Unpatchable Hardware Vulnerability Leaves Owners of Older iPhone XS, iPhone XR and iPhone 11 Models at Risk

Researchers say the vulnerability has been disclosed to Apple before publication, and the proof-of-concept code is publicly available.

Advertisement
Written by Shaurya Tomer, Edited by David Delima | Updated: 19 June 2026 17:21 IST
Highlights
  • Researchers say the exploit affects Apple's A12 and A13 chipsets
  • Software updates cannot fix this specific flaw
  • Upgrading to newer devices is recommended

Apple's 10th and 11th generation iPhones are said to be affected

Security researchers have published the proof-of-concept exploit, dubbed "usbliter8", which targets a vulnerability in Apple's BootROM component of iPhone, the unalterable code that runs before iOS starts loading. Since BootROM is permanently etched into a chip during the manufacturing process, researchers claimed that vulnerabilities discovered at this level cannot be fixed through software updates. The newly disclosed exploit is said to affect devices ranging from the iPhone XS lineup to the iPhone 11 series, along with several iPad models powered by the A12 and A13 SoCs.

Usbliter8 Exploit Works on Apple's A12 and A13 Chips 

According to a report published by European cybersecurity research firm Paradigm Shift, the usbliter8 exploit targets a flaw in the USB controller integrated into Apple's A12 and A13 chips. The vulnerability is claimed to be significant since it exists at the BootROM level, the earliest stage of the device's boot process.

Advertisement

During an iPhone's startup, the USB controller usually stores incoming data in memory buffers. Researchers said they discovered a way to manipulate how the controller manages those buffers by injecting a specially crafted sequence of unusually small USB packets during startup. This causes memory corruption at a very low level of the system.

While the internal memory pointer inside the USB controller is only intended to move forward, they were able to move it backwards as well, which allowed data to be written to the protected regions of the memory. The process of gaining control of the processor is claimed to be relatively straightforward, especially on A12-powered devices, once the vulnerability is triggered.

Advertisement

On the other hand, A13-powered models were reportedly more complex due to Apple's introduction of Pointer Authentication Codes (PAC). It is, notably, a hardware security feature that is designed to detect unauthorised memory modifications. Thus, on such devices, bypassing PAC required a multi-stage exploitation process, and code could be executed.

Once successful, however, the exploit is claimed to be capable of lowering certain security restrictions and booting unsigned software that would normally fail Apple's verification checks.

Advertisement

The exploit is said to be a hardware-level flaw, originating from the USB controller hardware itself rather than being a software flaw. Researchers hence claim that such BootROM flaws cannot be patched through iOS updates, and shifting to newer hardware is the most effective solution for users with affected devices.

Researchers said they reported the vulnerability to Apple before publication and coordinated disclosure with the company. The proof-of-concept code has now been released publicly. However, it's worth noting that it requires physical access to the device to exploit, does not affect Secure Enclave, and it is not a complete jailbreak at present.

Advertisement

Apple Devices Affected By the Hardware Flaw

The exploit affects devices based on Apple's A12 and A13 chipsets, as well as certain Apple Watch models using related silicon. The affected models include the following devices:

  • iPhone XS
  • iPhone XS Max
  • iPhone XR
  • iPhone 11
  • iPhone 11 Pro
  • iPhone 11 Pro Max

Additionally, several iPad models powered by the A12-series processors are also said to be vulnerable, including those based on A12, A12X, A12Z, and A13 platforms. However, the cybersecurity firm's proof-of-concept only focuses on A12 and A13-powered devices. The company also confirmed support for Apple's S4 and S5 chips used in older Apple Watch models.

What's interesting is that the A11 chip inside the iPhone X is not affected. This is due to the Cupertino-based tech giant's implementation of an additional USB pointer reset mechanism in its BootROM. Further, newer Apple devices powered by the A14 and later processors also remain protected against the exploit, since correct memory-protection mechanisms were said to have been enabled by Apple at the BootROM level.

 
REVIEW
  • Design
  • Display
  • Software
  • Performance
  • Battery Life
  • Camera
  • Value for Money
  • Good
  • Best-in-class performance
  • Excellent cameras
  • Superb display
  • Dual SIM support is finally an option
  • Regular, timely software updates
  • Bad
  • Expensive
  • Dual SIM support is limited
  • First-party apps not great in India
  • Fast charger not bundled
 
KEY SPECS
Display 5.80-inch
Processor Apple A12 Bionic
Front Camera 7-megapixel
Rear Camera 12-megapixel + 12-megapixel
Storage 64GB
OS iOS 12
Resolution 1125x2436 pixels
NEWS
VARIANTS
REVIEW
  • Design
  • Display
  • Software
  • Performance
  • Battery Life
  • Camera
  • Value for Money
  • Good
  • Best-in-class performance
  • Excellent cameras
  • Superb display
  • Dual SIM is finally an option
  • Great battery life
  • Regular, timely software updates
  • Bad
  • Expensive
  • Some might find it bulky
  • Dual SIM support is limited
  • First-party apps not great in India
  • Fast charger not bundled
 
KEY SPECS
Display 6.50-inch
Processor Apple A12 Bionic
Front Camera 7-megapixel
Rear Camera 12-megapixel + 12-megapixel
Storage 64GB
OS iOS 12
Resolution 1242x2688 pixels
NEWS
VARIANTS
REVIEW
  • Design
  • Display
  • Software
  • Performance
  • Battery Life
  • Camera
  • Value for Money
  • Good
  • Best-in-class performance
  • Excellent cameras
  • Dual SIM is finally an option
  • Great battery life
  • Regular, timely software updates
  • Bad
  • Low-resolution display
  • Dual SIM support is limited
  • First-party apps not great in India
  • Fast charger not bundled
 
KEY SPECS
Display 6.10-inch
Processor Apple A12 Bionic
Front Camera 7-megapixel
Rear Camera 12-megapixel
RAM 3GB
Storage 64GB
Battery Capacity 2942mAh
OS iOS 12
Resolution 828x1792 pixels
NEWS
VARIANTS
REVIEW
  • Design
  • Display
  • Software
  • Performance
  • Battery Life
  • Camera
  • Value for Money
  • Good
  • Best-in-class performance
  • Excellent battery life
  • Great cameras
  • Night Mode is a welcome addition
  • iOS offers regular, timely updates
  • Bad
  • Low-resolution display
  • Slow bundled charger
  • No PiP or other software features that utilise the big screen
 
KEY SPECS
Display 6.10-inch
Processor Apple A13 Bionic
Front Camera 12-megapixel
Rear Camera 12-megapixel + 12-megapixel
RAM 4GB
Storage 64GB
Battery Capacity 3110mAh
OS iOS 13
Resolution 828x1792 pixels
NEWS
VARIANTS
REVIEW
  • Design
  • Display
  • Software
  • Performance
  • Battery Life
  • Camera
  • Value for Money
  • Good
  • Best-in-class performance
  • Insanely good battery life
  • Great cameras
  • Night Mode is a welcome addition
  • iOS offers regular, timely updates
  • Bad
  • Expensive
  • 64GB isn’t enough storage for a Pro device
  • No PiP or other features that utilise the big screen
 
KEY SPECS
Display 6.50-inch
Processor Apple A13 Bionic
Front Camera 12-megapixel
Rear Camera 12-megapixel + 12-megapixel + 12-megapixel
RAM 4GB
Storage 64GB
Battery Capacity 3969mAh
OS iOS 13
Resolution 1242x2688 pixels
NEWS
VARIANTS

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Redmi Turbo 5 With 7,540mAh Battery Goes on Sale in India: Price, Offers
  2. GTA 6 Website Shows New Look at Vice City, Removes Release Date Mention
  3. Haier Launches HQLED P7 Pro Series With Google TV, Dolby Atmos
  4. New OTT Releases of the Week: Drishyam 3, Thukra ke Mera Pyar S2, and More
  5. Athiradi Now Available for Streaming on OTT: Where to Watch the Malayalam Action Comedy
  6. Samsung Galaxy M47 5G India Launch Teased, Will Go on Sale via Amazon
  1. Reliance's Jio Platforms Files for Record $4 Billion IPO
  2. Nothing Teases Launch of Mysterious New “b” Product Series in India
  3. WhatsApp Begins Testing Online Indicator, New Feature to Manage Chat Backups on Android
  4. Rockstar Games Shares New Look at Vice City on GTA 6 Website, Removes Release Date Mentions
  5. UAE Reportedly Cracks Down on Social Media Use for Children Under 15, Mandates Age Verification
  6. Malta Seeks to Bring DAOs Under New DeFi Rules Aligned With MiCA
  7. Unpatchable Hardware Vulnerability Leaves Owners of Older iPhone XS, iPhone XR and iPhone 11 Models at Risk
  8. Haier HQLED P7 Pro Series Smart TVs Launched in India With Dolby Atmos, 50W Speakers
  9. Instagram Rolls Out Support for Multiple Captions on Carousel Posts
  10. Redmi Turbo 5 With 50-Megapixel Rear Camera, Dimensity 8500 Ultra Chip Goes on Sale in India: Price, Offers
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.