Unpatchable Apple chip flaw could open the door to iPhone jailbreaks

A newly disclosed flaw in Apple chips could help researchers and hacking-tool makers build iPhone jailbreaks for older devices — but only if they can chain it with other bugs.
Boot ROM flaw affects older iPhones
On Friday, Paradigm Shift, an offensive cybersecurity company based in Barcelona, published details of a vulnerability it calls “usbliter8,” along with a proof of concept showing how it can be exploited with physical access to a phone. The issue affects Apple chips A12 and A13, which power older iPhones including the XS, XR and up through the iPhone 11.
The bug sits in the iPhone’s Boot ROM, the first code to run when a device powers on and the foundation of its security checks. Because Boot ROM code is burned into the chip, it cannot be updated, which makes the flaw unpatchable. Paradigm Shift said users on affected hardware should see migration to newer devices as the most effective mitigation.
Why the disclosure matters
The release does not mean older iPhones are suddenly easy to break into. The exploit requires physical access, and attackers would still need additional vulnerabilities to create a working jailbreak or broader compromise. But the publication gives security researchers — including those working for governments or contractors — a new starting point for developing iOS exploits.
That makes the disclosure especially relevant to the market for spyware and law-enforcement hacking tools. Companies that sell systems for accessing seized phones often rely on chains of vulnerabilities, and an exploitable Boot ROM flaw can be a valuable first step.
The finding also underscores a familiar reality in mobile security: Apple has made the iPhone extremely difficult to hack, but not invulnerable. Sophisticated attackers continue to look for weak points in the earliest layers of the device’s startup process, where a single flaw can unlock deeper access if paired with the right follow-on bug.
For now, the impact is limited to older hardware and to attackers with the ability to get hands-on with a target device. But for researchers chasing an iPhone jailbreak, usbliter8 could become an important piece of the puzzle.
Sources: