Paradigm Shift Discloses Unpatchable Apple Chip Flaw Enabling iPhone Jailbreak
The immutable Boot ROM flaw cannot be fixed via software updates, with the Barcelona-based firm advising hardware migration as the only mitigation strategy.

Paradigm Shift, a Barcelona-based offensive cybersecurity firm known for supplying hacking tools to government agencies, has disclosed a critical vulnerability in Apple’s A12 and A13 chips. Dubbed “usbliter8,” the flaw resides in the device’s immutable Boot ROM, the foundational code executed during startup, rendering it impossible to patch through standard software updates. The disclosure, which included a blog post and a proof of concept on Friday, details how the vulnerability allows hackers to jailbreak older iPhones by bypassing initial security checks.
The vulnerability specifically impacts iPhones released between 2018 and 2019, including the XS, XR, and iPhone 11 models. Exploitation of the flaw requires physical access to the target device, meaning an attacker must be able to connect a cable to the phone. While the Boot ROM serves as the first line of defence against intrusion, the immutable nature of the code means that once the usbliter8 exploit is leveraged, it can potentially facilitate further security breaches by chaining with other vulnerabilities.
Paradigm Shift advises that migrating to newer hardware is the only effective mitigation strategy for users of the affected devices. The firm noted that because the vulnerabilities reside in immutable code, no software patch can rectify the issue. This stance underscores the permanent nature of hardware-level flaws, which remain a persistent challenge for mobile security despite Apple’s historically robust defence mechanisms.
The disclosure carries significant implications for the broader security research community and law enforcement. Companies such as Cellebrite and Magnet Forensics, which sell systems to authorities for hacking seized iPhones, likely already possess techniques similar to usbliter8. However, the public release of the exploit details may enable other researchers or government contractors to develop more effective hacks, provided they can identify additional vulnerabilities to combine with this one.
Public iPhone jailbreaks have become increasingly rare over the last decade, as researchers often withhold findings to prevent Apple from patching flaws and hindering their own work. Jailbreaking is frequently a preliminary step for identifying deeper system vulnerabilities. Paradigm Shift did not respond to questions regarding the usbliter8 vulnerability, leaving uncertainty as to whether this disclosure will trigger a resurgence in public jailbreak tools or remain a niche concern for advanced threat actors.

