

Apple A12 and A13 Chips Exposed to New usbliter8 BootROM Vulnerability
Researchers from Paradigm Shift have revealed a new BootROM-level vulnerability called usbliter8, which directly affects Apple devices using the A12 and A13 chips.
Unlike ordinary software flaws, this vulnerability is rooted deep in the hardware. Because it exists at the BootROM level, it cannot be fully fixed through a normal operating system update.
That makes the issue more serious for affected devices, especially those still being used in personal, business, or organization-level environments.
A Hardware-Level Flaw That Software Updates Cannot Fully Fix
The source explains that usbliter8 is not a normal software bug.
Instead, it is a flaw connected to the hardware design from the manufacturing stage. This means Apple cannot simply release a software patch that completely removes the vulnerability from affected devices.
Devices using the A12 and A13 chips may continue carrying this weakness throughout their remaining lifespan.
For users, this does not mean the device will automatically be compromised. However, it does mean the protection limit is different compared to a software-only security issue.
How usbliter8 Works
The vulnerability works through the device’s USB controller.
According to the source, the attack involves sending small data packets in an unusual sequence. This can cause the system to misunderstand the data flow and allow writing into memory areas that should normally be inaccessible.
If someone knows how to use this method, they may be able to gain deep control over the device from the moment it begins booting.
That is why a BootROM flaw is serious. It affects the device at a very early and fundamental stage of operation.
A14 and Newer Chips Are Reportedly Safe
The article notes that newer Apple chips starting from A14 are safe from this specific issue.
This is because Apple added memory protection at the BootROM level in later chip designs. As a result, the vulnerability mainly affects devices built with the older A12 and A13 chips.
For users with newer Apple devices, this specific usbliter8 risk should not apply based on the source.
The Attack Requires Physical USB Access
The good news is that this is not described as a remote attack.
The source emphasizes that attackers need direct physical access to the device through the USB port. This means users are not expected to be attacked simply by browsing the web, receiving a message, or using the device normally online.
Because of this, the best practical protection is to avoid connecting devices to untrusted chargers, strange accessories, unknown USB ports, or suspicious public charging stations.
For regular users, physical security becomes the most important defense.
Jailbreak Potential and Security Concerns
For some advanced users, usbliter8 may be seen as a possible future tool for jailbreaking older Apple devices.
A BootROM-level vulnerability can open opportunities for deeper device modification, which may extend what older hardware can do beyond Apple’s normal restrictions.
However, from a security perspective, the issue is much more concerning. For companies and organizations handling sensitive information, the vulnerability could become a serious risk if attackers gain physical access to affected devices.
The source notes that enterprise IT teams may need to plan future hardware transitions to reduce exposure.
What Users Should Do
Users with A12 or A13-based devices should be more careful with physical connections.
Avoid public chargers that look suspicious, unknown USB accessories, and unfamiliar devices that request connection access. Keeping the system updated is still important, even if the BootROM issue itself cannot be fully removed by software.
Users should also choose trusted accessories and stay alert when connecting phones or tablets outside their own safe environment.
THIS IS our take
The usbliter8 vulnerability is a reminder that even highly secure devices can still face hardware-level limits. For most everyday users, the risk is reduced because the attack requires direct USB access. However, the fact that A12 and A13 devices cannot fully remove the flaw through software updates makes this a long-term concern. The safest approach is simple: keep devices updated, avoid suspicious USB connections, and treat public charging points with extra caution.
This Is Game SEA





