Join the discussion
Write your take first — we'll ask for email only when you're ready to publish.
- Hacker News
- Since this can only underflow and some written bits are not attacker-chosen, does this not imply that the patchable part of the software could reliably detect this just in time and panic on suspected USB DMA corruption? Where is the catch?by edelbitter
- The articles have been unclear about this: Does this let attackers unlock a stolen iphone, for example, or is this just about jailbreaking a phone that you own and control.by empath75
- Where did they get the code for SecureROM? Also, why is the ROM code so large, I thought the BootROM should contain the minimal code to boot from flash memory and that's all.by codedokode
- Sounds like it’s a low level hardware/firmware hole that can’t be patched.by djfergus
- Ohhhh this is interesting!!!!! I really miss the glory days of jailbreaking, it just unlocked so many handy, fun, and cool stuff. From running webservers to speeding up the terribly slow animations.by thenthenthen
- I first thought of SecuROM, a CD/DVD copy protection scheme applied to computer game discs: https://en.wikipedia.org/wiki/SecuROMby nayuki
- This is awesome news! It isn't a jailbreak in and of itself, but it is the first step.
Right now we only have a reliable jailbreak (checkm8) for up to iOS 18 (and that's only thanks to one iPad model). Some app developers are pretty aggressive about dropping support for older iOS versions.
This affects iPhone XR, XS, 11, SE 2nd gen, and a smattering of iPads. Many of these devices got the iOS 27 beta and will likely see future iOS versions for at least another year or two.
Edit: here's the affected iPads:
* iPad Pro 11" (gen 1-2)
* iPad Pro 12.9" (gen 3-4)
* iPad mini (gen 5)
* iPad Air (gen 3)
* iPad (gen 8-9)
by nfriedly - I'm curious what this will lead to, both security wise and jailbreak hobbyist wise. I saw this overview: https://www.reddit.com/r/jailbreak/comments/1ua58xd/usbliter... which mentions that it won't let an attacker gain full access to iOS on a passworded device without another exploit:
> BPR, or Boot Process Register, was a feature implemented in iOS 14 in order to additionally secure devices from bootROM based attacks. Crucially, it restricts data access when a device is booted directly from DFU mode, which is required by both checkm8 and usbliter8. In iOS 14 and 15, this manifested as the requirement to disable your passcode when jailbreaking A11 devices with checkra1n/palera1n, and is the reason why A11 devices must be first erased if they previously had a passcode before jailbreaking with palera1n. A10 devices were not affected by this as they had a SEP exploit, known as blackbird, which prevented this issue from arising. We do not have a SEP exploit for A11 and newer.
by ndiddy