• News/
  • zdnet-f80d43c0-850a-43bc-a7f3-43a7cf643c69

Older iPhones have an unfixable security flaw - why it can't be patched and the models affected

ZDNet
·
Lance Whitney
·
Published Jun 22, 2026
·
Updated

The notch at the top of an iPhone XS Max. Follow ZDNET: Add us as a preferred source on Google. Do you still use an iPhone 11, XS, XR, or SE? If so, I have some bad news. Yep, another security flaw has been discovered, and Apple can't fix this with one of its typical updates. In a blog post published on Thursday, cybersecurity firm Paradigm Shift revealed a security vulnerability that it discovered and successfully exploited in older model iPhones with Apple's A12 or A13 chip. Dubbed usbliter8, the flaw affects the boot ROM, aka SecureROM, code of an iPhone, which executes before the operating system loads. By exploiting usbliter8, an attacker could install their own malicious code or run unauthorized commands on a victimized iPhone. Also: The 10-step phone security tune-up you should run every year - and why Because the flaw is in the device's ROM, Apple can't patch it via a software update. The only saving grace is that the flaw can't be triggered remotely. An attacker would need physical access to your phone. They would also need enough time to restart your device and enough know-how to take advantage of the exploit. Plus, the researchers at Paradigm Shift were unable to bypass Apple's other security safeguards, such as Data Protection. As such, your files, photos, messages, and other user data are not affected by the flaw. But that doesn't mean there's no cause for concern. "BootROM vulnerabilities are relatively rare, and when they surface the physical access requirement...

Read full article

Affected Software

6 affected components
Apple iPhone=devices with A12 or A13 processors (2018–2019)
Apple iPhone=11
Apple iPhone=XS
Apple iPhone=XR
Apple iPhone=SE
Apple Apple Watch=Series 4, =Series 5, =SE (1st generation)
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a newly discovered unfixable security flaw affecting older iPhone models that cannot be patched by Apple.

2

Which iPhone models are affected by this security flaw?

The affected models include iPhone 11, iPhone XS, iPhone XR, and iPhone SE.

3

What makes this security flaw unfixable?

The flaw is unfixable due to its deep integration within the hardware that prevents a typical software update from addressing it.

4

What implications does this security flaw have for users?

Users of the affected iPhone models may be vulnerable to exploitation, as no patch will be issued to resolve the issue.

5

When was this security flaw published and reported?

The security flaw was published and reported on June 22, 2026.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203