Researchers Boot Jailbroken iOS 17 on iPhone 11 Pro
Key Takeaways Security researchers have successfully booted a jailbroken version of iOS 17 on an iPhone 11 Pro. The exploit leverages the SecureROM vulnerability “usbliter8,” which...
Key Takeaways
- Security researchers have successfully booted a jailbroken version of iOS 17 on an iPhone 11 Pro.
- The exploit leverages the SecureROM vulnerability “usbliter8,” which affects Apple A12 and A13 processors.
- Exploitation requires physical access to the device in Device Firmware Upgrade (DFU) mode and specialized hardware.
- Since SecureROM is immutable, this vulnerability cannot be patched via software updates on affected hardware.
- The resulting jailbroken environment is experimental and causes significant functional limitations to the device.
Cybersecurity researchers have achieved a significant milestone by successfully booting a jailbroken iteration of iOS 17 on an iPhone 11 Pro. This accomplishment leverages the recently unveiled “usbliter8” SecureROM exploit, combined with an extensively customized firmware loading process.
Table Of Content
The demonstration specifically targets Apple’s iPhone 11 Pro, a device powered by the A13 Bionic chip. It illustrates how an attacker with physical access can exploit the device in DFU mode to circumvent the standard boot-chain security mechanisms.
This project, detailed in the 34306/usbliter8-fun GitHub repository, builds upon prior work by developer wh1te4ever. It incorporates specific patches tailored for iOS 17.0 beta 2, identified by build number 24A5370h.
The iPhone 11 Pro remains a compatible device for iOS 17, and Apple’s iOS 17 beta 2 release utilized the aforementioned build number. Central to this research is “usbliter8,” a bootrom-level exploit released by Paradigm Shift, which targets Apple’s A12 and A13 processors.
The exploit functions by manipulating the USB Device Firmware Upgrade mode. Successful execution necessitates physical access to the target device and the connection of specialized hardware by the researcher or attacker.
A critical aspect of this vulnerability is its location within SecureROM, immutable code embedded directly into the device’s silicon. Consequently, this type of vulnerability cannot be fully remediated through standard iOS software updates.
Jailbroken iOS 17 Achieved on iPhone 11 Pro
The implementation on the iPhone 11 Pro reportedly utilizes a Raspberry Pi Pico 2, configured with an RP2350 microcontroller, acting as the USB exploit device. Once the iPhone enters a compromised DFU state, identifiable by the “PWND:[usbliter8]” USB serial marker, researchers gain the ability to load modified boot components and restore a custom iOS image.
It is important to note that this attack is not remote. It requires DFU access, a direct USB connection, compatible hardware, and considerable technical expertise. The custom firmware includes modifications to both the kernel and userland, designed to disable various iOS security features.
Reported alterations encompass bypasses for USB Restricted Mode, circumvention of sandbox execution limitations affecting the /var/jb directory, and modifications to Apple Mobile File Integrity trust-cache checks. These changes are crucial for enabling the execution of unsigned or otherwise untrusted code, a fundamental requirement for any jailbreak environment.
Researchers also adapted system services to manage the inherent instability arising from the use of incompatible or unavailable Secure Enclave Processor (SEP) components.
Patches were implemented to prevent crashes in critical services such as coreauthd and ctkd. Concurrently, modifications related to device activation aim to present the altered device as officially activated.
The repository further disables a launchd job associated with Screen Time, addressing a deadlock encountered during the Setup Assistant process. The resulting installation is highly experimental and comes with significant functional limitations.
According to the project’s documentation, restoring this custom firmware can erase the device and render essential services inoperable. These include SEP functions, passcode support, Wi-Fi, baseband connectivity, Bluetooth functions, and various Apple services. The repository explicitly advises against attempting this procedure on a primary device.
Upon successful boot, the project facilitates USB-based SSH access and outlines the installation of a bootstrap environment and the Sileo package manager. However, network connectivity may necessitate USB internet sharing from a Mac, as normal Wi-Fi and cellular functions can be unavailable on the modified device.
This research underscores the enduring security implications of SecureROM-level vulnerabilities on older Apple hardware. While exploitation demands physical access and significant technical proficiency, “usbliter8” empowers researchers to examine and manipulate devices outside Apple’s conventional chain of trust, even on newer iOS versions like iOS 17.
It is noteworthy that at the time of “usbliter8’s” initial reporting, no CVE, CVSS score, Apple security advisory, or publicly documented in-the-wild exploitation had been disclosed.
What You Should Do
- Ensure your devices are running the latest available software updates to mitigate known software-level vulnerabilities.
- While this specific exploit requires physical access, always maintain physical security of your devices, especially in unsecured environments.
- Be cautious of third-party modifications or jailbreaks, as they often introduce instability and compromise device security.
- For devices with A12 or A13 processors, be aware that bootrom-level vulnerabilities like “usbliter8” cannot be fully patched by software updates.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.