XOOMAR
Disassembled smartphone chip with USB cable, broken security shield, and dark cybersecurity visuals.
CybersecurityJune 22, 2026· 8 min read· By XOOMAR Insights Team

Unpatchable Apple Chip Flaw Cracks iPhone Jailbreak Door

Share
Updated on June 23, 2026

XOOMAR Intelligence

Analyst Take

58/ 100
Moderate
4 sources analyzedLow confidenceTrend10Freshness97Source Trust90Factual Grounding91Signal Cluster20

That doesn't make an iPhone jailbreak automatic. It does something narrower, and more serious: it exposes a flaw in the Boot ROM, the first code an iPhone runs when it powers on. If attackers can compromise that stage, they can start challenging the trust chain Apple depends on before iOS even loads.

The Apple chip flaw turns older iPhones into permanent targets

Paradigm Shift, a Barcelona-based offensive cybersecurity company, published details of the vulnerability on Friday and named it “usbliter8.” The company also released a proof of concept showing how to exploit it.

The affected iPhones use Apple-made A12 and A13 chips, released in 2018 and 2019. TechCrunch names older models including the iPhone XS, iPhone XR, and devices up to the iPhone 11.

The hard part for Apple is where the bug lives. The Boot ROM is burned into the chip. Once shipped, that code can't be rewritten through a normal software update.

Paradigm Shift put it bluntly:

“as these vulnerabilities reside in immutable code, affected users should be aware that migrating to newer hardware remains the most effective mitigation.”

This is why the Apple chip flaw matters beyond jailbreak nostalgia. A Boot ROM exploit can give researchers, forensic vendors, government contractors, and potentially attackers a foothold at a level Apple usually keeps locked down. But TechCrunch is clear on the limit: older iPhones are not suddenly easy targets for anyone with a laptop.


How usbliter8 breaks into Apple’s early boot chain

The exploit requires physical access to the target phone. In practical terms, an attacker needs the ability to connect a cable to the device. Technical summaries from 9to5Mac say the exploit works while the device is in DFU mode, sending crafted USB data that causes the USB controller to write data into the wrong part of memory.

That matters because the earliest boot stage decides what code gets trusted. Apple normally verifies that only approved software runs. A successful Boot ROM exploit can let an attacker run code before iOS takes over.

According to 9to5Mac, Paradigm Shift described usbliter8 as involving both a hardware bug in the USB controller and a configuration flaw in device firmware. MacRumors reported that A14 and later chips are safe because they configure a memory protection feature correctly at the Boot ROM level, while A12 and A13 sit in the exposed middle.

A jailbreak built on this kind of access can allow unsigned software and remove Apple-imposed restrictions. For security researchers, that can open a path to inspect iOS more deeply. For offensive operators, it can become one part of a larger chain.

That last phrase is the key. TechCrunch says hackers would still need additional vulnerabilities to access user data stored on the phone. The exploit also does not directly compromise the Secure Enclave, according to 9to5Mac and MacRumors. Paradigm Shift warned, though, that it opens wider attack vectors against it.

The numbers that define the risk for older iPhones

The risk is not evenly spread. It depends on the chip, the device, the attacker’s access, and whether other exploit components exist.

Chip Devices named in supplied reporting usbliter8 status Practical exposure
A12 iPhone XR, iPhone XS/XS Max, iPad Air 3, iPad mini 5, iPad 8, second-generation Apple TV 4K Affected Physical-access risk, more relevant if a device is seized, stolen, or used in research
S4/S5 Apple Watch Series 4, Apple Watch Series 5, first-generation Apple Watch SE, HomePod mini Listed by 9to5Mac as affected SoCs Device impact depends on implementation and available exploit paths
A13 iPhone 11/11 Pro/11 Pro Max, second-generation iPhone SE, iPad 9, Studio Display Affected Harder to exploit than A12 because of Pointer Authentication Codes
A12X/Z 2018 and 2020 iPad Pro lineups “technical support” described as possible, not implemented Unclear based on supplied material
A14 and later Later Apple chip generations Reported as safe from this issue Not affected by usbliter8 as described

The clearest high-risk scenario is not a fully updated phone sitting in someone’s pocket. It is a device already in someone else’s hands, especially where forensic unlocking, targeted intrusion research, or chained vulnerabilities are in play.

That distinction matters for ordinary users. Your photos, messages, banking apps, and passwords do not become exposed merely because a proof of concept exists. The attacker still needs the right device, physical access, technical steps, and likely other vulnerabilities.

For readers tracking Apple’s older-device story from the product side, XOOMAR’s look at 5 iOS 27 Features Rescue Older iPhones From Clutter covers a different pressure point: keeping aging hardware useful. usbliter8 shows the security tradeoff that can sit underneath that same hardware life cycle.


Researchers, Apple defenders, and forensic firms each see a different asset

For jailbreak researchers, usbliter8 is valuable because public Boot ROM exploits have become rare. TechCrunch notes that public iPhone jailbreaks were once relatively widespread, but have become rarer over the last decade.

There is a simple incentive problem. Researchers who find valuable iPhone flaws often have little reason to publish them. Once Apple learns enough to fix software bugs, those researchers lose the advantage.

For Apple, the picture is mixed. The flaw is serious because it lives in immutable code. But the Secure Enclave caveat matters. So does the physical-access requirement. Apple’s broader security architecture still forces attackers to assemble more than one piece before reaching protected user data.

For offensive security vendors, the calculus is different. TechCrunch says companies that sell systems to hack iPhones seized by authorities, including Cellebrite and Magnet Forensics, need and likely already have techniques similar to usbliter8. Public release narrows the gap between private capability and public research.

For criminals, the exploit is not a push-button theft tool based on the supplied facts. It is a potential building block. That is still meaningful.

XOOMAR has seen a similar pattern in peripheral security coverage, where proximity or physical conditions shape real-world exposure, as in Beats Studio Buds Flaw Let Nearby Hackers Tap Mics. The lesson is the same: access conditions decide whether a vulnerability is theoretical noise or operationally useful.

From checkm8 to usbliter8, Apple’s old hardware problem keeps returning

The obvious comparison is checkm8, the unpatchable Boot ROM exploit released in 2019. MacRumors says checkm8 affected devices from the iPhone 4S through the iPhone X. usbliter8 extends that lineage into the next chip generation, covering iPhone XS through iPhone 11 series devices.

That history is why the jailbreak angle has weight. Checkm8 became the basis for multiple jailbreak tools targeting older iPhones and iPads. 9to5Mac says the same could happen with devices affected by usbliter8.

The deeper lesson is harsher. Apple can make iPhones extremely difficult to attack, and TechCrunch says it has done so. But if the earliest trust layer contains a permanent flaw, older hardware carries that exposure for the rest of its life.

The jailbreak community has changed around that fact. The center of gravity is no longer just consumer customization. Based on TechCrunch’s framing, the audience now includes independent researchers, government-linked contractors, spyware makers, and forensic vendors.

What iPhone owners and organizations should do with this

For most regular users, this is not panic time. It is inventory time.

If you own a potentially affected device, identify the model and chip generation. Keep it on the latest supported software. Use a strong passcode. Avoid unknown USB accessories and situations where someone else can connect your device to a cable.

For higher-risk users and organizations, the bar is higher. XOOMAR analysis: the most relevant question is whether older A12 and A13 devices still handle sensitive work. If they do, replacement becomes the only mitigation explicitly supported by Paradigm Shift’s own statement.

Refurbished and secondhand buyers should pay attention too. A permanent hardware vulnerability does not make a device useless, but it changes the security profile in a way software updates cannot erase.

The next evidence to watch is concrete: whether public jailbreak tools adopt usbliter8, whether researchers chain it with other vulnerabilities, and whether more affected device classes get working support. The iPhone’s security reputation remains intact, but this Apple chip flaw shows the uncomfortable rule of hardware bugs: they don’t disappear. The devices eventually have to.

Impact Analysis

  • The flaw affects the Boot ROM, meaning Apple cannot fully fix it with a standard iOS update.
  • Public proof-of-concept code gives researchers and attackers a new low-level path into older iPhones.
  • Exploitation still requires physical access, limiting immediate risk for most users.

Affected vs. safer iPhone hardware

CategoryDetailsRisk/Mitigation
Older iPhones with A12/A13 chipsIncludes iPhone XS, iPhone XR, and devices up to iPhone 11Boot ROM flaw cannot be patched through normal software updates
Newer iPhone hardwareDevices beyond the affected A12 and A13 chip generationsMigrating to newer hardware is described as the most effective mitigation
XOOMAR

Written by

XOOMAR Insights Team

Research and Editorial Desk

The XOOMAR Insights Team pairs automated research with human editorial judgment. We track hundreds of sources across technology, fintech, trading, SaaS, and cybersecurity, cross-check the facts, and explain what happened, why it matters, and what to watch next. We do not just rewrite headlines. Every article is fact-checked and scored for reliability before it goes live, and we link back to the original sources so you can verify anything yourself.

Related Articles

Generic phone with fake crypto wallet app draining digital coins past a cracked security shield.Cybersecurity

App Store Crypto Scam Drags Apple Into $1.8M Fight

Apple faces a lawsuit after users say a fake Sparrow Wallet on the App Store drained $1.8M in Bitcoin, testing its safety pitch.

Jul 27, 20269 min
Departing employee silhouette near secured corporate network, illustrating offboarding data risks.Cybersecurity

Exit Gap Haunts Apple OpenAI Lawsuit Over Data Access

Apple says a former employee got back into its network after joining OpenAI. Offboarding just became a live security fight.

Jul 13, 202611 min
Close-up view of a mouse cursor over digital security text on display.Cybersecurity

Security Chaos Floods Apple Bug Bounties With AI Slop

A flood of AI-generated reports is overwhelming companies like Apple, forcing them to cap bug bounties as attacks swamp ports, banks, and infrastructure in a se

Aug 8, 20267 min
Smart TV and home router protected by a cyber shield blocking suspicious proxy connections.Cybersecurity

Samsung Smart TV Apps Caught Renting Out Your Home IP

Samsung is banning smart TV apps with proxy code that could quietly route strangers through users' home internet connections.

Aug 3, 20269 min
Telehealth patient data flowing through locks and shields toward shadowy ad network nodesCybersecurity

FTC Says Hims & Hers Fed Patient Data to Ad Giants

The FTC says Hims & Hers shared sensitive health data with ad platforms, turning telehealth growth tactics into a major privacy fight.

Jul 30, 20268 min
Close-up of a modern wristwatch on a laptop with vibrant digital wallpaper.Technology

Samsung's Galaxy Watch Ultra 2 Beats Apple Watch in Run Test

In a real-world 10K test, the Samsung Galaxy Watch Ultra 2 outperformed the Apple Watch Ultra 2 for a dedicated runner in three key areas, challenging Apple's p

Aug 10, 20267 min
A person typing on a laptop in an office, with a ping pong paddle and ball nearby.Technology

Apple's Ted Lasso Season 4 Streams August 5

Ted Lasso Season 4 premieres August 5 exclusively on Apple TV+ with a weekly episode release. This guide shows you how to stream it instantly.

Aug 10, 20266 min
A partial view of a modern laptop closed in shadow, highlighting its sleek design.Technology

Bluesky Hides Reposts From That One Annoying Account

Bluesky added a feature allowing users to hide reposts from specific accounts they follow, a targeted tool for feed curation without unfollowing.

Aug 10, 20267 min
Candlestick chart showing a downward trend in the stock market analysis.Trading

Strait of Hormuz Shutdown Lifts Oil Prices 6%

WTI crude oil jumped over 6% after Iran confirmed talks on shipping routes don't mean the Strait of Hormuz will reopen, setting the stage for a prolonged geopol

Aug 10, 20268 min
A smartphone displays a financial stock market app on a desk with a notebook and pencil.Fintech

Erebor Quadruples Deposits In 100 Days For $8B Valuation

Startup-focused Erebor Bank has quadrupled deposits in three months and is now raising $1.5 billion at an $8 billion valuation, a giant bet on its post-SVB nich

Aug 10, 20265 min

Don't miss the signal

Get our weekly roundup of the stories that matter across tech, fintech, and trading. No noise, just signal.

Free forever. No spam. Unsubscribe anytime.