Researcher claims he found “a permanent unpatchable bootrom exploit” for iOS devices with A5 to A11 chips, enabling jailbreaks for iPhone 4S to X, releases code
New jailbreak will work on iPhones 4S up to iPhone 8 and X. — A security researcher has released today …
ZDNet Catalin Cimpanu
Context & Ripple Effects
The release of checkm8 lands as a category of flaw Apple structurally cannot fix: because it lives in the bootrom burned into the silicon, no iOS update will close it, and every device with an A5 through A11 chip — iPhone 4S up to the X — carries it permanently. What came before in this arc were software-side jailbreaks that each new iOS release could kill; what changes here is that the unlock target moves below the operating system entirely.
The follow-on coverage sharpens the picture: the creator himself notes the exploit requires physical device access and does not persist after reboot (checkm8's own limitations), which caps its usefulness for attackers but makes jailbreaking more accessible and safer for hobbyists and researchers. Within a year the technique jumped product lines when researchers showed Macs with T2 chips are vulnerable to a checkm8 variant, confirming the weakness spans Apple silicon rather than one phone generation.
First-order effects
- Every iPhone from the 4S to the X becomes permanently jailbreakable at any current or future iOS version, since Apple's only real mitigation is shipping new chip generations rather than issuing patches.
Second-order effects
- The tooling lowers the barrier for the jailbreak and forensics communities — a line that continued with Unc0ver's jailbreak covering iOS 11 through 14.3 — while Apple faces pressure to harden the boot chain in future silicon, as the later T2 Mac finding shows the same class of flaw reaching beyond iPhones.
Third-order effects
- If hardware-baked exploits keep proving unpatchable, the industry's security model shifts from 'every flaw gets fixed' to 'assume some devices stay compromised forever,' pushing vendors toward silicon-level redesign cycles instead of relying on over-the-air updates.
The trend: Unpatchable bootrom flaws like checkm8 are making jailbreakability a permanent property of shipped Apple hardware, moving the arms race from software patches to chip design.
Related: Checkm8 requires physical access, lacks persistence · Macs with T2 chips vulnerable to checkm8 variant · Unc0ver jailbreak covers iOS 11–14.3 · A11 · iPhone 8
Related Coverage
- Axi0mX showcases verbose boot on iPhone X with iOS 13.1.1 via checkm8 iDownloadBlog.com
- Unpatchable bug in millions of iOS devices exploited, developer claims Ars Technica
- Checkm8 exploit promises permanent jailbreak for Apple A5-A11 devices VentureBeat
- New iOS exploit checkm8 allows permanent compromise of iPhones Malwarebytes Labs
- Exploit uncovered to allow permanent iPhone jailbreak Pocketnow
- Tethered jailbreaks are back — Earlier today, a new iPhone … Trail of Bits Blog
- This ‘Unpatchable’ Exploit Leads To Permanent Jailbreaking On iPhones Fossbytes
- iOS exploit discovered recently reportedly puts millions of iPhones at risk Firstpost Tech
- iPhone exploit could allow permanent jailbreak for millions of devices Engadget
- Checkm8 Exploit Opens Door to Unpatchable Jailbreak on iPhone 4S Through iPhone X MacRumors
- Most iPhones and iPads could be jailbroken via the new checkm8 exploit Liliputing
- New ‘unpatchable’ iPhone exploit could allow permanent jailbreaking on hundreds of millions of devices The Verge
- New Hack Unlocks ‘Hundreds of Millions’ of iPhones: What You Need to Know Tom's Guide
- Got a pre-A12 iPhone? Love jailbreaks? Happy Friday! ‘Unpatchable tethered Boot ROM exploit’ released The Register
- Researcher discovers unpatchable iPhone jailbreak exploit The Daily Dot
- Hacker publishes ‘unpatchable’ permanent jailbreak for iPhone 4s to iPhone X HackRead
- Hacker Releases ‘Unpatchable’ Jailbreak For All iOS Devices, iPhone 4s to iPhone X The Hacker News
- New iPhone bootROM exploit might lead to permanent jailbreak on hundreds of millions of devices TechSpot
- ‘Unpatchable’ iOS exploit sends jailbreak enthusiasts into a frenzy CyberScoop
- There's a new jailbreak for millions of iPhones, and Apple can't patch it CNET
- checkm8 promises to permanently jailbreak millions of iOS devices Cult of Mac
- iOS Exploit ‘Checkm8’ Could Allow Permanent iPhone Jailbreaks Threatpost
- New ‘unpatchable’ iOS exploit could lead to permanent jailbreak for iPhone 4s to iPhone X 9to5Mac
- Anonymous researcher publishes ‘unpatchable’ iOS exploit SiliconANGLE
- First major iPhone jailbreaking development in years ‘Checkm8’ could be big one Android Authority
- New iPhone exploit rocks the jailbreaking community Mashable
- Checkm8 iOS exploit could make for a new unpatchable iPhone jailbreak Digital Trends
- Major iOS Exploit Could Pave the Way to a New Age of Jailbreaking Gizmodo
- ‘Checkm8’ Exploit Jailbreaks Generations of iPhones Geek.com
- Unpatchable iOS Exploit Could Leave Seven Generations of iPhones Vulnerable WinBuzzer
- ‘Unpatchable’ iOS Bootrom Exploit Allows Jailbreaking of Many iPhones SecurityWeek
- New “Checkm8” Jailbreak to Remain Forever on iPhone 4S to X Says Researcher iPhone in Canada Blog
- New exploit could lead to permanent jailbreak on iPhone X and older iMore
- Developer Releases Unpatchable Jailbreak Exploit For Older iOS Devices Tom's Hardware
- Hacker Claims New ‘checkm8’ Exploit Can Lead to Permanent Jailbreak The Mac Observer
- New ‘checkm8’ iOS exploit could lead to permanent jailbreak for iPhone 4s to iPhone X MacDailyNews
- New checkm8 bootrom exploit potentially ensures lifetime jailbreakability for A5-A11 devices iDownloadBlog.com
- Unpatchable Bootrom Exploit Could Lead to Permanent iPhone Jailbreak iPhone Hacks
- New Checkm8 Jailbreak Released For All iOS Devices Running A5 To A11 Chips Slashdot
Discussion
-
@axi0mx
@axi0mx
on x
EPIC JAILBREAK: Introducing checkm8 (read “checkmate"), a permanent unpatchable bootrom exploit for hundreds of millions of iOS devices. Most generations of iPhones and iPads are vulnerable: from iPhone 4S (A5 chip) to iPhone 8 and iPhone X (A11 chip). https://github.com/...
-
@martijn_grooten
Martijn Grooten
on x
I'm with Eva here and to the various people pointing out you need physical access to jailbreak an iPhone: this is the stalkerware threat model. https://twitter.com/...
-
@joebeone
Joseph Lorenzo Hall, PhD
on x
“We strongly urge all journalists, activists, and politicians to upgrade to an iPhone that was released in the past two years with an A12 or higher CPU.” https://blog.trailofbits.com/ ...
-
@albertwenger
Albert Wenger
on x
If there is indeed an unpatchable jailbreak I may actually buy a used iPhone X https://twitter.com/...
-
@kennwhite
Kenn White
on x
Nice scoop — @dangoodin001 interviews @axi0mX and gets all the details on the new iOS bootrom exploit. https://arstechnica.com/...
-
@dangoodin001
Dan Goodin
on x
The jailbreaking exploit released Friday prompted lots of security concerns. But it turns out it's not remotely exploitable, doesn't have persistence, and can't bypass the Secure Enclave. That's not to say Checkm8 isn't impressive and important. Read on for why. https://twitter.c…
-
@dguido
Dan Guido
on x
Read our comprehensive explainer on the new iOS Boot ROM exploit. https://twitter.com/...
-
@evacide
Eva
on x
I support people's right to jailbreak their phones. But I'm also bracing myself for the coming upgrades to the capabilities of iOS spouseware and stalkerware. https://twitter.com/...
-
@morpheus______
@morpheus______
on x
Non techie version: Any iPhone 8/X or earlier can now be: - booted to any iOS version, past/present/future, with no SHSH/APTickets - booted to any OS (e.g. Android) - compromised by attacker w/physical access, but still requires password (or brute force)for private data
-
@strangepartscom
Strange Parts
on x
This is a HUGE deal. Both for the security of iOS devices, but also for the ability for non-apple employees to modify iPhones and conduct security research. It's also unfixable by Apple for all iPhones up to the iPhone X (any device with an A11 or earlier). https://twitter.com/..…
-
@thomasareed
Thomas Reed
on x
If you haven't heard yet, an exploit was dropped on Twitter this morning capable of modifying the bootrom on nearly all iOS devices except the most recent. Learn about the possible implications here: https://blog.malwarebytes.com/ ...
-
@queercommunist
@queercommunist
on x
“And since it's ROM (read-only memory), it can't be overwritten or patched by Apple through a software update, so it's here to stay. It's the first bootrom-level exploit publicly released for an iOS device since the iPhone 4, which was released almost a decade ago.” https://twitt…
-
@dsilverman
Dwight Silverman
on x
As well as iPads, iPods, Apple Watches and Apple TVs. BUT ... the hacker needs to have physical access to the device. It's not a remote vulnerability. https://twitter.com/...
-
@andreabarisani
Andrea Barisani
on x
What was I saying recently about unpatchable bootrom exploits? We find them constantly in automotive grade SoCs. Consumer products have even larger attack surface... Future hacks will more and more target the code embedded in the silicon. https://twitter.com/...
-
@dangoodin001
Dan Goodin
on x
Good writeup for anyone trying to understand the security consequences of the Checkm8 exploit. https://twitter.com/...
-
@ihackbanme
@ihackbanme
on x
and... the sandbox is now (mostly) free. #StillWIP #ToBeContinued #FreeTheSandbox https://twitter.com/...
-
@icj_
Callum Jones
on x
Congratulations. An incredible achievement. https://twitter.com/...
-
@_klutchkyle_
Kyle
on x
Huge thanks to @axi0mX. These exploits are worth a fortune and to see @axi0mX share it for free is unbelievable. https://twitter.com/...
-
@dinodaizovi
Dino A. Dai Zovi
on x
Holy ... I didn't think that we'd see another of these... https://twitter.com/...
-
@mcgrewsecurity
Wesley McGrew
on x
If you open your window, you can hear the parties at Cellebrite and XRY from your office https://twitter.com/...
-
@evanderburg
Eric Vanderburg
on x
Checkm8: unpatchable iOS exploit could lead to permanent jailbreak for iOS devices running A5 to A11 chips http://i.securitythinkingcap.com/ RF1gS2
-
@campuscodi
Catalin Cimpanu
on x
NEW: New Checkm8 jailbreak released for all iOS devices running A5 to A11 chips -works on iPhones 4S up to iPhone 8 and X -doesn't support A12 and A13 chipsets -code available on GitHub -uses “a permanent unpatchable Bootrom exploit” https://www.zdnet.com/... https://twitter.com/…