A group of security researchers from Paradigm Shift has discovered a vulnerability in older iPhone, iPad and Apple Watch models that can be used to jailbreak to the device. The ruling, named ‘usbliter8’it is not a software error that Apple can correct with an update, but rather a physical design flaw in certain chips. According to the study, devices that use the chips are affected A12 and A13as well as others with S4 and S5.
In the first group are the iPhone 11, iPhone 11 Pro, iPhone 11 Pro Max, iPhone SE second generation, iPhone XR, iPhone XS and iPhone XS Maxaccording to AppleInsider. Also the eighth and ninth generation iPad, third generation iPad Air, fifth generation iPad mini, first and second generation 11-inch iPad Pro, and third and fourth generation 12.9-inch iPad Pro.
In the second, Apple Watch Series 4, Apple Watch Series 5, first-generation Apple Watch SE, and HomePod mini. iPhones, iPads and Apple Watches with chips earlier or later than those mentioned would not be affected.
The origin of the problem is in the way the USB controllers on those chips handle the data they receive. According to the researchers, the system does not correctly reset some memory addresses between data transfers, allowing placing unauthorized code in a protected area of the chip. That is the key that opens the door to bypassing the usual restrictions of iOS.
The ‘jailbreak’ consists precisely in breaking part of the limitations imposed by Apple on its devices. It is usually used to install applications outside of the App Storemodify system functions, change interface elements or access parts of iOS that are normally locked to the user. In the hands of an advanced owner it may be a form of customization, but in the hands of an attacker it can also serve to compromise the device at a much deeper level.
Paradigm Shift warns that ‘usbliter8’ would allow install highly privileged software and potentially exfiltrate data stored on the device. Fortunately, this is not a vulnerability that can be exploited remotely. To take advantage of it You need physical access to the device and connect it to a Raspberry Piwhich greatly reduces the risk for most users.
Even so, the finding is relevant because it affects devices that may end up in the hands of third parties. A stolen, lost or seized iPhone could be more exposed if it belongs to one of the vulnerable generations. The technical difficulty does not eliminate the risk, although it does distance it from large-scale attacks that are carried out over the Internet or through malicious messages.
The main problem for Apple is that there is no possible patch. Being in the hardware, an iOS update cannot correct the chip design. The only real mitigation for anyone who needs a high level of security is stop using affected models and switch to a device with a non-vulnerable chip. For the average user, the practical recommendation remains to protect physical access to the phone well, keep the system updated and take extreme precautions if the device is lost or stolen.