Cybersecurity researchers from the Paradigm Shift group have unveiled a serious structural flaw affecting older iPhone generations.
At the heart of the investigations are the Apple A12 Bionic and A13 Bionic, components that govern the operation of devices that have seen widespread commercial deployment since 2018.
Unlike typical software vulnerabilities, this particular weakness cannot be resolved by distributing an operating system update.
The anomaly resides within the BootROM, also known as SecureROM, i.e., the very first portion of code the device executes at the exact moment it is powered on.
Because these instructions are physically embedded into the chip during factory production, the company is literally unable to release a patch to fix it.
The defect, which researchers have dubbed usbliter8, is rooted in the USB controller and is completely detached from the iOS software environment.
During the normal boot sequence, the iPhone receives streams of information divided into tiny data packets. The USB controller has the delicate task of directing these elements, routing them to the appropriate buffer memory. The flaw manifests when the device receives packets of unusually small size and sent at a precise cadence.
This specific alteration can confuse the internal hardware pointer, which, instead of advancing regularly to position the next packet, retreats anomalously. As a direct consequence, the information is written and stored in sectors of the system that should remain absolutely inaccessible.
Exploiting this mechanism, a third party with physical access to the smartphone can force the execution of a customized code and boot a modified software even before the original operating system takes control of the device.
However, there is a reassuring detail confirmed by the analysts themselves: even if the weakness were actively exploited, the user’s unlock codes and all data protected by encryption remain inviolable.
Despite the security of personal data, the conclusions drawn by the Paradigm Shift experts are alarming. The architectures of earlier processors, such as the A11, are protected because the pointer automatically resets after each packet. Similarly, versions from the A14 onward are immune thanks to fixes applied directly on the assembly line.
For all users using the A12 and A13 generation chips, total invulnerability is guaranteed only by purchasing a newer iPhone model.
The discovery of “usbliter8” lengthens the list of hardware-compromised devices, joining the previous issue “checkm8” that emerged in 2019. Below is the list of iPhones exposed to these variants of the BootROM defect:
The future of OPPO will be in line with that of OnePlus and Realme: according…
The next flagship series from the Chinese company should arrive fully in international markets as…
The need to hide private details before sharing an image is an increasingly common requirement,…
Steam becomes the real protagonist of household cleaning with Roborock F25 Steam, the new vacuum-mop…
Currently the tech sector is facing a period of constant price increases, largely justified by…
Instagram has decided to intervene firmly against a worrying trend: the spread of videos filmed…