{"rewrite":{"id":"r_e402e3e0ce031ca04e3fe64a","clusterId":"c_bd3821ed82d4ed112ef156a0","slug":"unpatchable-usbliter8-vulnerability-found-on-apple-a12-and-a13-chips","model":"deepseek-v4-flash","headline":"Unpatchable Usbliter8 Vulnerability Found on Apple A12 and A13 Chips","summary":"European cybersecurity research organization Paradigm Shift has disclosed an unpatchable vulnerability called usbliter8 that affects Apple devices with A12, A13, S4, and S5 chips. The exploit allows arbitrary code execution via USB when a device is in DFU mode, giving an attacker with physical access control over the boot process. The Secure Enclave is not compromised, but the attack surface for compromising it may broaden.","whyItMatters":"The usbliter8 vulnerability is unpatchable because it exploits a hardware bug in the USB controller and specific firmware configuration flaws, meaning affected devices cannot be fixed through software updates.","webCardHtml":"\u003cp\u003eParadigm Shift, an independent European cybersecurity research organization, disclosed an unpatchable vulnerability called usbliter8 that affects Apple devices with A12, A13, S4, and S5 chips. The exploit sends specially crafted data via USB while the device is in DFU mode, confusing the USB controller and writing data to incorrect memory locations. An attacker with physical access can then control the boot process, execute custom code before iOS loads, bypass signature checks, and boot modified system software.\u003c/p\u003e\u003cp\u003eDevices affected include the iPhone XS series, iPhone 11 series, iPhone XR, iPhone SE (2nd generation), multiple iPad models, Apple Watch Series 4 and 5, Apple Watch SE (1st generation), Apple TV 4K, Apple Studio Display, and HomePod mini. The Secure Enclave is not compromised, so passcodes and encrypted user data remain safe. Paradigm Shift coordinated the announcement with Apple\u0026#39;s security team and released a proof-of-concept project on GitHub.\u003c/p\u003e","blueskyPost":"Usbliter8 exploits the DFU mode handshake, not the Secure Enclave. But physical access plus boot-level code execution is the kind of foothold that makes the Enclave less isolated than Apple designed.","twitterPost":"Usbliter8 gives boot-level code execution via USB on A12/A13 devices. The Secure Enclave is safe; the attack surface to reach it is not.","threadsPost":"Usbliter8 is unpatchable because it lives in the SecureROM, not the OS. The Secure Enclave itself is not compromised, but the vulnerability widens the corridor an attacker can walk to reach it. Physical access is required, but for a targeted device that is not a high bar.","newsletterBlurb":"Paradigm Shift disclosed usbliter8, an unpatchable vulnerability affecting Apple devices with A12 and A13 chips. The exploit requires physical access via USB in DFU mode and allows control of the boot process. The Secure Enclave is not compromised. Devices include iPhone XS, iPhone 11 series, iPads, Apple Watches, and more.","attributionJson":"[{\"source\":\"GIGAZINE\",\"url\":\"https://gigazine.net/news/20260619-unpatchable-exploit-targets-apple-a12-a13/\",\"title\":\"Unpatchable Vulnerability 'usbliter8' Found on Apple Devices with A12 and A13 Chips\"}]","lintFlagsJson":null,"lintHits":0,"costUsd":0,"inputTokens":4310,"outputTokens":687,"status":"published","repairAttempts":0,"nextRepairAt":null,"factsAttemptedAt":1781839528,"createdAt":"2026-06-19T03:16:27.000Z","publishedAt":"2026-06-19T03:18:15.000Z","updatedAt":"2026-06-19T03:18:15.000Z"},"cluster":{"id":"c_bd3821ed82d4ed112ef156a0","canonicalTitle":"A12およびA13チップ搭載のAppleデバイスでパッチ不可能な脆弱性「usbliter8」が見つかる","representativeArticleId":"a_1fe5aaf9663004edbfc56a8d","sourceCount":1,"writtenSourceCount":1,"writeAttempts":0,"isSolo":true,"entitiesJson":"{\"anime_titles\":[],\"manga_titles\":[],\"work_titles\":[],\"studios\":[],\"people\":[],\"type\":\"news\",\"domain\":\"other\",\"is_roundup\":false}","contentType":"news","status":"published","firstSeenAt":"2026-06-19T02:36:00.000Z","lastSeenAt":"2026-06-19T02:36:00.000Z","updatedAt":"2026-06-19T03:18:16.000Z"},"attribution":[{"source":"GIGAZINE","url":"https://gigazine.net/news/20260619-unpatchable-exploit-targets-apple-a12-a13/","title":"A12およびA13チップ搭載のAppleデバイスでパッチ不可能な脆弱性「usbliter8」が見つかる"}],"entities":{"anime_titles":[],"manga_titles":[],"work_titles":[],"studios":[],"people":[],"type":"news","domain":"other","is_roundup":false},"keyFacts":["The usbliter8 vulnerability is unpatchable because it exploits a hardware bug in the USB controller and specific firmware configuration flaws on Apple A12, A13, S4, and S5 chips.","The Secure Enclave is not compromised by usbliter8, so passcodes and encrypted user data remain safe.","Paradigm Shift coordinated the vulnerability disclosure with Apple's security team and released a proof-of-concept project on GitHub."]}
