Unpatchable BootROM Vulnerability Affects Apple A12 & A13 Devices

unrecognizable hacker with smartphone typing on laptop at desk

Security researchers have disclosed a significant vulnerability affecting Apple devices powered by the A12 and A13 chipsets. Dubbed ‘usbliter8,’ this exploit targets SecureROM, the foundational code that executes when an iPhone or iPad starts up. The immutable nature of BootROM means that traditional software updates cannot address this issue, presenting a long-term security challenge for potentially millions of devices.

The vulnerability stems from a combination of factors: a hardware bug within the Synopsys DesignWare USB2 (DWC2) controller and a configuration flaw in the device firmware. Researchers have found that the exploit is triggered through Device Firmware Update (DFU) mode, allowing attackers to bypass standard security measures. The attack specifically targets how the DWC2 controller handles consecutive USB Setup packets, opening a pathway for malicious code execution.

The implications of this vulnerability are substantial. Attackers can potentially gain control over affected devices, install persistent malware that survives restarts, and even manipulate device identifiers. Security researchers demonstrated how the exploit could be used to inject a string – ‘PWND’ – into the USB serial number, effectively branding compromised devices.

While Apple has not yet released an official statement regarding this vulnerability, cybersecurity experts emphasize the seriousness of its unpatchable nature. The fact that it resides within SecureROM makes it impervious to standard software updates and requires a fundamental hardware or firmware redesign – an unlikely scenario for older device models. The exploit leverages both a hardware bug in the USB controller and a specific configuration flaw present in the device firmware, making mitigation complex.

Defensive measures are currently limited. Users should exercise caution when connecting their devices to unfamiliar USB ports or computers, especially if they suspect potential compromise. While patching via software is not possible, ongoing monitoring for suspicious activity and maintaining a strong awareness of security best practices can help mitigate the risk. The vulnerability was publicly disclosed recently, highlighting the immediate need for users to be aware of this issue.

Sources: