number as a signal that the device has been compromised, a convention that carries over from checkm8 and earlier exploits.

Paradigm Shift notes that while usbliter8 does not affect the Secure Enclave directly, a BootROM compromise of this kind opens up wider avenues for attacking it. The firm says it reported its findings to Apple Product Security before publication and worked with Apple on coordinated disclosure. The full proof-of-concept code has been published alongside the write-up at ps.tc.

Related Forum: iPhone

Popular Stories

Dynamic Island iPhone 18 Pro Feature

12 Reasons to Wait for the iPhone 18 Pro

Thursday June 18, 2026 2:17 am PDT by
We're only three months out from the launch of Apple's premium next-generation smartphone lineup, and while we're not expecting a sea change in terms of functionality, there are still several enhancements rumored to be coming to the iPhone 18 Pro and iPhone 18 Pro Max. One thing worth noting is that Apple is reportedly planning a major change to its iPhone release cycle this year, adopting a ...
Apple Watch Ultra Orange Alpine Loop Action button 220907 big

Apple Explains Why watchOS 27 Drops Support for So Many Models

Friday June 19, 2026 6:07 am PDT by
Apple today detailed why five Apple Watch models will miss out on watchOS 27 and the new Siri AI features that come with it. The Apple Watch Series 6, 7, 8, SE 2, and the original Apple Watch Ultra will not receive watchOS 27, and will only get basic security updates going forward. With the update, Apple is effectively dropping three years' worth of device support in a single software...
Rivian Explains Why CarPlay Debate Will Become Completely Obsolete Feature

iOS 27 Adds Major New Feature to CarPlay

Wednesday June 17, 2026 9:10 am PDT by
Last year, Apple revealed that it was planning to allow CarPlay users to watch video via AirPlay in their vehicles while they are not driving, and the company finally provided more specific details about this functionality at WWDC 2026. In a WWDC 2026 video aimed at developers, Apple said the CarPlay video feature is available in new vehicles that support it. When playing a video in an...

Top Rated Comments

Shin-Ra Avatar
2 days ago at 10:06 am
Here is the complete list of Apple devices powered by the A12, A12X, A12Z, and A13 chips, ordered chronologically by their release date:


A12 Bionic Devices [wiki ('https://en.wikipedia.org/wiki/Apple_A12')]

* iPhone XS: September 21, 2018
* iPhone XS Max: September 21, 2018
* iPhone XR: October 26, 2018
* iPad Air (3rd generation): March 18, 2019
* iPad mini (5th generation): March 18, 2019
* iPad (8th generation): September 18, 2020
* Apple TV 4K (2nd generation) (no external USB/Lightning access): May 21, 2021


A12X Bionic Devices [wiki ('https://en.wikipedia.org/wiki/Apple_A12X')]

* iPad Pro 11-inch (1st generation): November 7, 2018
* iPad Pro 12.9-inch (3rd generation): November 7, 2018


A12Z Bionic Devices [wiki ('https://en.wikipedia.org/wiki/Apple_A12X')]

* iPad Pro 11-inch (2nd generation): March 25, 2020
* iPad Pro 12.9-inch (4th generation): March 25, 2020
* Developer Transition Kit (Mac mini prototype): June 22, 2020


A13 Bionic Devices [wiki ('https://en.wikipedia.org/wiki/Apple_A13')]

* iPhone 11: September 20, 2019
* iPhone 11 Pro: September 20, 2019
* iPhone 11 Pro Max: September 20, 2019
* iPhone SE (2nd generation): April 24, 2020
* iPad (9th generation): September 24, 2021
* Apple Studio Display: March 18, 2022
Score: 50 Votes (Like | Disagree)
2 days ago at 09:24 am
Me with a 14 pro and M2 iPad Pro thinking I'm just fine...then realizing "Oh no, my 2022 Studio Display!"
Score: 34 Votes (Like | Disagree)
vegetassj4 Avatar
2 days ago at 09:49 am
Whew, lucky I'm still rocking this bad boy



Attachment Image
Score: 29 Votes (Like | Disagree)
Jseeker Avatar
2 days ago at 09:38 am
it would be helpful if the article listed effected devices.
Score: 28 Votes (Like | Disagree)
Westside guy Avatar
2 days ago at 09:31 am
If the jailbreaking community was still active, this could've ended up being very useful. I miss those days...
Score: 25 Votes (Like | Disagree)
2 days ago at 09:33 am

Are the current Neo...
Did you read the post?

...and future generations of Mac run by phone chip be affected?
Ask AI - maybe it's going to hallucinate a response for you.
Score: 16 Votes (Like | Disagree)