Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
New BootROM Exploit Threatens iPhone Security

New BootROM Exploit Threatens iPhone Security

Posted on June 22, 2026 By CWS

European cybersecurity firm Paradigm Shift has unveiled a critical vulnerability dubbed Usbliter8, which targets Apple’s BootROM. This exploit affects millions of iPhones and is immune to software patches, posing a significant risk to devices.

Understanding the Usbliter8 Exploit

Usbliter8 specifically attacks the SecureROM, an integral part of the iPhone’s System on Chip (SoC) that initializes during startup. This exploit combines a flaw in the USB controller with a device firmware configuration weakness. It requires physical access to the device via USB, affecting iPhones with A12 and A13 chips, such as the iPhone XS, XR, and 11, as well as Apple Watches with S4 and S5 chips, all released in 2018 and 2019.

The attack mechanism involves connecting a specialized USB device, like a Raspberry Pi Pico 2, to the target iPhone. By sending crafted USB setup packets, the attacker can trigger an out-of-bounds write operation, allowing them to overwrite crucial memory data, thereby gaining control over the processor and executing arbitrary code at the system level.

Potential Impact and Security Implications

Despite bypassing Apple’s signature checks and enabling full code execution before the operating system loads, Usbliter8 does not grant direct access to user data. Apple’s Secure Enclave Processor (SEP), responsible for protecting user data, remains unaffected. However, the exploit opens up possibilities for broader attacks on the Secure Enclave.

While remote attacks are not feasible with Usbliter8, its potential utility for forensic vendors is noteworthy. The exploit’s impact is akin to Checkm8, a 2019 BootROM vulnerability that left many iPhones vulnerable to jailbreaks.

Apple’s Response and Future Outlook

Paradigm Shift reported the exploit to Apple ahead of public disclosure, but the tech giant has yet to issue a public statement. SecurityWeek is awaiting further comments from Apple on the matter. Meanwhile, Paradigm Shift has released proof-of-concept (PoC) code to highlight the practical implications of such hardware vulnerabilities and to enhance understanding of modern BootROM security challenges.

The release of this research underscores a continuing challenge for Apple in securing even the latest generations of SecureROM against hardware-based exploits. As the tech industry watches closely, the company will need to address these vulnerabilities to maintain the integrity of its devices.

Security Week News Tags:A12 and A13 chips, Apple vulnerability, BootROM exploit, checkm8, Cybersecurity, Forensics, iPhone security, Secure Enclave, SecureROM, usbliter8

Post navigation

Previous Post: Canada’s Spy Agency Neutralizes Botnets with Unique Warrant
Next Post: GitHub Strengthens Actions Security with New Checkout Update

Related Posts

Hackers Stole Data From Public Safety Comms Firm BK Technologies Hackers Stole Data From Public Safety Comms Firm BK Technologies Security Week News
CISO Burnout – Epidemic, Endemic, or Simply Inevitable? CISO Burnout – Epidemic, Endemic, or Simply Inevitable? Security Week News
GitHub Breach Affects 3,800 Repositories in Major Hack GitHub Breach Affects 3,800 Repositories in Major Hack Security Week News
Alleged Conti, TrickBot Gang Leader Unmasked Alleged Conti, TrickBot Gang Leader Unmasked Security Week News
Hundreds of N-able N-central Instances Affected by Exploited Vulnerabilities Hundreds of N-able N-central Instances Affected by Exploited Vulnerabilities Security Week News
Chipmaker Patch Tuesday: Intel, AMD, Arm Respond to New CPU Attacks Chipmaker Patch Tuesday: Intel, AMD, Arm Respond to New CPU Attacks Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Linux Kernel Bridge Vulnerability Exposes Security Risks
  • Future Cyber Risks: Insights from Edna Conway
  • Weak RNG in CryptoJS Leads to $5.7M Crypto Wallet Drains
  • AI Models Uncover Vulnerabilities, Risk Network Security
  • Paperclip Security Flaw Risked Code Execution

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Linux Kernel Bridge Vulnerability Exposes Security Risks
  • Future Cyber Risks: Insights from Edna Conway
  • Weak RNG in CryptoJS Leads to $5.7M Crypto Wallet Drains
  • AI Models Uncover Vulnerabilities, Risk Network Security
  • Paperclip Security Flaw Risked Code Execution

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark