Usbliter8: an A12/A13 SecureROM Exploit
- Security
- Hardware
- Mobile
- Reverse Engineering
The post points to usbliter8, a newly disclosed SecureROM exploit for Apple’s A12 and A13 chips. SecureROM is code burned into the chip at manufacture, so a flaw there cannot be patched on affected hardware. The exploit works through the USB recovery path in DFU mode and gives code execution very early in the boot process. That makes it a big deal for jailbreak research and device reversing, especially because these chips power iPhone XR, XS, 11, SE 2nd gen, and several iPads that are still in active use.
If you build for iOS, expect renewed jailbreak and reverse-engineering activity on still-supported older devices. If you handle sensitive-device policies, do not treat this as instant passcode bypass, but do assume physical access to A12 and A13 hardware now carries a new class of boot-time risk.
- ps.tc
- Discuss on HN