Back to Home
Apple

Your old iPhone has a security flaw, and there’s nothing Apple can do to fix it

A newly disclosed exploit called usbliter8 hijacks the boot process on older iPhones with A12 and A13 chips, as well as other Apple devices. (via Cult of Mac - Your source for the latest Apple news, rumors, analysis, reviews, how-tos and deals.)

t
tech4you AI
June 20, 20263 min read
Share

Still holding onto an iPhone XS, XR or 11 because it gets the job done? There’s now a good reason to upgrade: usbliter8. This security flaw lets anyone with physical access to an older iPhone hijack the startup process, and Apple won’t be able to patch it with a software update.

That’s because it isn’t an iOS bug — the flaw is in the chip’s boot code, the first thing that runs when you turn on the device.

What the usbliter8 iPhone security flaw does

Security researchers at Paradigm Shift discovered the flaw, which they call usbliter8, publishing a detailed technical breakdown on Thursday. The firm said it worked with Apple before making the information public.

As for the flaw, it lives in the USB controller built into the older iPhone chips.  When you plug an affected iPhone into a computer while it’s in Device Firmware Update (DFU) mode, the exploit sends a specific sequence of tiny USB packets.

It tricks an internal memory pointer into going backward instead of forward, allowing attackers to write data into the wrong parts of the memory.

From there, things get worse. The attacker can plant code that survives restarts and boot a piece of software not approved by Apple. It can even stamp a “PWND” tag directly into the USB serial number, something jailbreakers have been doing for years.

Which Apple devices are affected?

The security flaw affects the iPhone XR, iPhone XS, iPhone XS Max, iPhone SE (2nd gen) and the entire iPhone 11 lineup. It also reaches way beyond your pocket. Paradigm Shift says it extends to the iPad Air 3, iPad mini 5, eight- and ninth-gen iPad, Studio Display, Apple Watch Series 4 and 5, Watch SE (1st gen), Apple TV 4K (2nd gen) and even the HomePod mini.

Researchers go on to say that “technical support for A12X/Z is possible,” but it’s “not currently implemented.” That means the iPad Pro 2018 and 2020 could end up on the list.

Notably, the security exploit does not affect the iPhone X and earlier. This is because the A11’s USB driver resets the memory pointer after every packet sent. iPhone 12 and newer are also unaffected because the A14 chip handles memory protection differently at the hardware level.

Apple’s previous device-wide BootROM scare (called checkm8) affected the iPhone 4S to the iPhone X. Now, usbliter8 picks up right where it left off.

Should you ditch your old device?

This is not a remote attack. What it means is that the attacker will need physical access to your device. And Apple’s Secure Enclave, the mechanism that protects your passcode and encrypts your data, remains unaffected.

Researchers say usbliter8 could theoretically help crack the Secure Enclave indirectly. But for now, your data isn’t up for grabs.

The team also notes that “affected users should be aware that migrating to newer hardware remains the most effective mitigation.”

If you still own an A12- or A13-powered device, this could be your sign to upgrade.


Originally published on Cult of Mac

Related Articles

Amazon slashes Apple Watch Series 11 to $279 in early Prime Day saleApple

Amazon slashes Apple Watch Series 11 to $279 in early Prime Day sale

Save $120 to $200 on the Apple Watch Series 11 with new early Prime Day deals, as Amazon drops prices on numerous styles.Save up to $200 with early Prime Day Apple Watch Series 11 deals - Image credit: AppleAmazon's early Prime Day Apple Watch sale includes discounts across the entire wearable line, but we're pleased to see the Apple Watch Series 11 has received a steeper price drop today, bringing the wearable down to $279. Save $120 to $200 on numerous styles, including 46mm case options and G

Jun 22, 20261 min
These are the best new MacBook deals currently: June 2026 Buyer’s GuideApple

These are the best new MacBook deals currently: June 2026 Buyer’s Guide

In the era of Apple Silicon, MacBooks are more affordable than ever. Nowadays, you can buy a MacBook Air with 512GB of storage and 16GB of memory for $1099 directly from Apple, when such a configuration would’ve cost $1599 just a few years ago. And on top of that, we have MacBook Neo bringing the entry-point down substantially. That said, Apple has warned that there will be price hikes in the future because of the AI-induced memory crisis, so now might be a good time to buy if you’re in the mark

Jun 22, 20264 min
Apple Wallet’s Digital ID feature could potentially have a major new use case soonApple

Apple Wallet’s Digital ID feature could potentially have a major new use case soon

Last year, Apple debuted Digital ID on iPhone, allowing users to use their US passport as identification in Apple Wallet. Apple’s been rolling out drivers licenses in Wallet slowly over the past few years, but that’s on a state-by-state basis. Digital ID is universal, allowing anyone with a passport to use it. Of course, you can use it at TSA checkpoints in airports – but Apple had a bigger scope in mind: digital age and identity verification. While not yet confirmed, it’s possible that we could

Jun 22, 20262 min