Security researchers from Paradigm Shift disclose a new, unpatchable BootROM/SecureROM vulnerability called “usbliter8,” targeting Apple chips used in a wide range of devices. Because BootROM code is permanently embedded in silicon during manufacturing, the flaw cannot be corrected through software updates, meaning affected hardware remains vulnerable for its lifetime.
The exploit uses a hardware weakness involving the USB boot process. Researchers say it requires physical USB access and the device to be in DFU mode (Device Firmware Update). During startup, carefully crafted USB data manipulates the USB controller’s handling of memory so an attacker can achieve code execution before iOS loads, and bypass normal boot integrity checks to boot modified software.
Across sources, the affected SoCs include Apple A12 and A13, with additional mention of S4 and S5 chips for certain Apple Watch and related products. Researchers also state the exploit does not directly compromise the Secure Enclave (SEP), though they note that BootROM compromise can open additional attack paths. A proof-of-concept and technical details are reported as published after coordinated disclosure efforts with Apple Product Security.