Security researchers at change published details of a new, unpatchable BootROM exploit affecting Apple’s A12 and A13 chips last month, then removed the post after being hit with a lawsuit from digital forensics company Magnet Forensics. The exploit, called usbliter8, enables arbitrary code execution on devices including the iPhone XS and iPhone 11 series, and because it lives in hardware, no software update can ever fix it.

What the Exploit Actually Does
BootROM vulnerabilities are about as serious as iPhone security flaws get. The BootROM is the first code a device executes when it powers on, and it is burned into the chip at manufacture. Any bug found there is permanent. Paradigm Shift’s researchers identified usbliter8 by combining a hardware bug in the USB controller with a specific configuration flaw in the device firmware. The result affects these Apple chips:
- A12 (iPhone XS, XS Max, XR)
- A13 (iPhone 11, 11 Pro, 11 Pro Max)
- S4 and S5 (select Apple Watch models)
The last comparable exploit was checkm8, published in 2019, which covered devices from the iPhone 4S through the iPhone X. Usbliter8 picks up roughly where checkm8 left off, extending the window of permanently vulnerable Apple hardware by two additional chip generations.
Paradigm Shift followed responsible disclosure procedures, sharing its findings with Apple Product Security before going public. Apple’s team engaged cooperatively throughout the process. That goodwill did not extend to the forensics industry.
Magnet Forensics filed a complaint in Georgia federal court this month alleging that former contractor Mario Del Gaudio brought trade secrets to Paradigm Shift. The core claim is that the usbliter8 vulnerability is substantially the same as one Del Gaudio worked on during his time at Magnet Forensics, and that by publishing it, change exposed proprietary research.
The lawsuit reveals how the forensics industry actually operates. Companies like Magnet Forensics sell hardware devices, GrayKey being the well-known example, to law enforcement and intelligence agencies for extracting evidence from locked iPhones. Their business model depends entirely on keeping these exploits secret. Disclose a vulnerability to Apple, and Apple may find a way to mitigate it architecturally, rendering the tool obsolete. Keep it quiet, and you have a durable commercial product.
This dynamic puts forensics firms directly at odds with security researchers, who operate under the principle that public disclosure protects everyone in the long run. Change apparently believed usbliter8 met the bar for responsible public disclosure. Magnet Forensics clearly disagreed, and now a federal court will have to sort out who owns an exploit when a researcher crosses from one firm to another.
Roughly one in five to one in four active iPhones worldwide is an iPhone 11 or earlier, which means tens of millions of devices are permanently exposed to usbliter8 with no patch coming, ever. Users on these devices can mitigate risk through behavior, avoiding untrusted USB connections is the practical advice here, but the underlying vulnerability cannot be closed.
The parallel to checkm8 is worth taking seriously. Within months of that exploit going public in 2019, it became the backbone of multiple jailbreak tools. Paradigm Shift’s post is currently offline because of the lawsuit, but the technical details are unlikely to stay contained indefinitely. If and when they circulate more widely, the jailbreaking community will almost certainly treat usbliter8 the same way.
The legal question at the center of this case, whether a researcher can be sued for independently publishing knowledge of a vulnerability they may have first encountered at a previous employer, has real implications beyond this dispute. A ruling in Magnet Forensics’ favor would give forensics companies a powerful tool to suppress security research. Responsible disclosure norms exist precisely to prevent that outcome.