Observed Signal · Jun 22, 2026 · Technical Release · Source: techcrunch · Impact: 2/5 · Sentiment: Neutral

Unpatchable Apple A12/A13 Boot ROM Flaw Enables Jailbreak

Executive Signal Summary

Paradigm Shift, an offensive cybersecurity company based in Barcelona that sells spyware and hacking tools to government agencies, published technical details and a proof-of-concept for a vulnerability it calls “usbliter8.” The flaw affects the Boot ROM on Apple A12 and A13 chips (used in iPhone XS, XR and iPhone 11), code burned into the chip that cannot be patched. Exploiting the bug requires physical access to the device (a cable connection) and could allow attackers or researchers to defeat boot-level security checks—potentially serving as a building block for iPhone jailbreaks when combined with other vulnerabilities. Paradigm Shift recommends migrating to newer hardware as the primary mitigation. The publication underscores that while modern iPhones are difficult to compromise, immutable low-level firmware bugs remain a persistent risk.

Polaris7 AgentPolaris7 Strategic Assessment
High Confidence

Public disclosure of an unpatchable Boot ROM vulnerability on Apple A12/A13 devices is significant for device security and could enable jailbreak development or forensic/hacking tool capabilities, but it affects older hardware and requires physical access, limiting immediate industry-wide impact.

SIGNAL RADAR

Track Apple Signals & Market Shifts in Real-Time

Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.

Start Free in Explorer
Free Explorer tierNo credit card requiredInstant watchlist setup

Key Takeaways & Evidence Grounding

  • Paradigm Shift published details and a proof-of-concept for a vulnerability named "usbliter8".
  • The flaw affects Apple-designed A12 and A13 chips (found in iPhone XS, XR and iPhone 11).
  • The bug resides in the iPhone Boot ROM, which is immutable and therefore cannot be patched via software updates.
  • Exploitation requires physical access to the target phone (ability to connect a cable).
  • Paradigm Shift is described as an offensive cybersecurity company based in Barcelona that sells spyware and hacking tools to government agencies.
Primary Source Grounding & Direct Attribution
Direct Origin Attribution
Primary Reporting: techcrunch•Published: Jun 22, 2026
Original Coverage Title: “A new unpatchable flaw in Apple chips opens the door to an iPhone jailbreak”

Related Market Signals & Shifts

Recent verified developments and strategic activity across this market segment.

SecurityJun 19, 2026

Unpatchable BootROM USB Flaw in A12/A13 Apple Chips

Security researchers at Paradigm Shift disclosed a BootROM vulnerability called “usbliter8” affecting Apple A12 and A13 family chips and Apple Watch S4/S5 processors. The flaw resides in the USB controller (Synopsys DWC2) inside the immutable BootROM, so Apple cannot patch it with a software update. Paradigm Shift published a proof-of-concept on GitHub that uses a modified Waveshare USB-A board (or compatible RP2350 boards) connected via cable; exploitation requires physical access to the device. The bug can let specially crafted USB packets corrupt the controller’s buffer and access protected memory, potentially enabling full device takeover. A12X/A12Z are suspected vulnerable but not confirmed; A11 is unaffected. Researchers expect a full jailbreak could follow, and recommend upgrading hardware as the primary mitigation.

Read assessment
SecurityMar 24, 2026

Darksword Exploit Kit Leaked, Puts Millions of iPhones at Risk

A modified version of the Darksword exploit kit has been published publicly on GitHub, lowering the technical barrier for large-scale attacks against iPhones and iPads. Security researchers uncovered a related hacking campaign in mid‑March 2026 that could target hundreds of millions of devices still running older iOS versions. The leaked package is composed of HTML and JavaScript files and includes code comments explaining exploit behavior and data exfiltration. Apple says devices running the latest updates (iOS 26.4/iPadOS 26) are protected and has issued emergency fixes for older models; users are advised to update or enable Lockdown Mode for extra protection.

Read assessment
PrivacySep 29, 2026

Apple fixes iOS 26 zero-click security flaws

Apple has patched two critical security vulnerabilities affecting iOS 26, iPadOS 26, and macOS 26. The first, CVE-2026-86950, is a graphics engine bug that may have been exploited in highly sophisticated attacks. The second, CVE-2026-86869, is a zero-click iMessage vulnerability that could bypass BlastDoor, discovered by Belgian firm ironPeak and Meta. Apple credited Meta's product security team and ironPeak's Niels Hofmans. Both vulnerabilities affect a large user base still on iOS 26, though iOS 27 devices are unaffected. Details remain limited, and it's unknown if the flaws were actively exploited.

Read assessment

Track Real-Time Market Signals & Shifts

Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.