Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
proof-of-concept-releaseembedded-device-vulnerabilitywidely-deployed-product-advisoryendpoint-security-bypass

Boot-Level Flaws Expose Secure Boot Bypass on PCs and Unpatchable Exploit on Apple Chips

Updated 5d agoFirst seen Jun 15, 20264 sources

Researchers disclosed two separate boot-chain security issues that undermine trusted startup protections on major platforms. CERT/CC warned that outdated Microsoft-signed UEFI shim bootloaders—especially shim version 0.9 and earlier, including forked or unpatched builds used by vendors such as Red Hat Enterprise Linux, CentOS, Oracle, OpenSUSE, and WhiteCanyon—can be abused to bypass Secure Boot and run arbitrary code before the operating system loads. Because the attack executes in the early boot phase, it can evade EDR visibility and establish persistent compromise; Microsoft is responding by expanding the UEFI Forbidden Signature Database (DBX) to revoke vulnerable bootloaders, while administrators have been urged to update signature databases first and test carefully to avoid leaving systems unbootable.

Paradigm Shift also disclosed an unpatchable BootROM flaw in Apple A12 and A13 chips and released a proof-of-concept exploit, usbliter8, showing that affected devices from the iPhone XS through the iPhone 11 line can be compromised during startup. The bug stems from USB controller behavior in SecureROM that allows unauthorized memory writes via crafted packets, enabling temporary reduction of security settings, booting of unsigned software, and the familiar PWND USB serial marker after exploitation. Apple was notified before publication, but because the weakness is embedded in silicon, software updates cannot fully eliminate the risk for affected devices over their operational lifetime.

Share:
Boot-Level Flaws Expose Secure Boot Bypass on PCs and Unpatchable Exploit on Apple Chips
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Jun 18, 20266d ago

Researchers extend usbliter8 impact to Apple S4/S5 chips

Paradigm Shift said the usbliter8 BootROM exploit chain also affects Apple S4 and S5 chips, in addition to A12 and A13 devices. The expanded scope means the chain-of-trust compromise is not limited to iPhones using A12/A13 silicon and also impacts additional Apple hardware families built on vulnerable immutable BootROM code.

New iPhone BootROM Vulnerability Exposes Apple SoCs to Full Chain-of-Trust Compromise

Paradigm Shift discloses A12/A13 exploit and releases usbliter8 PoC

Paradigm Shift publicly disclosed the A12 and A13 BootROM vulnerability and released a proof-of-concept exploit named usbliter8. The exploit abuses a USB controller bug during startup to enable unauthorized memory writes, allowing temporary security downgrades and booting unsigned software on affected devices.

Apple's A12 and A13 Chips Facing New Unpatchable Exploit - MacRumors

Paradigm Shift reports A12/A13 BootROM flaw to Apple

Paradigm Shift reported a BootROM vulnerability affecting Apple A12 and A13 chips to Apple Product Security and coordinated disclosure before publication. Because the flaw resides in immutable BootROM/SecureROM code, affected devices cannot be fully fixed through software updates.

Apple's A12 and A13 Chips Facing New Unpatchable Exploit - MacRumors
Jun 15, 20269d ago

Microsoft expands DBX revocations to mitigate vulnerable shim bootloaders

Microsoft began mitigating the Secure Boot bypass risk by expanding the UEFI Forbidden Signature Database (DBX) to revoke trust in vulnerable bootloaders. The guidance emphasized updating authorized signature databases before deploying DBX revocations to avoid rendering systems unbootable.

Vulnerable UEFI Shim Bootloaders Allow Secure Boot Bypass

CERT/CC documents vulnerable Microsoft-signed UEFI shim bootloaders

Security researchers reported that outdated Microsoft-signed UEFI shim bootloaders, especially shim version 0.9 and earlier, can be abused to bypass Secure Boot across multiple operating systems and vendors. CERT/CC documented the issue, which affects forked and unpatched shim versions used by vendors including Red Hat Enterprise Linux, CentOS, Oracle, OpenSUSE, and WhiteCanyon.

Vulnerable UEFI Shim Bootloaders Allow Secure Boot Bypass
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

36 LINKEDOpen in app
Affected products
14 linked
Iphone XsIphone XrIphone 11CentosRed Hat Enterprise LinuxUefi ShellUefi ShellGrub2Uefi ShellUefi ShellUefi ShellUefi ShellUefi ShellUefi Shell
Organizations
22 linked
AppleParadigm ShiftSynopsysEsetUniwillToshiba CorporationRed HatASUSAdvanced Micro DevicesMicrosoft CorporationGIGABYTE TechnologyOracleAcerOpensuseSecurityOnline.infoSchenker TechnologiesEmdoorGetacWhiteCanyon SoftwareElitegroup Computer SystemsMaibenbenMaingear
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Boot-Level Flaws Expose Secure Boot Bypass on PCs and Unpatchable Exploit on Apple Chips | Mallory