A vulnerability has been found in the bootrom of all Apple devices with A5 to A11 chips.

Researcher axi0mX has discovered a vulnerability in the bootrom loader of Apple devices, which operates at the very first stage of booting and subsequently hands control over to iBoot. The vulnerability is named checkm8 and allows full control over the device. The published exploit can potentially be used to bypass firmware verification (Jailbreak), set up dual booting of other OSes, and various versions of iOS.

The issue is notable as the Bootrom resides in read-only NAND memory, preventing the problem from being fixed in devices already released (the vulnerability can only be addressed in new batches of devices). The issue manifests in SoCs from A5 to A11 used in products made from 2011 to 2017, starting with the iPhone 4S and ending with the iPhone 8 and X models.

A preliminary version of the code to exploit this vulnerability has already been integrated into an open (GPLv3) toolkit ipwndfu, designed for bypassing Apple's firmware. The exploit is currently limited to the functions of creating a SecureROM dump, decrypting firmware keys for iOS, and enabling JTAG. A fully automated jailbreak for the latest iOS release is possible but has not yet been implemented, as it requires further work. Currently, the exploit has been adapted for SoCs s5l8947x, s5l8950x, s5l8955x, s5l8960x, t8002, t8004, t8010, t8011, and t8015, and in the future will be expanded to support s5l8940x, s5l8942x, s5l8945x, s5l8747x, t7000, t7001, s7002, s8000, s8001, s8003, and t8012.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster