The cybersecurity market has faced a serious challenge: the Spanish company Paradigm Shift, based in Barcelona, has published technical details of an exploit capable of hacking millions of Apple smartphones. The tool, named usbliter8, provides access to devices whose protection was considered invincible.

Vulnerability at the silicon level

The main feature of the discovered defect is that it is hardcoded directly into the architecture of Apple's proprietary A12 and A13 Bionic processors. The problem lies in the Boot ROM — the boot read-only memory that activates first upon power-on and serves as the foundation of the iPhone's digital protection.

Since the bootloader code is "etched" into the silicon structure of the chip during manufacturing, specialists confirm: it is technically impossible to fix the vulnerability using standard iOS software updates. This is the first time Apple's basic line of defense has been breached at the hardware level.

How the attack works

To implement the exploit, attackers or forensic experts need physical access to the device. It is sufficient to connect the smartphone to a cable to activate the bug. Thanks to usbliter8, hackers gain the ability to completely disable subsequent levels of security checks that usually block unauthorized access.

The vulnerability affects a wide range of popular models released in 2018 and 2019. The only effective method of protection against potential spying, according to experts, is for users to fully switch to newer generations of smartphones equipped with new processors.

Jailbreak boom and market reaction

The publication of the usbliter8 code has caused a stir among independent researchers and developers. Open access to the exploit will significantly facilitate the creation of so-called jailbreaks — the procedure for removing factory restrictions on the operating system.

Over the last decade, such utilities have become rare. Exploit developers on the black market preferred to keep their findings secret so that Apple would not have time to close loopholes and deprive them of income. Now the situation has changed: the code is available to everyone.

Real risks for users

Despite the sensational headlines, experts reassure ordinary iPhone owners: usbliter8 itself does not mean that anyone can instantly leak personal files from the phone. To access encrypted data, hackers will have to develop and link several additional vulnerabilities into a single chain.

Furthermore, major commercial developers of digital forensics systems, supplying tools to the police and special services, likely already have similar private methods for bypassing the Boot ROM in their arsenal to unlock confiscated devices. The publication by Paradigm Shift simply legalizes access to this technology for a wide range of specialists.