A company that sells spyware and hacking tools to government agencies has released details of a vulnerability in Apple chips that could help hackers unlock older iPhones.
This release opens the door for other researchers who specialize in finding iOS vulnerabilities, including governments and their contractors, to develop effective iPhone hacks if they can find additional vulnerabilities that chain with this one. This could help security researchers develop a so-called iPhone jailbreak, a technique that hacks into Apple's mobile operating system and removes all the restrictions the company imposes.
The release also serves as a reminder that while Apple has made the iPhone harder to hack, there are and always will be vulnerabilities that sophisticated hackers can exploit to break into them.
On Friday, Paradigm Shift, a Barcelona-based offensive cybersecurity company, published a blog post about the vulnerability, which it dubbed “usbliter8.” The company also published a proof of concept showing how to exploit this vulnerability, which requires physical access to a target phone.
This flaw and related exploit were released in 2018 and 2019 and affect iPhones with Apple chips A12 and A13, which are found in older iPhones up to the XS, XR, and iPhone 11.
The release of usbliter8 is important to the world of security research, spyware, and hacking tool makers, but it doesn't mean anyone can easily hack an old iPhone.
The bug discovered by Paradigm Shift affects the iPhone's boot ROM. Boot ROM is the first code that runs when your iPhone powers on, making it your first line of defense against hackers. To hack an iPhone by physically accessing it (by connecting a cable), a hacker must first exploit the boot ROM. Now, thanks to usbliter8, that's possible, potentially disabling and circumventing further security checks.
“Because these vulnerabilities exist in immutable code, affected users should be aware that migrating to new hardware remains the most effective mitigation,” Paradigm Shift wrote in a blog post.
In other words, the boot ROM is burned into the chip, so it cannot be modified and its defects cannot be patched.
Generally speaking, companies like Cellebrite and Magnet Forensics that sell systems for hacking iPhones seized by authorities need technology similar to usbliter8 to break into iPhones, and likely already have it at their disposal. However, hackers must incorporate other techniques to access user data stored on the phone.
Publicly jailbreaking iPhones was relatively common in the past, but has become rare over the past decade. Jailbreaking your iPhone is often the first step in investigating other vulnerabilities on your system. Researchers intent on discovering valuable flaws in the iPhone and ways to exploit them have little incentive to release that information publicly. That's because Apple will fix the flaws and hinder researchers.
Paradigm Shift did not answer a series of questions regarding usbliter8.
If you buy through links in our articles, we may earn a small commission. This does not affect editorial independence.

