An unfixable security flaw affects several iPhone models
Security researchers have discovered a hardware-based vulnerability affecting older Apple devices equipped with A12, A13, S4, and S5 chips. While the flaw cannot be fixed through software updates, it requires physical access to the device and does not compromise the Secure Enclave.
Security researchers at Paradigm Shift have disclosed a serious and unpatchable vulnerability affecting several older Apple devices, including multiple generations of iPhones, iPads, and Apple Watches.
According to a detailed technical report, the flaw—dubbed "usbliter8"—stems from a hardware-level defect in the USB interface combined with a firmware configuration issue, making it impossible for Apple to fully fix through future software updates.
Which Devices Are Affected?
The vulnerability impacts devices powered by Apple's A12, A13, S4, and S5 chips, including:
iPhone XR
iPhone XS
iPhone XS Max
iPhone 11
iPhone 11 Pro
iPhone 11 Pro Max
iPhone SE (2nd generation)
Several older iPad, Apple TV, and Apple Watch models
How Does the Vulnerability Work?
The exploit targets Apple's Device Firmware Update (DFU) mode. If an attacker gains physical access to a device and connects it via USB, specially crafted data can be sent to manipulate the USB controller and force it to write to unintended memory locations.
This allows attackers to inject custom code before iOS boots, potentially bypassing certain security protections. The flaw can enable modified system software to run or circumvent some digital signature verification processes.
Because the exploit executes before the operating system fully loads, it is considered particularly valuable for security researchers and reverse-engineering specialists.
Are User Data at Risk?
Despite its severity, researchers emphasized that one of Apple's most important security components remains protected. The vulnerability does not affect the Secure Enclave, Apple's dedicated security processor responsible for safeguarding passcodes, encrypted data, and sensitive information.
As a result, attackers cannot use this exploit alone to extract device passcodes or directly access encrypted data stored within the Secure Enclave.
More importantly, the vulnerability requires physical possession of the device and a USB connection. It cannot be exploited remotely through the internet, malicious websites, emails, or text messages.
Researchers said Apple has worked with them to understand the issue. However, because the flaw is rooted in hardware rather than software, it cannot be fixed through future iOS updates. The most effective long-term solution is upgrading to newer devices powered by more recent Apple Silicon generations that are not affected.
What Does This Mean for Everyday Users?
For most consumers, the vulnerability poses limited practical risk as long as their devices remain physically secure. However, it could become a concern in situations involving device theft, confiscation, or direct access by highly skilled attackers.
That is why researchers describe the flaw as highly serious despite the relatively narrow conditions required for successful exploitation.

