Unpatchable Apple Chip Flaw Hits Older iPhones and Watches

Researchers disclosed an unpatchable SecureROM flaw called usbliter8 that affects A12/A13 and S4/S5 Apple chips, impacting older iPhones, iPads, and some Apple Watches. The Secure Enclave stays intact, but hardware upgrades may be required.

Unpatchable Apple Chip Flaw Hits Older iPhones and Watches
Reading time: 3 Minutes
Follow on Google

Picture this: you hand an aging iPhone to a technician and, with a few clever moves and the right gear, someone can slip past the phone's unchangeable boot code. It sounds like a plot point from a hacker thriller, but researchers have revealed a real hardware-level weakness that plays out much the same way.

Inside the flaw and which gadgets are exposed

Security firm Paradigm Shift published a technical write-up and a working proof-of-concept for an exploit they call usbliter8. The target is SecureROM — the immutable boot code etched into the silicone — on devices using Apple A12, A13 and the S4, S5 system-on-chips. Because SecureROM is baked into silicon during manufacture, the vulnerability cannot be patched with a software update.

That means several still-popular devices are affected. The list includes:

  • iPhone XR, XS, XS Max
  • iPhone 11, 11 Pro, 11 Pro Max
  • iPhone SE (2nd generation)
  • iPad Air (3rd generation), iPad mini (5th generation), iPad (8th and 9th generation)
  • Apple Watch Series 4, Series 5, and the first Watch SE
  • Also a few other devices such as the 2nd-generation Apple TV 4K and the Studio Display

There is a sliver of good news. The exploit does not touch the Secure Enclave, which handles passcodes and encryption keys, so your encrypted data and Face ID or Touch ID secrets remain protected. Also, older A11 chips (found in the iPhone 8 and iPhone X) are not affected, and A14 and newer processors appear safe from this particular method.

Is this cause for panic? Not for everyone. The attack requires technical skill and direct access to the device. It is not something a casual thief can likely execute in a moment. Yet for users who keep sensitive corporate data or handle classified information on the affected models, the implications are real and immediate.

Paradigm Shift coordinated disclosure with Apple before publishing. Apple cannot issue a traditional patch for code that lives in hardware. Their practical advice is straightforward: if device security is critical for you, consider moving to a newer phone or watch with unaffected silicon.

Expect two predictable reactions. Tech-conscious users will weigh the cost of replacing hardware against the low-but-present risk. And the jailbreaking community will see opportunity — this kind of hardware-level access can be attractive to people trying to bend devices beyond manufacturer limits. Apple, meanwhile, will focus on designing future chips to resist similar attacks.

What you can do right now is simple. Use a strong, unique passcode. Do not leave devices unattended or in the hands of strangers. For work phones, follow company security guidance and talk to your IT team about hardware replacement timelines.

This episode is a reminder that some vulnerabilities live beneath the operating system, down in the silicon itself. They are harder to fix, and often require hardware turnover instead of a quick download. If you own one of the affected devices and handle sensitive information, take it seriously. If you don’t, keep your passcode tight and carry on.

Chloe Nakamura

“I love exploring gadgets, apps, and trends that redefine how we connect, work, and play in a digital world.”

Leave a Comment

Comments (2)

Daniel

Wow that freaks me out. I still use an XR as a backup, might have to ditch it sooner than planned. Apple really has no fix for this?!

mechbyte

So a tech can bypass the boot code? sounds kinda wild. Is this only lab-grade or real world exploit? curious if phones get bricked during it...