Unpatchable 'usbliter8' Exploit Breaks Apple A12 and A13 SecureROM Boot Chain

18 hours ago by Kid to c/cybersecurity

Paradigm Shift’s usbliter8 exploit targets Apple A12 and A13 SecureROM via USB DFU mode, creating an unpatchable hardware risk.
hayvan 7 points 17 hours ago

so, custom ROM possible?

path: 0 24379695, hotness: undefined, score: 7, children: 2
towerful 9 points 17 hours ago

Yes, but will only boot with an RP2350 plugged in.
So, yes as long as the device doesn't reboot.
Which reminds me of early iPhone Jailbreaks

Post-exploitation, usbliter8 injects a custom USB request handler and stamps PWND:[usbliter8] into the device's USB serial string. From there, an attacker can temporarily demote the SoC's production mode or boot a raw, unsigned iBoot image with no signature checks, stepping outside Apple's chain of trust entirely.

path: 0 24379695 24379868, hotness: undefined, score: 9, children: 0
SayJess 0 points 17 hours ago

Highly unlikely

path: 0 24379695 24379720, hotness: undefined, score: 0, children: 0
cybersecurity
cybersecurity

@sh.itjust.works

login for more options
10144
5227
1224

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

  • Be respectful. Everyone should feel welcome here.
  • No bigotry - including racism, sexism, ableism, homophobia, transphobia, or xenophobia.
  • No Ads / Spamming.
  • No pornography.

Community Rules

  • Idk, keep it semi-professional?
  • Nothing illegal. We're all ethical here.
  • Rules will be added/redefined as necessary.

If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities !databreaches@lemmy.zip !netsec@lemmy.world !securitynews@infosec.pub !cybersecurity@infosec.pub !pulse_of_truth@infosec.pub

Notable mention to !cybersecuritymemes@lemmy.world

go to feed...