An unpatchable Apple chip flaw now has public proof-of-concept code, giving researchers a new low-level route into older iPhones built on A12 and A13 chips, according to TechCrunch.

Unpatchable Apple Chip Flaw Cracks iPhone Jailbreak Door
XOOMAR Intelligence
Analyst Take
That doesn't make an iPhone jailbreak automatic. It does something narrower, and more serious: it exposes a flaw in the Boot ROM, the first code an iPhone runs when it powers on. If attackers can compromise that stage, they can start challenging the trust chain Apple depends on before iOS even loads.
The Apple chip flaw turns older iPhones into permanent targets
Paradigm Shift, a Barcelona-based offensive cybersecurity company, published details of the vulnerability on Friday and named it “usbliter8.” The company also released a proof of concept showing how to exploit it.
The affected iPhones use Apple-made A12 and A13 chips, released in 2018 and 2019. TechCrunch names older models including the iPhone XS, iPhone XR, and devices up to the iPhone 11.
The hard part for Apple is where the bug lives. The Boot ROM is burned into the chip. Once shipped, that code can't be rewritten through a normal software update.
Paradigm Shift put it bluntly:
“as these vulnerabilities reside in immutable code, affected users should be aware that migrating to newer hardware remains the most effective mitigation.”
This is why the Apple chip flaw matters beyond jailbreak nostalgia. A Boot ROM exploit can give researchers, forensic vendors, government contractors, and potentially attackers a foothold at a level Apple usually keeps locked down. But TechCrunch is clear on the limit: older iPhones are not suddenly easy targets for anyone with a laptop.
How usbliter8 breaks into Apple’s early boot chain
The exploit requires physical access to the target phone. In practical terms, an attacker needs the ability to connect a cable to the device. Technical summaries from 9to5Mac say the exploit works while the device is in DFU mode, sending crafted USB data that causes the USB controller to write data into the wrong part of memory.
That matters because the earliest boot stage decides what code gets trusted. Apple normally verifies that only approved software runs. A successful Boot ROM exploit can let an attacker run code before iOS takes over.
According to 9to5Mac, Paradigm Shift described usbliter8 as involving both a hardware bug in the USB controller and a configuration flaw in device firmware. MacRumors reported that A14 and later chips are safe because they configure a memory protection feature correctly at the Boot ROM level, while A12 and A13 sit in the exposed middle.
A jailbreak built on this kind of access can allow unsigned software and remove Apple-imposed restrictions. For security researchers, that can open a path to inspect iOS more deeply. For offensive operators, it can become one part of a larger chain.
That last phrase is the key. TechCrunch says hackers would still need additional vulnerabilities to access user data stored on the phone. The exploit also does not directly compromise the Secure Enclave, according to 9to5Mac and MacRumors. Paradigm Shift warned, though, that it opens wider attack vectors against it.
The numbers that define the risk for older iPhones
The risk is not evenly spread. It depends on the chip, the device, the attacker’s access, and whether other exploit components exist.
| Chip | Devices named in supplied reporting | usbliter8 status | Practical exposure |
|---|---|---|---|
| A12 | iPhone XR, iPhone XS/XS Max, iPad Air 3, iPad mini 5, iPad 8, second-generation Apple TV 4K | Affected | Physical-access risk, more relevant if a device is seized, stolen, or used in research |
| S4/S5 | Apple Watch Series 4, Apple Watch Series 5, first-generation Apple Watch SE, HomePod mini | Listed by 9to5Mac as affected SoCs | Device impact depends on implementation and available exploit paths |
| A13 | iPhone 11/11 Pro/11 Pro Max, second-generation iPhone SE, iPad 9, Studio Display | Affected | Harder to exploit than A12 because of Pointer Authentication Codes |
| A12X/Z | 2018 and 2020 iPad Pro lineups | “technical support” described as possible, not implemented | Unclear based on supplied material |
| A14 and later | Later Apple chip generations | Reported as safe from this issue | Not affected by usbliter8 as described |
The clearest high-risk scenario is not a fully updated phone sitting in someone’s pocket. It is a device already in someone else’s hands, especially where forensic unlocking, targeted intrusion research, or chained vulnerabilities are in play.
That distinction matters for ordinary users. Your photos, messages, banking apps, and passwords do not become exposed merely because a proof of concept exists. The attacker still needs the right device, physical access, technical steps, and likely other vulnerabilities.
For readers tracking Apple’s older-device story from the product side, XOOMAR’s look at 5 iOS 27 Features Rescue Older iPhones From Clutter covers a different pressure point: keeping aging hardware useful. usbliter8 shows the security tradeoff that can sit underneath that same hardware life cycle.
Researchers, Apple defenders, and forensic firms each see a different asset
For jailbreak researchers, usbliter8 is valuable because public Boot ROM exploits have become rare. TechCrunch notes that public iPhone jailbreaks were once relatively widespread, but have become rarer over the last decade.
There is a simple incentive problem. Researchers who find valuable iPhone flaws often have little reason to publish them. Once Apple learns enough to fix software bugs, those researchers lose the advantage.
For Apple, the picture is mixed. The flaw is serious because it lives in immutable code. But the Secure Enclave caveat matters. So does the physical-access requirement. Apple’s broader security architecture still forces attackers to assemble more than one piece before reaching protected user data.
For offensive security vendors, the calculus is different. TechCrunch says companies that sell systems to hack iPhones seized by authorities, including Cellebrite and Magnet Forensics, need and likely already have techniques similar to usbliter8. Public release narrows the gap between private capability and public research.
For criminals, the exploit is not a push-button theft tool based on the supplied facts. It is a potential building block. That is still meaningful.
XOOMAR has seen a similar pattern in peripheral security coverage, where proximity or physical conditions shape real-world exposure, as in Beats Studio Buds Flaw Let Nearby Hackers Tap Mics. The lesson is the same: access conditions decide whether a vulnerability is theoretical noise or operationally useful.
From checkm8 to usbliter8, Apple’s old hardware problem keeps returning
The obvious comparison is checkm8, the unpatchable Boot ROM exploit released in 2019. MacRumors says checkm8 affected devices from the iPhone 4S through the iPhone X. usbliter8 extends that lineage into the next chip generation, covering iPhone XS through iPhone 11 series devices.
That history is why the jailbreak angle has weight. Checkm8 became the basis for multiple jailbreak tools targeting older iPhones and iPads. 9to5Mac says the same could happen with devices affected by usbliter8.
The deeper lesson is harsher. Apple can make iPhones extremely difficult to attack, and TechCrunch says it has done so. But if the earliest trust layer contains a permanent flaw, older hardware carries that exposure for the rest of its life.
The jailbreak community has changed around that fact. The center of gravity is no longer just consumer customization. Based on TechCrunch’s framing, the audience now includes independent researchers, government-linked contractors, spyware makers, and forensic vendors.
What iPhone owners and organizations should do with this
For most regular users, this is not panic time. It is inventory time.
If you own a potentially affected device, identify the model and chip generation. Keep it on the latest supported software. Use a strong passcode. Avoid unknown USB accessories and situations where someone else can connect your device to a cable.
For higher-risk users and organizations, the bar is higher. XOOMAR analysis: the most relevant question is whether older A12 and A13 devices still handle sensitive work. If they do, replacement becomes the only mitigation explicitly supported by Paradigm Shift’s own statement.
Refurbished and secondhand buyers should pay attention too. A permanent hardware vulnerability does not make a device useless, but it changes the security profile in a way software updates cannot erase.
The next evidence to watch is concrete: whether public jailbreak tools adopt usbliter8, whether researchers chain it with other vulnerabilities, and whether more affected device classes get working support. The iPhone’s security reputation remains intact, but this Apple chip flaw shows the uncomfortable rule of hardware bugs: they don’t disappear. The devices eventually have to.
Impact Analysis
- The flaw affects the Boot ROM, meaning Apple cannot fully fix it with a standard iOS update.
- Public proof-of-concept code gives researchers and attackers a new low-level path into older iPhones.
- Exploitation still requires physical access, limiting immediate risk for most users.
Affected vs. safer iPhone hardware
| Category | Details | Risk/Mitigation |
|---|---|---|
| Older iPhones with A12/A13 chips | Includes iPhone XS, iPhone XR, and devices up to iPhone 11 | Boot ROM flaw cannot be patched through normal software updates |
| Newer iPhone hardware | Devices beyond the affected A12 and A13 chip generations | Migrating to newer hardware is described as the most effective mitigation |
Sources
Written by
XOOMAR Insights Team
Research and Editorial Desk
The XOOMAR Insights Team pairs automated research with human editorial judgment. We track hundreds of sources across technology, fintech, trading, SaaS, and cybersecurity, cross-check the facts, and explain what happened, why it matters, and what to watch next. We do not just rewrite headlines. Every article is fact-checked and scored for reliability before it goes live, and we link back to the original sources so you can verify anything yourself.
Explore More Topics
Related Articles
CybersecurityApp Store Crypto Scam Drags Apple Into $1.8M Fight
Apple faces a lawsuit after users say a fake Sparrow Wallet on the App Store drained $1.8M in Bitcoin, testing its safety pitch.
CybersecurityExit Gap Haunts Apple OpenAI Lawsuit Over Data Access
Apple says a former employee got back into its network after joining OpenAI. Offboarding just became a live security fight.
CybersecuritySecurity Chaos Floods Apple Bug Bounties With AI Slop
A flood of AI-generated reports is overwhelming companies like Apple, forcing them to cap bug bounties as attacks swamp ports, banks, and infrastructure in a se
CybersecuritySamsung Smart TV Apps Caught Renting Out Your Home IP
Samsung is banning smart TV apps with proxy code that could quietly route strangers through users' home internet connections.
CybersecurityFTC Says Hims & Hers Fed Patient Data to Ad Giants
The FTC says Hims & Hers shared sensitive health data with ad platforms, turning telehealth growth tactics into a major privacy fight.
TechnologySamsung's Galaxy Watch Ultra 2 Beats Apple Watch in Run Test
In a real-world 10K test, the Samsung Galaxy Watch Ultra 2 outperformed the Apple Watch Ultra 2 for a dedicated runner in three key areas, challenging Apple's p
TechnologyApple's Ted Lasso Season 4 Streams August 5
Ted Lasso Season 4 premieres August 5 exclusively on Apple TV+ with a weekly episode release. This guide shows you how to stream it instantly.
TechnologyBluesky Hides Reposts From That One Annoying Account
Bluesky added a feature allowing users to hide reposts from specific accounts they follow, a targeted tool for feed curation without unfollowing.
TradingStrait of Hormuz Shutdown Lifts Oil Prices 6%
WTI crude oil jumped over 6% after Iran confirmed talks on shipping routes don't mean the Strait of Hormuz will reopen, setting the stage for a prolonged geopol
FintechErebor Quadruples Deposits In 100 Days For $8B Valuation
Startup-focused Erebor Bank has quadrupled deposits in three months and is now raising $1.5 billion at an $8 billion valuation, a giant bet on its post-SVB nich
Don't miss the signal
Get our weekly roundup of the stories that matter across tech, fintech, and trading. No noise, just signal.
Free forever. No spam. Unsubscribe anytime.