Unpatchable usbliter8 Exploit Breaks Apple Boot Chain
Apple A12 and A13 chips carry a permanent SecureROM flaw. Attackers with physical access can now run unsigned code on those devices.
The usbliter8 exploit targets a DMA underflow in the Synopsys DWC2 USB controller. On A12 and A13 it reaches SRAM because the IOMMU runs in bypass mode during early boot. It achieves code execution inside SecureROM in under two seconds via DFU over USB.
Public PoC covers iPhone XS through 11, SE 2, certain iPads, Apple Watch Series 4 and 5, and HomePod mini. A11 is unaffected. A14 and newer hardware blocks the path.
Researchers published full write-up and working code the day after coordinated disclosure with Apple.
