Accueil / Apps & Logiciels / New lawsuit alleges unpatchable Apple chip exploit was developed using stolen trade secrets

New lawsuit alleges unpatchable Apple chip exploit was developed using stolen trade secrets

Magnet Forensics is suing Paradigm Shift Technology over its publication of usbliter8, alleging that the unpatchable exploit affecting several Apple SoCs was developed using trade secrets misappropriated by a former engineer. Here are the details.

Last month, researchers at Paradigm Shift published the technical details of usbliter8, a new unpatchable iPhone BootROM vulnerability that enables arbitrary code execution on devices powered by Apple’s A12 and A13 chips.

The bug, which affects the A12, S4, S5, and A13 SoCs, relies on specially crafted data that confuses the device’s USB controller, and gives an attacker physical access to the device and control over its startup process.

From there, the attacker can run their own code before iOS loads, bypass signature checks, and boot modified system software.

Because usbliter8 targets the BootROM, it cannot be fixed through a software update. Its practical impact is somewhat limited, however, as it only affects older Apple chips introduced in 2018 and 2019.

At the time, Paradigm Shift said the disclosure of the exploit had been coordinated with Apple Product Security. Now, Magnet Forensics claims usbliter8 was derived from confidential work performed by a former engineer who later joined Paradigm Shift.

Defendant Mario Del Gaudio worked as an Exploit Engineer placed with Magnet Forensics from November 2023 through November 2024. […] During his tenure, Del Gaudio was assigned to work on one of Magnet Forensics’ most sensitive proprietary capabilities: a zero day access capability internally designated as “MSG.”

After his placement with Magnet Forensics ended, Del Gaudio became affiliated with Defendant Paradigm Shift, an entity in the technology and cybersecurity industry in the business of monetizing access capabilities. On June 18, 2026, Paradigm Shift published a detailed technical blog post titled “Introducing usbliter8: An A12/A13 SecureROM Exploit” […], which disclosed extensive technical details regarding a proprietary access capability that is, in substance, the same capability Del Gaudio worked on at Magnet Forensics under the MSG designation.

Magnet Forensics claims it has proof that Del Gaudio is directly linked to the publication of the usbliter8 exploit, and says that Paradigm Shift has ignored multiple cease-and-desist demands to pull the publication and proof-of-concept code.

In addition to wanting the usbliter8 publication and related materials removed, Magnet Forensics is seeking financial compensation and a court order preventing any further use or disclosure of its alleged trade secrets.

To read Magnet Forensics’s full complaint and its associated documents, follow this link.

FTC: We use income earning auto affiliate links. More.

Check out 9to5Mac on YouTube for more Apple news:

Marcus Mendes is a Brazilian tech podcaster and journalist who has been closely following Apple since the mid-2000s.

He began covering Apple news in Brazilian media in 2012 and later broadened his focus to the wider tech industry, hosting a daily podcast for seven years.

Origine de l’article : lire l’article original
Traduction