惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

T
Tailwind CSS Blog
人人都是产品经理
人人都是产品经理
博客园 - 叶小钗
大猫的无限游戏
大猫的无限游戏
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
博客园 - 【当耐特】
The Cloudflare Blog
博客园 - 聂微东
博客园 - 司徒正美
量子位
博客园 - 三生石上(FineUI控件)
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
G
Google Developers Blog
Apple Machine Learning Research
Apple Machine Learning Research
罗磊的独立博客
酷 壳 – CoolShell
酷 壳 – CoolShell
Y
Y Combinator Blog
S
SegmentFault 最新的问题
T
The Blog of Author Tim Ferriss
P
Proofpoint News Feed
Google DeepMind News
Google DeepMind News
Blog — PlanetScale
Blog — PlanetScale
有赞技术团队
有赞技术团队
A
About on SuperTechFans

Gadget Review

Bernie Sanders Wants You to Own Half of OpenAI - And He's Not Kidding - Gadget Review California Bill Strikes Back Against Disappearing Video Games - Gadget Review Japan Cracks 6G's Speed Barrier With 112 Gbps Wireless Breakthrough - Gadget Review 31 Amazon Kitchen Tools and Gadgets That Make Prep Time a Breeze The 559-Mile Mic-Drop: Why BMW’s New i3 Just Made Tesla’s Range Look Like A Toy - Gadget Review 20 Genius Camping Gadgets That Will Help Make Summer Camping Easier Tesla Patents Transform Glass Roofs Into Smart Air Conditioners - Gadget Review Is Anthropic’s “Benefit Corp” Structure An Investor’s Worst Nightmare? - Gadget Review How An AI Weather Startup Just Beat the World’s Greatest Supercomputers - Gadget Review Dell's New XPS 13 Is Directly Targeting The MacBook Neo - Gadget Review 13 Smart Home Gadgets for True Local Control (No Cloud Needed!) Florida Sues OpenAI and CEO Sam Altman - Why Florida Is Treating AI Chatbots as "Hazardous Products" - Gadget Review Malaysia’s Scorched-Earth Policy Against Under-16 Social Media Access - Ban Carries Fines Up To $2.5 Million - Gadget Review PlayStation's Wireless Fight Stick and Latest Gaming Monitor Hits This August - Gadget Review How Meta's Chatbot Handed Over Million-Dollar Instagram Accounts To Attackers - Gadget Review 11 Home Security Gadgets That Help Safeguard Your Sanctuary Engineer Builds AI-Powered Laser System That Targets & Hunts Mosquitoes at Home - Gadget Review DuckDuckGo's No-AI Search Extensions Surge as Users Flee Google's AI Overhaul - Gadget Review Google Wants to Release 32 Million "Infected" Mosquitoes Into The Wild - Gadget Review Nvidia Is Bringing AI Power To Your Desk With New Superchip - Gadget Review Tech CEOs Are Using AI as the Perfect Scapegoat for Mass Layoffs - Gadget Review Wix Cuts 1,000 Jobs, Citing AI Evolution and Currency Pressures - Gadget Review Teen's Bluetooth Speaker Named "BOMB" Forces Flight U-Turn Mid-Atlantic - Gadget Review China's Humanoid Robots Sort 1,200 Postal Packages Per Hour - Gadget Review California Senate Passes Historic Ban on AI Chatbot Toys - Gadget Review Professor Declares War on AI: Will Fail Any Student Who Uses It - Gadget Review UK Military Looks At Allowing Lethal Strikes With Zero Human Intervention - Gadget Review Chinese EVs Are Tanking in Value - Gadget Review Japanese Researchers Create Chip That Could Run 1,000x Faster, Near-Zero Heat - Gadget Review Total Immobility: Why A Single Targeted Cyberattack Could Leave Every EV In Your City Stranded - Gadget Review
Apple's A12 and A13 Chips Have an Unpatchable Flaw – What...
C. da Costa · 2026-06-20 · via Gadget Review

Physical access to A12/A13 iPhones during boot is all an attacker needs — and no iOS update can ever close the gap

Someone would need your iPhone, a USB cable, a Raspberry Pi Pico, and access during boot to pull this off. That’s the good news. The bad news: security firm Paradigm Shift has disclosed usbliter8,” a BootROM exploit targeting Apple’s A12 and A13 custom silicon that no software update will ever fix. The vulnerability affects:

  • iPhone XS through the entire iPhone 11 lineup
  • iPhone SE 2nd gen
  • Select iPads
  • Apple Watch Series 4/5
  • HomePod mini

The flaw lives in read-only memory — burned into silicon at manufacture, immutable forever after.

What “Unpatchable” Actually Means

This isn’t a bug Apple can quietly patch overnight — it’s a hardware-level flaw locked into the chip itself.

BootROM is the first code your phone runs at power-on, and Apple can’t rewrite it any more than you can un-bake a cake. The bug sits in a third-party Synopsys USB controller built into A12 and A13 chips. That controller accepts malformed packets smaller than the USB spec allows. Three undersized packets cause a memory pointer to walk backwards into territory it was never meant to touch, according to Paradigm Shift’s technical writeup. From there, an attacker can write data into sensitive memory regions during the boot process.

The irony stings. A11 devices like the iPhone X escape because Apple’s USB driver manually resets the pointer after each packet. A14 and later escape because Apple finally configured its memory protection unit — called DART — correctly at boot. A12 and A13 sit in the gap: a vulnerable middle generation caught between an old fix and a newer one. Apple essentially threaded a needle badly, and researchers just found the hole.

“Moving to a newer device is the only way to mitigate this vulnerability.”Privacy Guides

The Real-World Risk Isn’t Zero, But It’s Not a Fire Drill

Your passcode and encrypted data stay protected — but high-risk users should take this seriously.

If you’re a journalist, activist, or executive whose phone might end up in hostile hands at a border crossing, this matters. For everyone else: the exploit demands physical USB access during DFU mode, relies on specialized microcontrollers rather than a standard Mac or PC, and your passcode and Secure Enclave remain intact. The Secure Enclave is not directly compromised by usbliter8. Nobody is tracking users over Wi-Fi.

What usbliter8 actually achieves is breaking Apple’s secure boot chain, allowing unsigned software to load before iOS ever starts. It stamps “PWND” into the device’s USB serial number — a deliberate callback to checkm8, the 2019 exploit that did the same for A5–A11 devices and powered a generation of jailbreak tools. For the jailbreak community, this is like finding a lost vinyl pressing everyone assumed was destroyed.

Paradigm Shift coordinated disclosure with Apple Product Security before publishing. Practical steps:

  • Keep a strong passcode
  • Avoid plugging into unknown USB accessories during reboot
  • Don’t hand a booting device to strangers

If physical-access threats are real in your world, upgrading to A14 or later hardware is the only true fix. Apple can’t patch the chip that already shipped.