Apple Chip Bug Leaves Affected iPhones Permanently Exposed

Sophia Taylor

By Sophia Taylor

Published:

Security researchers have disclosed a hardware flaw in some older Apple devices that could help hackers jailbreak iPhones and bypass important security protections. The vulnerability, called usbliter8, affects Apple A12 and A13 chips, which were used in models including the iPhone XS, iPhone XR and iPhone 11.

The flaw was found by Paradigm Shift, a Barcelona-based offensive cybersecurity company. The company also released a proof-of-concept exploit showing how the vulnerability could be used. While the finding is serious, it does not mean affected iPhones can be hacked remotely or easily by ordinary criminals.

Why the flaw cannot be patched

The issue affects the iPhone’s Boot ROM, which is one of the first pieces of code that runs when the device is powered on. Because this code is built into the chip itself, Apple cannot fix the flaw with a normal software update. That makes the vulnerability effectively unpatchable on affected hardware.

In simple terms, the bug is linked to how the chips handle data sent over USB. Researchers found that the affected chips do not properly reset certain memory addresses between data transfers. This can allow unauthorized code to be placed into protected parts of the chip.

That could help an attacker bypass some of Apple’s usual security checks and jailbreak the device. Jailbreaking removes Apple’s restrictions on iOS and can allow much deeper access to the system than Apple normally permits. In the wrong hands, that could support more serious attempts to extract data from a device.

Physical access is required

This is not a typical remote cyberattack. An attacker would need physical access to the iPhone and would have to connect it to specialist equipment. That means someone cannot exploit this flaw just by sending a text message, making a call or tricking a user into opening a link.

The risk is therefore highest if an affected iPhone is lost, stolen, seized or otherwise taken out of the owner’s control. It may also be more relevant for people who face targeted attacks, such as journalists, activists, executives, government workers or anyone handling sensitive information.

Which devices are affected?

The vulnerability affects Apple A12 and A13 chips used in older iPhones, including the iPhone XS, iPhone XR and iPhone 11. It also affects related chips used in other older Apple devices.

These include the S4 chip in the Apple Watch Series 4 and the S5 chip used in the Apple Watch Series 5, first-generation Apple Watch SE and HomePod mini.

Newer Apple devices using A14 chips or later are not affected by this specific flaw. Devices using chips older than A12 are also outside the scope of usbliter8, although very old devices may carry other risks if they no longer receive regular security updates.

For most everyday users, the practical advice is straightforward. Keep your iPhone physically secure, use a strong passcode and continue installing iOS updates when they are available. Updates cannot fix this hardware flaw, but they still protect against many other security issues.

Anyone relying on an iPhone XS, XR or iPhone 11 for highly sensitive work may want to consider upgrading.