<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Secure-Enclave on ZX Cloud Security</title><link>https://zxcloudsecurity.co.uk/tags/secure-enclave/</link><description>Recent content in Secure-Enclave on ZX Cloud Security</description><generator>Hugo</generator><language>en-GB</language><lastBuildDate>Fri, 19 Jun 2026 16:02:00 +0000</lastBuildDate><atom:link href="https://zxcloudsecurity.co.uk/tags/secure-enclave/index.xml" rel="self" type="application/rss+xml"/><item><title>BootROM Exploit Drops for A12 &amp; A13 iPhones — Unpatchable</title><link>https://zxcloudsecurity.co.uk/posts/checkm8-style-bootrom-exploit-a12-a13-iphone-securerom/</link><pubDate>Fri, 19 Jun 2026 16:02:00 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/checkm8-style-bootrom-exploit-a12-a13-iphone-securerom/</guid><description>A checkm8-style BootROM exploit for Apple A12 and A13 iPhones is now public. The hardware flaw is unpatchable via software — only a new device fixes it.</description><content:encoded><![CDATA[<p>🔴 <strong>Critical</strong>  |  <strong>Source:</strong> <a href="https://www.theregister.com/security/2026/06/19/researchers-drop-checkm8-style-bootrom-exploit-for-a12-and-a13-iphones/5259028">The Register — Security</a></p>
<hr>
<p>Security researchers have published a checkm8-style unpatchable BootROM exploit targeting Apple iPhones running A12 and A13 chips, including the iPhone XS through iPhone 11 series. Because the vulnerability exists in read-only boot firmware, Apple cannot issue a software patch — the only fix is a hardware replacement. This gives attackers a persistent, low-level foothold on affected devices that survives factory resets and OS reinstalls.</p>
<blockquote>
<p><strong>Security Architect&rsquo;s Take:</strong> Audit your mobile device fleet and MDM policies immediately: any corporate-issued or BYOD iPhone with an A12 or A13 chip should be considered untrustworthy for accessing sensitive cloud workloads or acting as an MFA device. Consider accelerating hardware refresh for those devices and enforce conditional access policies that block or flag authentication attempts from potentially compromised endpoints.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://www.theregister.com/security/2026/06/19/researchers-drop-checkm8-style-bootrom-exploit-for-a12-and-a13-iphones/5259028">Researchers drop checkm8-style BootROM exploit for A12 and A13 iPhones</a></p>
]]></content:encoded></item></channel></rss>