Observed Signal · Jun 19, 2026 · Security Vulnerability Disclosure · Source: t3n · Impact: 4/5 · Sentiment: Negative

Unpatchable BootROM USB Flaw in A12/A13 Apple Chips

Executive Signal Summary

Security researchers at Paradigm Shift disclosed a BootROM vulnerability called “usbliter8” affecting Apple A12 and A13 family chips and Apple Watch S4/S5 processors. The flaw resides in the USB controller (Synopsys DWC2) inside the immutable BootROM, so Apple cannot patch it with a software update. Paradigm Shift published a proof-of-concept on GitHub that uses a modified Waveshare USB-A board (or compatible RP2350 boards) connected via cable; exploitation requires physical access to the device. The bug can let specially crafted USB packets corrupt the controller’s buffer and access protected memory, potentially enabling full device takeover. A12X/A12Z are suspected vulnerable but not confirmed; A11 is unaffected. Researchers expect a full jailbreak could follow, and recommend upgrading hardware as the primary mitigation.

Polaris7 AgentPolaris7 Strategic Assessment
High Confidence

An unpatchable, low-level BootROM vulnerability in widely deployed Apple chips (A12/A13) enables device takeover and has a public proof-of-concept; affects many consumer Apple devices and cannot be mitigated via software updates, making it a serious industry security event.

SIGNAL RADAR

Track Apple Signals & Market Shifts in Real-Time

Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.

Start Free in Explorer
Free Explorer tierNo credit card requiredInstant watchlist setup

Key Takeaways & Evidence Grounding

  • Paradigm Shift disclosed a BootROM vulnerability named “usbliter8” in Apple A12 and A13 chips.
  • The flaw is in the Synopsys DWC2 USB controller embedded in the BootROM and cannot be fixed by a software update.
  • Paradigm Shift published a proof-of-concept on GitHub using a modified Waveshare USB-A board (and compatible RP2350 boards); exploitation requires physical access and a Lightning cable.
  • Affected devices include phones, tablets, Apple Watch models (S4, S5, SE 1st gen) and Apple TV models using A12/A13; iPhone 11 series and iPhone SE (2nd gen) are among supported devices still receiving iOS 27 updates.
  • Researchers suspect A12X/A12Z may be vulnerable; the older A11 chip is not affected.

Ontology Mapping & Concepts

Primary Source Grounding & Direct Attribution
Direct Origin Attribution
Primary Reporting: t3n•Published: Jun 19, 2026
Original Coverage Title: “Nicht behebbar: Sicherheitsforscher entdecken gefährliche Lücke bei älteren iPhones”

Related Market Signals & Shifts

Recent verified developments and strategic activity across this market segment.

Security / Device VulnerabilityJun 22, 2026

Unpatchable Apple A12/A13 Boot ROM Flaw Enables Jailbreak

Paradigm Shift, an offensive cybersecurity company based in Barcelona that sells spyware and hacking tools to government agencies, published technical details and a proof-of-concept for a vulnerability it calls “usbliter8.” The flaw affects the Boot ROM on Apple A12 and A13 chips (used in iPhone XS, XR and iPhone 11), code burned into the chip that cannot be patched. Exploiting the bug requires physical access to the device (a cable connection) and could allow attackers or researchers to defeat boot-level security checks—potentially serving as a building block for iPhone jailbreaks when combined with other vulnerabilities. Paradigm Shift recommends migrating to newer hardware as the primary mitigation. The publication underscores that while modern iPhones are difficult to compromise, immutable low-level firmware bugs remain a persistent risk.

Read assessment
SecuritySep 15, 2026

Apple Patches 100+ Security Flaws in iOS 27 and macOS 27

Apple released iOS 27, iPadOS 27, macOS 27, watchOS 27, tvOS 27, and visionOS 27 on September 14, 2026, fixing over 100 security vulnerabilities in iOS 27 alone. Critical issues include a Bluetooth vulnerability allowing arbitrary code execution and app crashes, and a baseband modem flaw enabling remote denial-of-service attacks. Apple credits AI tools like Anthropic Claude and OpenAI Codex Security for assisting researchers in finding these bugs. Older OS versions (iOS 26.7, macOS 26.7, macOS 15.8) received partial fixes, but Intel Macs are excluded from macOS 27. Additionally, Safari 27 was released for older macOS versions to address WebKit vulnerabilities, and users are advised to upgrade for full protection.

Read assessment
PrivacySep 29, 2026

Apple fixes iOS 26 zero-click security flaws

Apple has patched two critical security vulnerabilities affecting iOS 26, iPadOS 26, and macOS 26. The first, CVE-2026-86950, is a graphics engine bug that may have been exploited in highly sophisticated attacks. The second, CVE-2026-86869, is a zero-click iMessage vulnerability that could bypass BlastDoor, discovered by Belgian firm ironPeak and Meta. Apple credited Meta's product security team and ironPeak's Niels Hofmans. Both vulnerabilities affect a large user base still on iOS 26, though iOS 27 devices are unaffected. Details remain limited, and it's unknown if the flaws were actively exploited.

Read assessment

Track Real-Time Market Signals & Shifts

Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.