
Vulnerability Research
USBLITER8: Apple SecureROM BootROM Exploit Analysis
On 18 June 2026, the security research firm Paradigm Shift published "usbliter8", a new BootROM exploit targeting Apple's A12 and A13 SoCs along with the S4 and S5 chips used in Apple Watch. This report breaks down how the exploit works, why it cannot be patched, and what it means for device security.
How the exploit works
The exploit chains two underlying weaknesses: a hardware bug in the Synopsys DWC2 USB controller, and the USB DART being configured in bypass mode. Combined, they let an attacker corrupt SRAM through crafted USB packets while the device is in DFU mode, and execute high-privilege code before iOS has even started.
Why it cannot be patched
Because the vulnerabilities live in immutable BootROM code, they cannot be fixed with a software update. Paradigm Shift disclosed the findings to Apple ahead of publication; according to the report, no CVE has been assigned yet and no practical attack has been reported in the wild.
Get the full report
Enter your details and we'll email you a secure download link.