Apple Devices With A12 and A13 Chips Exposed to Unpatchable Security Flaw
Apple Devices With A12 and A13 Chips Exposed : Apple users with older iPhones, iPads, Apple Watches, and related devices are facing a new security concern after researchers revealed a hardware-level exploit affecting A12 and A13 chips. The flaw is important because it sits deep inside the device startup process, before iOS or iPadOS even begins to load. Unlike normal software bugs, this one cannot be fully removed with a system update. That does not mean every affected device is in immediate danger, but it does make the issue serious for people who rely on older Apple hardware in sensitive environments.
Roku Increases Streaming Hardware Prices Again With New Lineup Changes Affecting Millions of UsersA12 and A13 Chips Security Flaw
The A12 and A13 chips security flaw has been disclosed by security research firm Paradigm Shift under the name “usbliter8.” The exploit targets Apple’s SecureROM, also known as BootROM, which is the first code that runs when a device powers on. Since this code is burned into the chip during manufacturing, Apple cannot simply replace it through an iOS update. Devices using these chips may therefore remain exposed for the rest of their usable life.
How usbliter8 Works
The exploit depends on a vulnerability in the USB boot process. More particular, it exploits the way the device handles USB data while it is in DFU mode, the low-level recovery mode needed to restore firmware. Researchers observed that carefully constructed USB packets can cause memory to be written to areas it shouldn’t reach.
This happens before Apple’s normal boot protections are fully active. Once the exploit succeeds, it can allow code execution inside SecureROM. That is a powerful position because SecureROM helps enforce Apple’s chain of trust, which checks that each stage of the startup process is valid before passing control to the next one.
The vulnerability is linked to a hardware bug in the USB controller, combined with how affected Apple devices configure memory protections during early boot. According to the researchers, A14 and newer chips appear to handle this protection correctly, making the exploit path ineffective on newer devices.
Affected Devices
The public proof of concept supports devices using Apple’s A12, A13, S4, and S5 chips. This includes several popular products that are still in use today.
Affected models include the iPhone XR, iPhone XS, iPhone XS Max, iPhone 11, iPhone 11 Pro, iPhone 11 Pro Max, and the second-generation iPhone SE. Some iPads are also affected, including the iPad Air 3, iPad mini 5, iPad 8, and iPad 9. Apple Watch Series 4, Apple Watch Series 5, and the first-generation Apple Watch SE are also in the affected range.
Other products using related chips, such as the HomePod mini, Studio Display, and second-generation Apple TV 4K, may also be relevant depending on the hardware and exploit support. Researchers have also said that A12X and A12Z support may be technically possible, though it is not currently implemented in the public release.
Why the Exploit Matters
The biggest problem isn’t that a hacker can attack these devices remotely over the internet. The exploit requires physical access, USB connectivity, and DFU mode. That makes mass attacks unlikely for ordinary users.
Still, the flaw matters because it affects a part of the device that cannot be patched. A normal iOS security update can fix bugs in apps, system services, or kernel components. SecureROM is different. It is built into the silicon, so the vulnerability remains even after updates, restores, or firmware changes.
The exploit does not directly break Apple’s Secure Enclave, which protects sensitive data such as passcode-related secrets. However, gaining control so early in the boot process may give advanced attackers more room to test other attacks against the platform.
A New Chapter After checkm8
Security experts are comparing usbliter8 to checkm8, the well-known BootROM exploit released in 2019. Checkm8 affected older Apple devices using A5 through A11 chips and became important because it could not be patched through software.
Usbliter8 extends that history to newer hardware generations. A12 and A13 devices were considered much harder targets because Apple had added stronger protections. The fact that researchers achieved working exploitation on these chips shows that even modern secure boot systems can be weakened by subtle hardware behavior.
How to be safe
The danger is still low for most people. An attacker would have to have physical access to the device and attach it over USB in DFU mode. The SecureROM problem can’t be fixed with a software update, but it’s still crucial to keep your device updated. Software updates guard against many other risks.
Users must not leave vulnerable gadgets unattended in dangerous circumstances. They should also not connect gadgets to untrusted PCs, unknown USB accessories or repair tools. But a strong passcode is still crucial as it adds safety if a device is lost or stolen.
Business people, journalists and government workers, who are in high-risk groups, should take this issue more seriously. If you have an A12 or A13 device that handles sensitive data, you may need to replace it with a newer model. If so, upgrading to hardware with an A14 chip or later is the most effective long-term mitigation.
Usbliter8 is not a reason for panic, but it is a reminder that hardware security flaws can outlive software support. Once a vulnerability is built into silicon, the safest fix is often moving to newer hardware.



