Skip to main content
  1. Home
  2. Phones
  3. News

Your old iPhone may have a security flaw Apple can’t fix

Security researchers find a new BootROM exploit affecting iPhones with A12 and A13 chips

Add as a preferred source on Google
iPhone 11 Pro in hand
Apple iPhone 11 Pro Andy Boxall / Digital Trends

iPhones are widely seen as some of the most secure smartphones for everyday users. Still, Apple devices are not immune to serious security flaws, as recent threats like Coruna and DarkSword have shown. Now, security researchers at Paradigm Shift have detailed a different kind of exploit called usbliter8, which affects some older iPhones and targets a deep part of Apple’s startup process known as the BootROM.

The BootROM is the basic startup code that runs before iOS loads. It helps the iPhone begin the boot process and verify what should run next. Because it is built into the chip itself, it is much harder to fix than a normal iOS bug. Apple can usually patch software flaws through an update, but it cannot rewrite BootROM code on devices that have already shipped.

How does the exploit work?

According to the researchers, usbliter8 takes advantage of a weakness in the iPhone’s USB hardware and the way some older Apple chips handle USB data during startup. In simple terms, an attacker could send specially crafted USB data while the phone is starting up or in a restore mode. That can confuse the USB controller and cause data to be written to the wrong place in memory. From there, the exploit can interfere with the boot process and run unauthorized code before iOS has fully loaded.

That sounds serious, but there is an important limit. This is not a remote attack that can reach your iPhone through a website, text message, or app. It requires USB access, which means the iPhone would need to be connected to a computer or another USB device.

Which iPhones are affected?

The exploit affects Apple devices using A12 and A13 chips as well as Apple’s S4 and S5 smartwatch chips. For iPhone users, that includes the iPhone XR, iPhone XS, iPhone XS Max, iPhone 11, iPhone 11 Pro, iPhone 11 Pro Max, and the second-generation iPhone SE. For Apple Watch users, the affected models include the Apple Watch Series 4, Apple Watch Series 5, and the first-generation Apple Watch SE. Researchers do mention that the exploit is trickier to execute on devices with A13 chips.

Because this is a hardware-level issue, there is no normal software update that can completely remove the risk. A good rule is to avoid connecting older iPhones or Apple Watches to unknown computers, public USB ports, or untrusted accessories. If you own one of the affected models and security is a serious concern, moving to a newer device may offer the most peace of mind.

Sudhanshu Kumar Mangalam
I’ve got about 4 years of experience, mostly covering gaming, PC hardware, and smartphones. In my free time, I like…
Google Health adds a faster way to share your medical history with doctors
Version 5.05 introduces Smart Health Links, a way to share medical record summaries without filling out new intake forms.
Electronics, Mobile Phone, Phone

Google Health can now turn your stored medical records into a shareable link, letting you skip the tedious intake forms when you switch doctors or visit a specialist for the first time. The feature, called Smart Health Links, is rolling out with Google Health version 5.05 and is available in the US only for now.

How Smart Health Links work

Read more
Google Health just made Fitbit Air a better fit for Apple Health users
Google Health bridges Apple Health syncing, medical sharing, and fitness tracking fixes.
Body Part, Knee, Person

I've found it a little absurd that health apps from different companies and service providers refuse to communicate with each other, even when you're the one who owns the data. Google just took one small yet important step toward fixing it. 

Google Health version 5.05 started rolling out today. And compared to the last several releases, this one's fairly light, especially since it follows four crucial updates packed into June and July. 

Read more
Google can’t catch a break as the Pixel 11 Pro leaks once again
Electronics, Mobile Phone, Phone

Google's Made by Google 2026 event is just around the corner, but at this point, it feels like the company has very little left to surprise us with.

The latest leak brings what appear to be official marketing renders of the Pixel 11 Pro and Pixel 11 Pro XL, offering perhaps the clearest look yet at Google's upcoming flagship phones. Shared by well-known leaker Evan Blass, the images don't just show off the hardware — they also hint at camera upgrades, AI features, and the next-generation Tensor chip powering everything under the hood. While none of the images reveal anything dramatically unexpected, they do suggest Google is paying attention to one design complaint Pixel fans have had for years.

Read more