<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Physical-Access on ZX Cloud Security</title><link>https://zxcloudsecurity.co.uk/tags/physical-access/</link><description>Recent content in Physical-Access on ZX Cloud Security</description><generator>Hugo</generator><language>en-GB</language><lastBuildDate>Thu, 19 Jun 2025 18:37:41 +0000</lastBuildDate><atom:link href="https://zxcloudsecurity.co.uk/tags/physical-access/index.xml" rel="self" type="application/rss+xml"/><item><title>usbliter8: Unpatchable Apple A12/A13 SecureROM Exploit</title><link>https://zxcloudsecurity.co.uk/posts/usbliter8-unpatchable-apple-a12-a13-securerom-exploit/</link><pubDate>Fri, 19 Jun 2026 18:37:41 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/usbliter8-unpatchable-apple-a12-a13-securerom-exploit/</guid><description>The usbliter8 exploit achieves arbitrary code execution in Apple A12 and A13 SecureROM. Hardware-level flaw cannot be patched — affected devices remain vul</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://thehackernews.com/2026/06/unpatchable-usbliter8-exploit-breaks.html">The Hacker News</a></p>
<hr>
<p>Security researchers have released a working exploit called &lsquo;usbliter8&rsquo; that targets a hardware-level vulnerability in Apple&rsquo;s A12 and A13 chips, achieving arbitrary code execution within the SecureROM — the foundational boot code burned permanently into the silicon. Because the flaw exists in read-only memory, Apple cannot patch it via software updates. The attack requires physical USB access to the device, but any affected device remains permanently vulnerable for its operational lifetime.</p>
<blockquote>
<p><strong>Security Architect&rsquo;s Take:</strong> Review your organisation&rsquo;s mobile device and endpoint policies for any iPhone XS, XR, or equivalent A12/A13-era devices used to access cloud management consoles, VPNs, or sensitive SaaS platforms. Consider accelerating refresh cycles for these devices and enforcing compensating controls such as conditional access policies that factor in device hardware generation.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://thehackernews.com/2026/06/unpatchable-usbliter8-exploit-breaks.html">Unpatchable &lsquo;usbliter8&rsquo; Exploit Breaks Apple A12 and A13 SecureROM Boot Chain</a></p>
]]></content:encoded></item></channel></rss>