惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

M
MIT News - Artificial intelligence
WordPress大学
WordPress大学
GbyAI
GbyAI
S
SegmentFault 最新的问题
量子位
爱范儿
爱范儿
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
MyScale Blog
MyScale Blog
人人都是产品经理
人人都是产品经理
博客园 - 叶小钗
aimingoo的专栏
aimingoo的专栏
V
Visual Studio Blog
U
Unit 42
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
The Cloudflare Blog
Stack Overflow Blog
Stack Overflow Blog
博客园 - 聂微东
J
Java Code Geeks
The GitHub Blog
The GitHub Blog
Y
Y Combinator Blog
IT之家
IT之家
Martin Fowler
Martin Fowler
宝玉的分享
宝玉的分享
雷峰网
雷峰网

Android Authority

I know YouTube Music is flawed, yet I prefer it over Spotify Survey reveals 50% of users don’t like the new Google Health app It’s time for Samsung’s S Pen to evolve or die The Motorola Moto G Stylus (2026) is a sequel we didn’t need NotebookLM is quickly becoming the podcast app I didn’t know I needed Samsung’s next Galaxy Watch update could finally make your health data useful Google’s Gemini Spark is ready to run your digital errands while your phone is off Telegram’s finally getting an official Wear OS app again Nintendo is back on mobile, and it wants to turn your selfies into minigames Google Drive’s big document scanner overhaul is finally here — don’t overlook its power Spotify will finally give you real profile tools to make music listening more social Acer’s new gaming handheld might dodge the worst of tech inflation Meta is cooking up a new line of smart glasses, and they may not be Ray-Bans ChatGPT is retiring this beloved legacy model in June Is Microsoft Copilot not working? Here’s what’s going on (Update: Back up) Samsung Gallery starts quietly ending OneDrive support ahead of schedule Here’s a first look at custom wallpapers in Google Messages Rivian is pretty sure customers want AI, not Android Auto Leaked iPhone 18 Pro dummy units may have just shown the next Android phone color trend A company spent $500 million in one month after forgetting to set AI usage limits Now even MediaTek’s cheap chips are embarrassing the Tensor G5 in one major area Pixel 10 Pro XL user says Google returned their phone worse than dead The best robot pool cleaners of 2026: Top picks for all budgets and pool sizes Claude Opus 4.8 is more honest, less deceptive, and considerably cheaper Roborock’s Qrevo Curv 2 Flow is ready to mop up the competition — and your filthy floors Google is making it easier to share Gemini chats, media, and more with your team One UI 9 borrows one of the iPhone’s most useful call features This is the biggest mistake Oura is making with the Oura Ring 5 This Verizon user owed $400, but the carrier made an unexpected move Google’s Fitbit Air makes a strong case for minimalism and ditching your smartwatch
Your aging iPhone might be vulnerable to a flaw Apple can...
Akshay Gangwar · 2026-06-19 · via Android Authority
iPhone 11 Pro Max Rear in Hand

TL;DR

  • A new BootROM vulnerability has been discovered in older iPhones using the A12 and A13 chips.
  • It uses a hardware bug in the USB controller to gain access to an iPhone’s startup process.
  • It can’t be patched, and the only way to mitigate it is to switch to a device with a newer processor.

iPhones are not immune to vulnerabilities and exploits. They’ve previously suffered hardware-level exploits like checkm8, and widespread, easy-to-use ones like DarkSword. Now, researchers have found and exploited a new hardware-level BootROM vulnerability on iPhones.

Researchers at Paradigm Shift published an extremely detailed post explaining the “usbliter8” exploit, which leverages a hardware bug in the USB controller and a firmware configuration flaw.

The exploit takes advantage of a flaw in the iPhone’s USB hardware. By sending specially crafted USB data during startup, an attacker can confuse the controller into writing data to the wrong area of memory. This occurs before iOS loads, allowing the attacker to gain control of the boot process and run unauthorized code on the device.

The attack is a bit harder to pull off on devices powered by Apple’s A13 chip because Apple added an extra security feature called Pointer Authentication (PAC). This protection is designed to stop attackers from hijacking important parts of the processor.

However, the researchers say they were still able to find a way around this protection and successfully exploit the chip.

Why Apple can’t fix this

Apple A13 processor

Android often gets criticized for security issues, but the usbliter8 exploit is the kind of flaw that no software update can fix. The vulnerability lies in low-level hardware code permanently built into the affected chips. This code can’t be changed after a device leaves the factory, meaning Apple can’t fix the vulnerability through a software update.

As a result, devices that are vulnerable today will remain vulnerable forever. The only way to completely avoid the flaw is to use a newer iPhone, iPad, or Apple Watch that doesn’t contain the affected chips.

The exploit works on A12 and A13 chips, as well as the S4 and S5 chips. The researchers also note that “technical support for A12X/Z is possible,” but they haven’t implemented it yet.

There’s only a tiny bit of good news here: the exploit requires physical access to the iPhone and doesn’t affect Apple’s Secure Enclave, where the iPhone stores passcodes and encrypted user data. However, the researchers state that it also opens up possible attack vectors that could compromise the Secure Enclave.

Paradigm Shift disclosed the bug to Apple before publishing it. However, since it can’t be patched, there’s really nothing Apple can do to protect those with older devices. The only silver lining here, if you’re looking for one, is that just like checkm8, usbliter8 could also be used to get a working jailbreak for older iPhones.

Thank you for being part of our community. Read our Comment Policy before posting.