---
schema: 1
kind: research
title: usbliter8 — a permanent SecureROM boot-chain exploit for Apple A12/A13 silicon
headline: usbliter8 — a permanent SecureROM boot-chain exploit for Apple A12/A13 silicon
summary: "usbliter8 — a permanent, unpatchable SecureROM boot-chain exploit for Apple A12/A13 silicon. Working RP2350-based PoC published; a checkm8-class hardware bug (DWC2 USB DMA underflow) affecting iPhone XS through 11. Physical-access only, but it defeats Secure Enclave protections on affected devices — an MDM/device-retirement question for high-security estates (Paradigm Shift, 2026-06-18)."
discovered_at: "2026-06-20T05:12:16Z"
event_date: 2026-06-19
run_id: 2026-06-20-4cfd00ef
priority: high
immediate_action: null
tags:
  - vulnerabilities
  - poc-public
  - mobile
regions:
  - global
sectors:
  - technology
entities:
  - "tool:usbliter8-securerom-exploit"
cves: []
sources:
  - url: "https://ps.tc/pages/blog-usbliter8.html"
    publisher: Paradigm Shift Technology
    role: primary
  - url: "https://thehackernews.com/2026/06/unpatchable-usbliter8-exploit-breaks.html"
    publisher: The Hacker News
    role: corroborating
  - url: "https://appleinsider.com/articles/26/06/18/a12-a13-apple-devices-face-an-unpatchable-securerom-vulnerability"
    publisher: Apple Insider
    role: corroborating
closed_sources: []
evidence: []
verification: multi-source
sourcing_note: null
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
watchlist_hit: false
actions: []
migrated_from: briefs/2026-06-20.md
---

Paradigm Shift Technology published usbliter8 on 2026-06-18 with a full technical write-up and a working RP2350-based proof-of-concept: a software-unpatchable bootrom exploit for Apple A12 and A13 (and S4/S5) SoCs, conceptually the successor to 2019's checkm8 ([Paradigm Shift, 2026-06-18](https://ps.tc/pages/blog-usbliter8.html)). The root cause is a buffer underflow in the Synopsys DWC2 USB controller's DMA path that Apple's DART IOMMU does not block while the device is in DFU mode, allowing arbitrary SRAM overwrites; on A13 the chain additionally bypasses Pointer Authentication via heap corruption before booting unsigned iBoot images and fully subverting the chain of trust ([The Hacker News, 2026-06-19](https://thehackernews.com/2026/06/unpatchable-usbliter8-exploit-breaks.html)). Exploitation requires physical access to a device in DFU mode connected over USB to the attacker's microcontroller and completes in under two seconds. Affected hardware spans iPhone XS/XR through the iPhone 11 line, several iPad and Apple Watch generations and the HomePod mini; A14 and later are unaffected. Because the flaw is in mask-ROM, no OS update can remediate it (MITRE ATT&CK `T1542.003` Pre-OS Boot: Bootkit).

**Why it matters to us:** This is a physical-access risk, not a network threat, but it defeats every OS-level control — including Secure Enclave credential protections — on affected hardware. For high-security estates the practical questions are MDM supervised-mode enforcement (which can detect unmanaged DFU connections), physical custody of devices, and retiring A12/A13 hardware where physical control cannot be guaranteed.
