{"id":239358,"date":"2026-06-20T06:08:35","date_gmt":"2026-06-20T11:08:35","guid":{"rendered":"https:\/\/lifeboat.com\/blog\/2026\/06\/unpatchable-usbliter8-exploit-breaks-apple-a12-and-a13-securerom-boot-chain"},"modified":"2026-06-20T06:08:35","modified_gmt":"2026-06-20T11:08:35","slug":"unpatchable-usbliter8-exploit-breaks-apple-a12-and-a13-securerom-boot-chain","status":"publish","type":"post","link":"https:\/\/lifeboat.com\/blog\/2026\/06\/unpatchable-usbliter8-exploit-breaks-apple-a12-and-a13-securerom-boot-chain","title":{"rendered":"Unpatchable \u2018usbliter8\u2019 Exploit Breaks Apple A12 and A13 SecureROM Boot Chain"},"content":{"rendered":"<p style=\"padding-right: 20px\"><a class=\"aligncenter blog-photo\" href=\"https:\/\/lifeboat.com\/blog.images\/unpatchable-usbliter8-exploit-breaks-apple-a12-and-a13-securerom-boot-chain2.jpg\"><\/a><\/p>\n<p>Security researchers at Paradigm Shift have published a working exploit, dubbed <b>usbliter8<\/b>, that achieves arbitrary code execution inside the SecureROM of Apple\u2019s A12 and A13 chips.<\/p>\n<p>That code is burned into the silicon at manufacture. No software update can reach it. Affected devices will carry this flaw for as long as they stay in use.<\/p>\n<p>This is not a remote attack. It requires physical possession of the device, which must be in DFU mode and connected via USB to a dedicated RP2350-based microcontroller board. With that setup, the exploit finishes in under two seconds, before Apple\u2019s signed boot chain loads.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Security researchers at Paradigm Shift have published a working exploit, dubbed usbliter8, that achieves arbitrary code execution inside the SecureROM of Apple\u2019s A12 and A13 chips. That code is burned into the silicon at manufacture. No software update can reach it. Affected devices will carry this flaw for as long as they stay in use. [\u2026]<\/p>\n","protected":false},"author":427,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1523,1492],"tags":[],"class_list":["post-239358","post","type-post","status-publish","format-standard","hentry","category-computing","category-security"],"_links":{"self":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts\/239358","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/users\/427"}],"replies":[{"embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/comments?post=239358"}],"version-history":[{"count":0,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts\/239358\/revisions"}],"wp:attachment":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/media?parent=239358"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/categories?post=239358"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/tags?post=239358"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}