CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

usbliter8

tool · tool:usbliter8-securerom-exploit

Permanent, unpatchable SecureROM boot-chain exploit for Apple A12/A13 silicon (checkm8 successor).

Coverage
1
first 2026-06-20 → last 2026-06-20
Latest activity
2026-06-20
usbliter8, a permanent SecureROM boot-chain exploit for Apple A12/A13 silicon
Peak priority
high
1 high
Targets
technology
sectors: technology
Sources cited
3
3 hosts

Story timeline

  1. 2026-06-20usbliter8, a permanent SecureROM boot-chain exploit for Apple A12/A13 silicon
    research
ATT&CK techniques (1 across 2 tactics)

1 technique observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • PersistencePre-OS Boot: Bootkit
  • StealthPre-OS Boot: Bootkit

Persistence TA0003

T1542.003Pre-OS Boot: Bootkit×1

Adversaries may use bootkits to persist on systems. A bootkit is a malware variant that modifies the boot sectors of a hard drive, allowing malicious code to execute before a computer's operating system has loaded. Bootkits reside at a layer below the operating system and may make it difficult to perform full remediation unless an organization suspects one was used and can act accordingly.

Evidence: 2026-06-20/usbliter8-a-permanent-securerom-boot-chain-exploit-for-apple · ATT&CK page ↗

Stealth TA0005

T1542.003Pre-OS Boot: Bootkit×1

Adversaries may use bootkits to persist on systems. A bootkit is a malware variant that modifies the boot sectors of a hard drive, allowing malicious code to execute before a computer's operating system has loaded. Bootkits reside at a layer below the operating system and may make it difficult to perform full remediation unless an organization suspects one was used and can act accordingly.

Evidence: 2026-06-20/usbliter8-a-permanent-securerom-boot-chain-exploit-for-apple · ATT&CK page ↗

Entries about usbliter8 (1)

2026-06-20 · view entry permalink →

HIGH

usbliter8, a permanent SecureROM boot-chain exploit for Apple A12/A13 silicon

Paradigm Shift Technology published usbliter8 on 2026-06-18 with a full technical write-up and a working RP2350-based proof-of-concept: a software-unpatchable bootrom exploit for Apple A12 and A13 (and S4/S5) SoCs, conceptually the successor to 2019's checkm8 (Paradigm Shift, 2026-06-18). The root cause is a buffer underflow in the Synopsys DWC2 USB controller's DMA path that Apple's DART IOMMU does not block while the device is in DFU mode, allowing arbitrary SRAM overwrites; on A13 the chain additionally bypasses Pointer Authentication via heap corruption before booting unsigned iBoot images and fully subverting the chain of trust (The Hacker News, 2026-06-19). Exploitation requires physical access to a device in DFU mode connected over USB to the attacker's microcontroller and completes in under two seconds. Affected hardware spans iPhone XS/XR through the iPhone 11 line, several iPad and Apple Watch generations and the HomePod mini; A14 and later are unaffected. Because the flaw is in mask-ROM, no OS update can remediate it (MITRE ATT&CK T1542.003 Pre-OS Boot: Bootkit).

Why it matters to us: This is a physical-access risk, not a network threat, but it defeats every OS-level control (including Secure Enclave credential protections) on affected hardware. For high-security estates the practical questions are MDM supervised-mode enforcement (which can detect unmanaged DFU connections), physical custody of devices, and retiring A12/A13 hardware where physical control cannot be guaranteed.

research20 Jun 05:12Zmulti-sourceOpen finding →

explore in graph

Where this entity is cited

  • Research1

Source distribution

  • appleinsider.com1 (33%)
  • ps.tc1 (33%)
  • thehackernews.com1 (33%)