This Week In Security: Stealing Email With AI, AMD Nerfs Chips, The World Cup Nearly Rickrolled, And GPSD Bugs

Firefox recently added integrated AI support — a generally poorly received move among many Firefox users — that includes an AI chatbot integration for interacting with web pages. Floria…

Hackaday
Paradigm Shift - Introducing usbliter8

This write-up details a novel iPhone BootROM vulnerability discovered and exploited by our team. It covers the underlying bug, the associated exploitation techniques, and the post-exploitation steps required...

Unpatchable BootROM Flaw Impacts Apple A12 and A13 (usbliter8) via USB Controller + SecureROM - https://www.redpacketsecurity.com/unpatchable-bootrom-flaw-impacts-apple-a12-a13-chips/

#threatintel #iPhone_BootROM #USB_Controller_Exploit #SecureROM

Unpatchable BootROM Flaw Impacts Apple A12 and A13 (usbliter8) via USB Controller + SecureROM - RedPacket Security

A novel iPhone BootROM vulnerability has been discovered by researchers that gives attackers with physical access a route to compromise the boot chain on

RedPacket Security

Mashable: Older iPhones are vulnerable to a flaw Apple likely can’t fix. “The issue exists within SecureROM, the code that runs when an iPhone turns on, which is embedded in certain chips. Apple can’t fix these flaws, as the code can’t be extracted from the chips.”

https://rbfirehose.com/2026/06/21/mashable-older-iphones-are-vulnerable-to-a-flaw-apple-likely-cant-fix/
Mashable: Older iPhones are vulnerable to a flaw Apple likely can’t fix

Mashable: Older iPhones are vulnerable to a flaw Apple likely can’t fix. “The issue exists within SecureROM, the code that runs when an iPhone turns on, which is embedded in certain chips. Ap…

ResearchBuzz: Firehose
Вразливість usbliter8 на iPhone: мільйони пристроїв Apple отримали незламну проблему безпеки
# #A12 #A13 #Apple #BootROM #IPhone #SecureEnclave #SecureROM #Usbliter8
https://gizchina.net/2026/06/21/usbliter8-vrazlyvis-iphone-a12-a13-bootrom/
Вразливість usbliter8 на iPhone: мільйони пристроїв Apple отримали незламну проблему безпеки

Вразливість usbliter8 на iPhone стала однією з найсерйозніших апаратних загроз для пристроїв A

GizChina.net
Вразливість usbliter8 на iPhone: мільйони пристроїв Apple отримали незламну проблему безпеки
# #A12 #A13 #Apple #BootROM #IPhone #SecureEnclave #SecureROM #Usbliter8
https://gizchina.net/2026/06/21/usbliter8-vrazlyvis-iphone-a12-a13-bootrom/
Вразливість usbliter8 на iPhone: мільйони пристроїв Apple отримали незламну проблему безпеки

Вразливість usbliter8 на iPhone стала однією з найсерйозніших апаратних загроз для пристроїв A

GizChina.net

BootROM Exploit Targets Millions of iPhones

Millions of iPhones are vulnerable to a newly discovered BootROM exploit, known as "usbliter8", that can't be fixed with software updates because it's embedded in the device's hardware. This means iPhones with A12 and A13 processors will be at risk for the rest of their lifespan.

https://osintsights.com/bootrom-exploit-targets-millions-of-iphones?utm_source=mastodon&utm_medium=social

#BootromExploit #Iphones #A12Processor #A13Processor #Securerom

BootROM Exploit Targets Millions of iPhones

Learn about the BootROM exploit targeting iPhones with A12 and A13 processors, and find out if your device is vulnerable - read the details now and take action to protect yourself.

OSINTSights

Decided to fork #pongoos and work on a new project called "secuOS".

What is secuOS?

secuOS aims to be an alternative OS to #ios for #checkm8 capable #iphone devices using the #checkra1n application.

It aims to support A6-A11 chips/devices. (A5 excluded, nightmarish and 32-bit so no 4s)

"SecureROM? More Like InSecureROM."

GitHub: https://github.com/AFellowSpeedrunner/secuOS

Using the 6s on this project as of now.

#apple #securerom #exploit #tech #technology #osdev #programming #operatingsystems #development

GitHub - AFellowSpeedrunner/secuOS: secuOS, an alternative OS for the iPhone based off of pongoOS

secuOS, an alternative OS for the iPhone based off of pongoOS - AFellowSpeedrunner/secuOS

GitHub

iPhone/iPadなどに修正困難な脆弱性 ~物理アクセス可能であれば端末ロックを突破できる
OS起動に用いる“SecureROM”には解放済みメモリ使用の欠陥
https://forest.watch.impress.co.jp/docs/news/1226007.html

せやな。

#Apple #AppleTV #AppleWatch #CVE-2019-890 #iPad #iPhone #iPodTouch #JVN #SecureROM

iPhone/iPadなどに修正困難な脆弱性 ~物理アクセス可能であれば端末ロックを突破できる/OS起動に用いる“SecureROM”には解放済みメモリ使用の欠陥

 脆弱性対策情報ポータルサイト“JVN”は12月20日、脆弱性レポート(JVNVU#95417700)を公開した。Apple製デバイスの“SecureROM”には解放済みメモリ使用(use-after-free)の脆弱性(CVE-2019-890)が存在し、製品へ物理的にアクセスできる第三者によって任意のコードを実行されてしまう可能性があるという。