/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Researcher claims he found “a permanent unpatchable bootrom exploit” for iOS devices with A5 to A11 chips, enabling jailbreaks for iPhone 4S to X, releases code

New jailbreak will work on iPhones 4S up to iPhone 8 and X.  —  A security researcher has released today …

ZDNet Catalin Cimpanu

Context & Ripple Effects

The release of checkm8 code is a hardware-level event: because the flaw sits in Apple's bootrom, it cannot be fixed by any software update, so every device from the iPhone 4S to the iPhone X carrying A5–A11 chips stays exposed permanently. The exploit's own creator quickly bounded expectations, explaining that checkm8 requires physical device access and loses persistence after reboot, making it more of a research and jailbreaking tool than a remote-attack vector.

The story did not stay confined to old iPhones: within a year, researchers showed Macs with T2 security chips are vulnerable to a variant of the same checkm8 exploit, suggesting the affected silicon family is broader than the initial disclosure.

First-order effects

  • Owners of iPhones 4S through X gain a working, permanent jailbreak path that no iOS update can close, since the bootrom cannot be patched after manufacture.
  • Apple faces an unfixable vulnerability across its A5–A11 installed base and can only mitigate at the OS level, not eliminate it.

Second-order effects

  • The jailbreak ecosystem gets safer and more accessible tooling, as the creator noted, shifting custom-iOS development away from paid or closed exploits toward a free public one.
  • Secondary-market and refurbished-device buyers face new risk calculus: used A5–A11 iPhones can be tampered with via bootrom-level access, pressuring resellers to prove device integrity.

Third-order effects

  • If unpatchable silicon flaws keep surfacing — as the later Unc0ver jailbreak covering iOS 11 through 14.3 reinforced on the OS side — Apple's security model may shift further toward hardware attestation and rapid device replacement cycles rather than long software support for older chips.
  • Enterprises running legacy A5–A11 fleets face a structural choice between retiring hardware early or accepting devices whose lowest firmware layer is permanently compromised.

The trend: Security research is moving down the stack to unpatchable hardware layers like the bootrom, where vendor fixes are impossible and exposure lasts the lifetime of the chip.

Discussion

  • @axi0mx @axi0mx on x
    EPIC JAILBREAK: Introducing checkm8 (read “checkmate"), a permanent unpatchable bootrom exploit for hundreds of millions of iOS devices. Most generations of iPhones and iPads are vulnerable: from iPhone 4S (A5 chip) to iPhone 8 and iPhone X (A11 chip). https://github.com/...
  • @albertwenger Albert Wenger on x
    If there is indeed an unpatchable jailbreak I may actually buy a used iPhone X https://twitter.com/...
  • @dguido Dan Guido on x
    Read our comprehensive explainer on the new iOS Boot ROM exploit. https://twitter.com/...
  • @kennwhite Kenn White on x
    Nice scoop — @dangoodin001 interviews @axi0mX and gets all the details on the new iOS bootrom exploit. https://arstechnica.com/...
  • @evacide Eva on x
    I support people's right to jailbreak their phones. But I'm also bracing myself for the coming upgrades to the capabilities of iOS spouseware and stalkerware. https://twitter.com/...
  • @morpheus______ @morpheus______ on x
    Non techie version: Any iPhone 8/X or earlier can now be: - booted to any iOS version, past/present/future, with no SHSH/APTickets - booted to any OS (e.g. Android) - compromised by attacker w/physical access, but still requires password (or brute force)for private data
  • @strangepartscom Strange Parts on x
    This is a HUGE deal. Both for the security of iOS devices, but also for the ability for non-apple employees to modify iPhones and conduct security research. It's also unfixable by Apple for all iPhones up to the iPhone X (any device with an A11 or earlier). https://twitter.com/..…
  • @thomasareed Thomas Reed on x
    If you haven't heard yet, an exploit was dropped on Twitter this morning capable of modifying the bootrom on nearly all iOS devices except the most recent. Learn about the possible implications here: https://blog.malwarebytes.com/ ...
  • @queercommunist @queercommunist on x
    “And since it's ROM (read-only memory), it can't be overwritten or patched by Apple through a software update, so it's here to stay. It's the first bootrom-level exploit publicly released for an iOS device since the iPhone 4, which was released almost a decade ago.” https://twitt…
  • @dsilverman Dwight Silverman on x
    As well as iPads, iPods, Apple Watches and Apple TVs. BUT ... the hacker needs to have physical access to the device. It's not a remote vulnerability. https://twitter.com/...
  • @andreabarisani Andrea Barisani on x
    What was I saying recently about unpatchable bootrom exploits? We find them constantly in automotive grade SoCs. Consumer products have even larger attack surface... Future hacks will more and more target the code embedded in the silicon. https://twitter.com/...
  • @dangoodin001 Dan Goodin on x
    Good writeup for anyone trying to understand the security consequences of the Checkm8 exploit. https://twitter.com/...
  • @icj_ Callum Jones on x
    Congratulations. An incredible achievement. https://twitter.com/...
  • @ihackbanme @ihackbanme on x
    and... the sandbox is now (mostly) free. #StillWIP #ToBeContinued #FreeTheSandbox https://twitter.com/...
  • @dinodaizovi Dino A. Dai Zovi on x
    Holy ... I didn't think that we'd see another of these... https://twitter.com/...
  • @_klutchkyle_ Kyle on x
    Huge thanks to @axi0mX. These exploits are worth a fortune and to see @axi0mX share it for free is unbelievable. https://twitter.com/...
  • @mcgrewsecurity Wesley McGrew on x
    If you open your window, you can hear the parties at Cellebrite and XRY from your office https://twitter.com/...
  • @evanderburg Eric Vanderburg on x
    Checkm8: unpatchable iOS exploit could lead to permanent jailbreak for iOS devices running A5 to A11 chips http://i.securitythinkingcap.com/ RF1gS2
  • @campuscodi Catalin Cimpanu on x
    NEW: New Checkm8 jailbreak released for all iOS devices running A5 to A11 chips -works on iPhones 4S up to iPhone 8 and X -doesn't support A12 and A13 chipsets -code available on GitHub -uses “a permanent unpatchable Bootrom exploit” https://www.zdnet.com/... https://twitter.com/…