
Security research team Paradigm Shift recently revealed a BootROM vulnerability called “usbliter8” that affects Apple’s A12, A13, and S4 and S5 chips. In addition to affecting the iPhone XS to iPhone 11 series, it also affects some iPad, Apple Watch, Apple TV, HomePod mini and other devices.
BootROM is the first code to be executed when a device boots up, and is written directly into the chip hardware. Therefore, once a vulnerability is discovered, it cannot be patched through iOS updates or firmware upgrades, and the affected device will be at risk of vulnerabilities throughout its life. The last well-known BootROM vulnerability was “checkm8” disclosed in 2019.
Simply put, the usbliter8 vulnerability exploits a hardware flaw in the USB controller built into Apple chips. Researchers found that as long as a data packet of a specific format is transmitted through USB during the device startup process, there is a chance that the controller will write data to a memory area that should not be accessed, thereby obtaining higher permissions.
A12, A13 chip vulnerability
Affected iPhone models
● iPhone XS
● iPhone XS Max
● iPhone XR
● iPhone 11
● iPhone 11 Pro
● iPhone 11 Pro Max
● iPhone SE (2nd generation)
Affected iPad models
● iPad Air (3rd generation)
● iPad mini (5th generation)
● iPad (8th generation)
● iPad (9th generation)
Other affected devices
● Apple TV 4K (2nd generation)
● Studio Display
S4, S5 chip vulnerability
Affected Apple Watch models
● Apple Watch Series 4
● Apple Watch Series 5
● Apple Watch SE (1st generation)
Other affected devices
●HomePod mini
Researchers also pointed out that the A12X and A12Z chips may theoretically have the same vulnerability, but it has not yet been implemented. If confirmed in the future, it means that the 2018 and 2020 iPad Pro models may also be affected.
Although this vulnerability cannot be patched through software updates, ordinary users do not need to worry too much. Because the attacker must obtain physical access to the device, operate it through USB and put the device into DFU mode, it cannot simply be remotely invaded through the network. At the same time, the vulnerability itself will not directly crack the device password or obtain encrypted user information, so the actual risk is relatively limited. If you are particularly concerned about the related security risks, it is recommended to upgrade to a device using a newer chip.
“You May Also Want to See”
iPhone Air 2 fights against the odds! Apple is rumored to have strengthened two major shortcomings and may be cut off if it does not sell well.
No need to draw, no need to grab. Now use the APP to watch the news and you are guaranteed to win every day. Click me to download the APP. Click me to see the event details.