Researchers found a flaw in older iPhones that Apple can never fully fix. The attack, named usbliter8 and shown on June 18, 2026, breaks the very first code these phones run when they turn on. The catch for any attacker is huge. Nobody can do this over the internet. They have to be holding your actual phone, plug in a cable, and use a small gadget.
The reason Apple cannot patch it is the wild part. The broken code lives in a tiny piece of the phone's chip that gets burned in at the factory. It stays read-only for life, so no iOS update can touch it.
What it does
The attack lets someone run their own code at the deepest level of the phone, before iOS even loads. It skips Apple's check that the system is really from Apple, then boots a changed version instead. Picture a thief who has your phone and wants to load their own software onto it. This gives them a way in.
It does not crack your passcode, and it does not read your photos or messages. A separate locked part of the chip guards those, and this attack does not break it.
usbliter8 disclosure write-up details the steps, and the usbliter8 project lists the cheap maker board it needs.
Who should worry
For everyday use, almost no one. The trick only works hands-on, and it resets every time the phone restarts. So it matters for a phone that gets lost or stolen, not the one in your pocket with a passcode.
It hits Apple gear built on the A12 and A13 chips: the iPhone XR, XS, 11, the 2020 iPhone SE, several iPads, two Apple Watch models, and the HomePod mini. An iPhone 12 or newer is safe.
This is the same kind of unfixable flaw as checkm8, the 2019 attack on even older iPhones. As of June 19, Apple had put out no warning. The researchers say the only real fix is a newer phone, since the chip cannot be patched.





