usbliter8: non-patchable SecureROM A12/A13 exploit — actions

Colleagues, an exploit named usbliter8 has been published that achieves code execution in SecureROM on A12/A13.
Summary:
— Root cause: hardware flaw in Synopsys DWC2 (DMA underflow) permits SRAM overwrite.
— Affected: SoCs A12/A13/S4/S5 (iPhone 11/XS/SE2, early iPad, Apple Watch, etc.); A14 and newer are not at risk.
— Conditions: requires physical access, DFU, USB and a specialized controller; the exploit operates before the signed boot chain.
Recommendations: inventory impacted devices, prioritise upgrades to A14+, and disable DFU/USB in critical environments.
Why it matters: hardware vulnerabilities cannot be mitigated by software alone—physical access controls are essential.
How do you manage device issuance and storage in your organisation?
#cybersecurity #vulnerabilities #Apple #infosec

