Live data from Hacker News

Usbliter8: an A12/A13 SecureROM Exploit

ps.tc

31–39 of 39 posts

Re: Usbliter8: an A12/A13 SecureROM Exploit

#31
post #29
post #25

Earlier quoted context omitted.

They have to reboot it to use a bootloader exploit. Reboot it again after you get it back to erase whatever they did.

I realized they might have added a fake reboot menu. So either use the exploit yourself to check it's the real bootloader (no realistic chance the FBI made a fake bootloader exploit in the fake reboot menu) or let the battery run out or remove it.

All Apple mobile devices I've used have had some form of low-level forced reboot method, akin to holding down your PC's power button. Though I can't say whether it's also something one could subvert with a BootROM exploit.

https://support.apple.com/guide/iphone/force-restart-iphone-...

Re: Usbliter8: an A12/A13 SecureROM Exploit

#32
post #29

Earlier quoted context omitted.

I realized they might have added a fake reboot menu. So either use the exploit yourself to check it's the real bootloader (no realistic chance the FBI made a fake bootloader exploit in the fake reboot menu) or let the battery run out or remove it.

Nobody is going to add a fake reboot menu

Or they wouldn’t have, until they saw this thread, just for the sport

Re: Usbliter8: an A12/A13 SecureROM Exploit

#34

Where did they get the code for SecureROM? Also, why is the ROM code so large, I thought the BootROM should contain the minimal code to boot from flash memory and that's all.

Do you want to break out a flash programmer and disassemble the entire smartphone whenever someone bricks it via firmware?

If not, you need to have unbrick-capable DFU straight in BootROM.

Which typically means: ROM code that carries an entire USB stack, as well as means of validating and booting executables from the USB stack.

An alternative would be to have BootROM recovery off MicroSD, but, iPhone lmao. They didn't chase the trend of "no expandable storage" - they created it.

Re: Usbliter8: an A12/A13 SecureROM Exploit

#36

Where did they get the code for SecureROM? Also, why is the ROM code so large, I thought the BootROM should contain the minimal code to boot from flash memory and that's all.

Many are dumped publicly at https://securerom.fun/

Some were dumped via known exploits, but I don't know how A12/A13 were dumped in the first place. I'd guess someone got code exec via fault injection and dumped it out that way, or perhaps just a privately known vuln.

iBoot source code has also been leaked, in the past.

Re: Usbliter8: an A12/A13 SecureROM Exploit

#37
post #21

This is awesome news! It isn't a jailbreak in and of itself, but it is the first step. Right now we only have a reliable jailbreak (checkm8) for up to iOS 18 (and that's only thanks to one iPad model). Some app developers are pretty aggressive about dropping support for older iOS versions. This affects iPhone XR, XS, 11, SE 2nd gen, and a smattering of iPads. Many of these devices got the iOS 27 beta and will likely…

Also great new for Cellebrite?

Not unless they also have a SEP exploit.

Re: Usbliter8: an A12/A13 SecureROM Exploit

#38
post #25

Earlier quoted context omitted.

Once the feds have the phone, they aren't going to allow him to touch it, much less reboot it.

They have to reboot it to use a bootloader exploit. Reboot it again after you get it back to erase whatever they did.

seems like a huge amount of effort when they could simply give you a bugged phone of the same model that automatically transmits the passcode to them when you enter it. Newest ios are usually vulnerable to Cellebrite anyways.
Post reply on HN