Apple A12/A13 SecureROM USB DMA underflow with public usbliter8 exploit security flaw
Vulnerability
Summary
Hide ▲
Show ▼
A public usbliter8 exploit now reaches arbitrary code execution in Apple's SecureROM, exposing an unpatchable USB DMA underflow flaw across A12, A13, S4, and S5 hardware. The attack needs physical possession, DFU mode, and a RP2350-based microcontroller board, but it completes in under two seconds before the signed boot chain loads. Because the vulnerable code is burned into silicon, no software update can remove the flaw. The result is a durable device-custody risk for environments that must protect high-value Apple hardware from direct access.
Related Happenings
AirDrop and Quick Share nearby crash and session-bypass flaws security flaw
Vulnerability
H score1
First: 30.06.2026 12:27
Last: 30.06.2026 12:27
Sources 1
About this happening:
Nearby attackers can crash AirDrop and bypass Quick Share session checks, exposing Apple, Samsung, and Google Windows file-sharing stacks to local disruption a...
AirDrop and Quick Share nearby crash and session-bypass flaws security flaw
VulnerabilityAbout this happening: Nearby attackers can crash AirDrop and bypass Quick Share session checks, exposing Apple, Samsung, and Google Windows file-sharing stacks to local disruption a...
Apple A12/S4/S5/A13 BootROM usbliter8 authentication bypass flaw
Vulnerability
H score27
First: 22.06.2026 17:00
Last: 22.06.2026 17:00
Sources 1
About this happening:
Researchers disclosed usbliter8, an unpatchable BootROM flaw affecting Apple A12, S4/S5, and A13 SoCs, creating boot-chain compromise risk for devices with physical...
Apple A12/S4/S5/A13 BootROM usbliter8 authentication bypass flaw
VulnerabilityAbout this happening: Researchers disclosed usbliter8, an unpatchable BootROM flaw affecting Apple A12, S4/S5, and A13 SoCs, creating boot-chain compromise risk for devices with physical...
Beats Studio Buds Bluetooth BR/EDR missing-authentication security flaw (multiple vulnerabilities)
Vulnerability
H score24
First: 18.06.2026 15:23
Last: 18.06.2026 15:23
Sources 1
About this happening:
Beats Studio Buds are affected by CVE-2025-20701, a missing-authentication flaw in Airoha system-on-a-chip (SoCs) and the Bluetooth BR/EDR radio that can let a...
Beats Studio Buds Bluetooth BR/EDR missing-authentication security flaw (multiple vulnerabilities)
VulnerabilityAbout this happening: Beats Studio Buds are affected by CVE-2025-20701, a missing-authentication flaw in Airoha system-on-a-chip (SoCs) and the Bluetooth BR/EDR radio that can let a...
Android Framework code execution and privilege escalation flaw (CVE-2025-48595)
Vulnerability
H score40
First: 02.06.2026 14:10
Last: 02.06.2026 14:10
Sources 1
About this happening:
Google's June 2026 Android security patches now cover CVE-2025-48595, an actively exploited Android Framework flaw that can lead to code execution and privilege...
Android Framework code execution and privilege escalation flaw (CVE-2025-48595)
VulnerabilityAbout this happening: Google's June 2026 Android security patches now cover CVE-2025-48595, an actively exploited Android Framework flaw that can lead to code execution and privilege...
Coruna iOS exploit analysis ties updated Triangulation kernel exploit lineage
Technical Analysis
H score33
First: 26.03.2026 15:10
Last: 26.03.2026 15:10
Sources 1
About this happening:
Coruna has been linked to an updated exploit lineage from Operation Triangulation, showing that a long-running iPhone attack framework continues to evolve and can stil...
Coruna iOS exploit analysis ties updated Triangulation kernel exploit lineage
Technical AnalysisAbout this happening: Coruna has been linked to an updated exploit lineage from Operation Triangulation, showing that a long-running iPhone attack framework continues to evolve and can stil...
Timeline
-
19.06.2026 21:37 1 articles · 26d ago
Paradigm Shift releases usbliter8 for Apple A12 and A13 SecureROM
Initial DisclosureParadigm Shift publicly released usbliter8, a working exploit that achieves arbitrary code execution inside Apple's SecureROM on A12 and A13 chips after physical possession of the device in DFU mode with a dedicated RP2350-based microcontroller board.
Show sources
- Unpatchable 'usbliter8' Exploit Breaks Apple A12 and A13 SecureROM Boot Chain — thehackernews.com — 19.06.2026 21:37
-
19.06.2026 21:37 2 articles · 26d ago
USB DWC2 DMA underflow exposes Apple SecureROM on affected chips
Technical Analysis UpdateSecurity researchers describe a hardware flaw in the Synopsys DWC2 USB controller that, when Apple's SecureROM configures the USB DART in bypass mode, can step the DMA write pointer backward through memory and overwrite arbitrary SRAM on affected A12 and A13 devices; as of June 19, 2026, no CVE, CVSS score, Apple security advisory, or CISA alert had been issued and no in-the-wild exploitation had been publicly reported.
Show sources
- Unpatchable 'usbliter8' Exploit Breaks Apple A12 and A13 SecureROM Boot Chain — thehackernews.com — 19.06.2026 21:37
- Unpatchable 'usbliter8' Exploit Breaks Apple A12 and A13 SecureROM Boot Chain — thehackernews.com — 19.06.2026 21:37