# Apple's A12/A13 iPhones Have an Unfixable Chip Hole — XS Through 11 Cooked Forever

**URL:** <https://onehack.st/t/apples-a12-a13-iphones-have-an-unfixable-chip-hole-xs-through-11-cooked-forever/325019>\
**Category:** News & Articles\
**Tags:** hacking, phone, tips-tricks, news\
**Created:** [August 24, 2026, 2:39pm UTC](https://onehack.st/t/apples-a12-a13-iphones-have-an-unfixable-chip-hole-xs-through-11-cooked-forever/325019 "2026-08-24T14:39:28Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![Aina](https://onehack.st/user_avatar/onehack.st/aina/32/167469_2.png) [@Aina](https://onehack.st/u/Aina)\
**Post date:** [August 24, 2026, 2:39pm UTC](https://onehack.st/t/apples-a12-a13-iphones-have-an-unfixable-chip-hole-xs-through-11-cooked-forever/325019/1 "2026-08-24T14:39:28Z")

</div>

# 🔓 Apple Just Found Out Its Own iPhones Have a Hole That Can NEVER Be Fixed — iPhone XS Through 11 Are Cooked Forever

_Somebody found a crack in the chip itself. Not the software — the actual metal. You can’t update your way out of this one. Ever._

**Affected: iPhone XS → iPhone 11, plus iPad Air 3, iPad mini 5, iPad 8/9, iPhone SE2, Apple Watch S4/S5, HomePod mini, even the Studio Display. Tens of millions of devices with a wound that stays open for life.**

Okay so. You’re not ready for this one. Some security crew dropped a working tool called “usbliter8” that busts open the very first piece of code an iPhone runs when it wakes up — the part burned straight into the chip at the factory. And because it’s baked into the metal, Apple physically CAN’T patch it. No update fixes it. These phones die vulnerable. There’s even [a lawsuit now](https://www.macrumors.com/2026/07/24/unpatchable-iphone-11-exploit-sparks-legal-battle/). Read the [original 9to5Mac writeup](https://9to5mac.com/2026/06/18/new-unpatchable-exploit-targets-apple-devices-with-a12-and-a13-chips/) and the [MacRumors breakdown](https://www.macrumors.com/2026/06/18/a12-and-a13-chips-facing-exploit/). I mean. WHAT.

![circuit board](https://media.giphy.com/media/IcZhFmufozDCij3p22/giphy.gif)

> **🧩 Dumb Mode Dictionary (read this first, everything clicks after)**
>
> | Scary Word | What It Actually Means |
> | --- | --- |
> | **BootROM / SecureROM** | The very first tiny program a phone runs the instant you power it on. It checks “is this a real Apple phone?” before anything else. |
> | **Baked into silicon** | The code is physically etched into the chip when it’s made. Like a tattoo — you can’t edit it later with an update. |
> | **Unpatchable** | Apple literally cannot fix it. The only “fix” is buying a newer phone. |
> | **DFU mode** | A “totally blank” state you put an iPhone into with button combos + a USB cable. Used for deep repairs. |
> | **Jailbreak** | Kicking Apple’s locks off so YOU decide what runs on your device — install anything, change anything. |
> | **PoC (proof-of-concept)** | A working demo that proves the hack is real, not just talk. |

> **🕰️ Wait, haven't we seen this movie before? (yeah — and it was legendary)**
>
> Back in 2019 a hacker dropped [**checkm8**](https://en.wikipedia.org/wiki/Checkm8) — the SAME kind of forever-hole, but on older chips (iPhone X and down). It powered the famous [checkra1n jailbreak](https://checkra.in/) and basically gave those phones a second life for years.
> 
> This new one? It’s checkm8’s big brother. It jumps forward two whole generations — to the A12 and A13. That’s a HUGE chunk of iPhones people are still using in 2026.
> 
> - Same flavor: physical USB + DFU mode required (nobody’s hacking you over WiFi with this).
> - Same result: run your own code _before_ Apple’s system even loads.
> - The [RedEye Security teardown](https://threat-intelligence.redeyesecurity.com/blog/usbliter8-apple-a12-a13-securerom-exploit-2026.html) has the gory technical bits if you wanna nerd out.

> **😱 So am I about to get hacked? (calm down, read this)**
>
> Short answer: **not remotely.** This isn’t a virus. Nobody’s stealing your bank app from across the internet.
> 
> The catch — someone needs your phone **in their hands** , plugged into a computer, for a few minutes. So:
> 
> - Regular you, phone in your pocket? Basically fine.
> - Cops, border agents, a shady repair shop, a jealous ex with your unlocked laptop? _Different_ story — physical access changes everything.
> 
> The scary part isn’t your daily life. It’s that the door can NEVER be shut on these models. Whatever the tool can do today, it can do in 2035 too. That’s why [Privacy Guides flagged it](https://www.privacyguides.org/news/2026/06/19/unpatchable-exploit-found-apples-a12-and-a13-chips/).

> **📋 The full hit-list (is YOUR gadget on here?)**
>
> | Chip | Devices Stuck With It Forever |
> | --- | --- |
> | **A12** | iPhone XS / XS Max / XR, iPad Air 3, iPad mini 5, iPad 8, Apple TV 4K (gen 2) |
> | **A13** | iPhone 11 / 11 Pro / Pro Max, iPhone SE (2nd gen), iPad 9, Studio Display |
> | **S4 / S5** | Apple Watch Series 4, Series 5, first Apple Watch SE, HomePod mini |
> 
> Yeah — the **Studio Display** ($1,600 monitor) is on the list. A _monitor_. Because it secretly runs an iPhone chip inside. Wild, right? Full list on [9to5Mac](https://9to5mac.com/2026/06/18/new-unpatchable-exploit-targets-apple-devices-with-a12-and-a13-chips/).

> **⚖️ Now there's a lawsuit (of course there is)**
>
> Fast-forward a month and lawyers showed up. Owners are arguing Apple sold devices with a permanent security flaw and can’t (or won’t) make it right on gear people are still paying off. Whether it goes anywhere is anyone’s guess — but the [legal fight is real](https://www.macrumors.com/2026/07/24/unpatchable-iphone-11-exploit-sparks-legal-battle/).
> 
> Here’s the plot twist though: to hackers, hobbyists, and repair folks, an unpatchable hole isn’t a bug. It’s a **gift.** Keep reading. 👇

#### Cool. So Millions of “Locked” Apple Bricks Just Became Wide-Open Playgrounds… Now What the Hell Do We Do? ( ͡° ͜ʖ ͡°)

![handheld game console](https://media.giphy.com/media/RCUwXSkpRTdAFWjJim/giphy.gif)

> **🕳️ The Dead-Phone Necromancer**
>
> People throw out iPhones that are “bricked” — stuck in a boot loop, won’t turn on, endless Apple logo. Most get tossed for $10 or free. But a BootROM-level tool can force these into DFU and **flash a clean system back on** — reviving stuff Apple’s own store gave up on.
> 
> Buy dead A12/A13 phones by the box, revive the fixable ones, resell as working refurbs.
> 
> 🧠 _Example:_ A 24-year-old repair hobbyist in Nigeria scoops “for parts / boot loop” iPhone XS lots off local marketplaces at ~$15 each, revives ~6 of every 10 with DFU restore tools like [libimobiledevice](https://libimobiledevice.org/), flips them at $90+. That’s a fat margin on e-waste nobody wanted.
> 
> > 📈 **Timeline:** First flip in 1–2 weeks once you learn the button combos. Stays alive as long as A12/A13 phones keep circulating (years). Slows when local supply of dead units dries up.

> **🔧 The Downgrade Dealer**
>
> Here’s a thing normies don’t know: you CAN’T normally roll an iPhone back to an older iOS. Apple blocks it. But bootrom-level access laughs at that block. Tons of people WANT old iOS — an app they love broke on the new update, or a game feature got nuked, or they just hate the new look.
> 
> Offer a downgrade / “keep-my-old-iOS” service for A12/A13 owners.
> 
> 🧠 _Example:_ A 22-year-old in the Philippines runs a tiny WhatsApp service downgrading iPhone 11s for locals whose favorite modded apps stopped working on the latest iOS, charging ~$20 a pop. Word-of-mouth in one city = steady weekend income. Reference tools: the classic [checkra1n](https://checkra.in/) lineage.
> 
> > 📈 **Timeline:** First paying customer within days of posting in local groups. Plateaus once you saturate your city — then franchise the how-to to another town.

> **🎮 The Pocket Arcade Plug**
>
> A jailbroken old iPhone = a shockingly good retro game handheld. Emulators for old consoles run buttery on an A13. Grandma’s drawer iPhone 11 becomes a Game Boy / SNES / PS1 machine that fits in your palm.
> 
> Buy cheap old models, jailbreak, pre-load emulators + a controller clip, sell as a “retro pocket console” bundle.
> 
> 🧠 _Example:_ A 25-year-old in Brazil pairs revived iPhone XS units with a $6 clip-on gamepad and open-source emulators, sells the combo as a “retro handheld” for ~$70 at flea markets and on Instagram. Buyers think it’s magic; he thinks it’s a Tuesday. Emulator scene lives at [r/EmulationOnAndroid](https://www.reddit.com/r/emulation/) energy but for iOS.
> 
> > 📈 **Timeline:** First sale within a weekend of your first build. Hot while retro nostalgia sells (years). Dips only if you stop restocking cheap donor phones.

> **📼 The Digital Archaeologist**
>
> Somebody’s phone dies with the ONLY photos of a lost relative on it. Apple says “sorry, can’t help, it won’t boot.” But bootrom access can sometimes reach the device _before_ the broken system loads — a shot at pulling data off gadgets everyone declared dead.
> 
> Offer respectful data-recovery for boot-looped A12/A13 devices — photos, notes, memories.
> 
> 🧠 _Example:_ A 27-year-old in India advertises “recover photos from dead iPhones” on local Facebook groups, focusing on A12/A13 models where deep-access tools give a real shot, charging per successful recovery (~$40–120). Emotional value = people pay happily. Groundwork: forensic-style access documented by outfits like the [RedEye writeup](https://threat-intelligence.redeyesecurity.com/blog/usbliter8-apple-a12-a13-securerom-exploit-2026.html).
> 
> > 📈 **Timeline:** First job within 2 weeks of building trust. Steady forever — dead phones with precious data never stop existing. Only limit is your honesty (over-promise = bad reviews).

> **🪟 The Kiosk Konverter**
>
> Small shops need cheap “single-purpose” screens — a menu board, an order kiosk, a smart-home wall display, a store signboard. A jailbroken old iPad locks into ONE app and never wanders. Way cheaper than a “real” commercial kiosk.
> 
> Grab old A12 iPads, jailbreak, lock them into kiosk mode, install/sell to local cafes and shops.
> 
> 🧠 _Example:_ A 26-year-old in Indonesia buys iPad 8/Air 3 units at ~$70, jailbreaks and locks each into a single menu-display app, then rents them to warungs and cafés as digital signboards for a small monthly fee. Recurring cash off gear the world called obsolete. Setup tips float around [r/homelab](https://www.reddit.com/r/homelab/).
> 
> > 📈 **Timeline:** First install in ~1 week. Recurring rental income scales as you sign more shops. Only threat: cheap Android tablets eventually undercutting you — so bank the early-mover lead.

> **🛠️ Follow-Up Actions (bookmark these)**
>
> | Wanna… | Go Here |
> | --- | --- |
> | Understand the exploit deeply | [9to5Mac report](https://9to5mac.com/2026/06/18/new-unpatchable-exploit-targets-apple-devices-with-a12-and-a13-chips/) |
> | See the OG version (checkm8) | [Wikipedia: checkm8](https://en.wikipedia.org/wiki/Checkm8) |
> | Grab the classic jailbreak lineage | [checkra1n](https://checkra.in/) |
> | Talk to a real device via USB | [libimobiledevice](https://libimobiledevice.org/) |
> | Track the lawsuit | [MacRumors legal update](https://www.macrumors.com/2026/07/24/unpatchable-iphone-11-exploit-sparks-legal-battle/) |

**⚡ Quick Hits**

| You Want | Do This |
| --- | --- |
| 🔍 Check if you’re affected | Match your model to the [hit-list](https://9to5mac.com/2026/06/18/new-unpatchable-exploit-targets-apple-devices-with-a12-and-a13-chips/) — A12/A13 = affected |
| 🔒 Stay safe day-to-day | Keep a passcode, don’t hand your unlocked phone to strangers — this needs _physical_ access |
| ♻ Flip dead phones | Learn [DFU restore](https://libimobiledevice.org/), buy “boot loop” lots cheap |
| 🎮 Build a retro handheld | Old iPhone + [emulators](https://en.wikipedia.org/wiki/Video_game_console_emulator) + a $6 clip |
| 🧠 Go deep on the tech | Read the [RedEye teardown](https://threat-intelligence.redeyesecurity.com/blog/usbliter8-apple-a12-a13-securerom-exploit-2026.html) |

_Apple spent a decade building a fortress. Turns out the front gate was welded open at the factory — and now the whole neighborhood has a key._
