/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Researcher claims he found “a permanent unpatchable bootrom exploit” for iOS devices with A5 to A11 chips, enabling jailbreaks for iPhone 4S to X, releases code

New jailbreak will work on iPhones 4S up to iPhone 8 and X.  —  A security researcher has released today …

ZDNet Catalin Cimpanu

Context & Ripple Effects

The release of checkm8 lands as a category of flaw Apple structurally cannot fix: because it lives in the bootrom burned into the silicon, no iOS update will close it, and every device with an A5 through A11 chip — iPhone 4S up to the X — carries it permanently. What came before in this arc were software-side jailbreaks that each new iOS release could kill; what changes here is that the unlock target moves below the operating system entirely.

The follow-on coverage sharpens the picture: the creator himself notes the exploit requires physical device access and does not persist after reboot (checkm8's own limitations), which caps its usefulness for attackers but makes jailbreaking more accessible and safer for hobbyists and researchers. Within a year the technique jumped product lines when researchers showed Macs with T2 chips are vulnerable to a checkm8 variant, confirming the weakness spans Apple silicon rather than one phone generation.

First-order effects

  • Every iPhone from the 4S to the X becomes permanently jailbreakable at any current or future iOS version, since Apple's only real mitigation is shipping new chip generations rather than issuing patches.

Second-order effects

  • The tooling lowers the barrier for the jailbreak and forensics communities — a line that continued with Unc0ver's jailbreak covering iOS 11 through 14.3 — while Apple faces pressure to harden the boot chain in future silicon, as the later T2 Mac finding shows the same class of flaw reaching beyond iPhones.

Third-order effects

  • If hardware-baked exploits keep proving unpatchable, the industry's security model shifts from 'every flaw gets fixed' to 'assume some devices stay compromised forever,' pushing vendors toward silicon-level redesign cycles instead of relying on over-the-air updates.

The trend: Unpatchable bootrom flaws like checkm8 are making jailbreakability a permanent property of shipped Apple hardware, moving the arms race from software patches to chip design.

Discussion

  • @axi0mx @axi0mx on x
    EPIC JAILBREAK: Introducing checkm8 (read “checkmate"), a permanent unpatchable bootrom exploit for hundreds of millions of iOS devices. Most generations of iPhones and iPads are vulnerable: from iPhone 4S (A5 chip) to iPhone 8 and iPhone X (A11 chip). https://github.com/...
  • @martijn_grooten Martijn Grooten on x
    I'm with Eva here and to the various people pointing out you need physical access to jailbreak an iPhone: this is the stalkerware threat model. https://twitter.com/...
  • @joebeone Joseph Lorenzo Hall, PhD on x
    “We strongly urge all journalists, activists, and politicians to upgrade to an iPhone that was released in the past two years with an A12 or higher CPU.” https://blog.trailofbits.com/ ...
  • @albertwenger Albert Wenger on x
    If there is indeed an unpatchable jailbreak I may actually buy a used iPhone X https://twitter.com/...
  • @kennwhite Kenn White on x
    Nice scoop — @dangoodin001 interviews @axi0mX and gets all the details on the new iOS bootrom exploit. https://arstechnica.com/...
  • @dangoodin001 Dan Goodin on x
    The jailbreaking exploit released Friday prompted lots of security concerns. But it turns out it's not remotely exploitable, doesn't have persistence, and can't bypass the Secure Enclave. That's not to say Checkm8 isn't impressive and important. Read on for why. https://twitter.c…
  • @dguido Dan Guido on x
    Read our comprehensive explainer on the new iOS Boot ROM exploit. https://twitter.com/...
  • @evacide Eva on x
    I support people's right to jailbreak their phones. But I'm also bracing myself for the coming upgrades to the capabilities of iOS spouseware and stalkerware. https://twitter.com/...
  • @morpheus______ @morpheus______ on x
    Non techie version: Any iPhone 8/X or earlier can now be: - booted to any iOS version, past/present/future, with no SHSH/APTickets - booted to any OS (e.g. Android) - compromised by attacker w/physical access, but still requires password (or brute force)for private data
  • @strangepartscom Strange Parts on x
    This is a HUGE deal. Both for the security of iOS devices, but also for the ability for non-apple employees to modify iPhones and conduct security research. It's also unfixable by Apple for all iPhones up to the iPhone X (any device with an A11 or earlier). https://twitter.com/..…
  • @thomasareed Thomas Reed on x
    If you haven't heard yet, an exploit was dropped on Twitter this morning capable of modifying the bootrom on nearly all iOS devices except the most recent. Learn about the possible implications here: https://blog.malwarebytes.com/ ...
  • @queercommunist @queercommunist on x
    “And since it's ROM (read-only memory), it can't be overwritten or patched by Apple through a software update, so it's here to stay. It's the first bootrom-level exploit publicly released for an iOS device since the iPhone 4, which was released almost a decade ago.” https://twitt…
  • @dsilverman Dwight Silverman on x
    As well as iPads, iPods, Apple Watches and Apple TVs. BUT ... the hacker needs to have physical access to the device. It's not a remote vulnerability. https://twitter.com/...
  • @andreabarisani Andrea Barisani on x
    What was I saying recently about unpatchable bootrom exploits? We find them constantly in automotive grade SoCs. Consumer products have even larger attack surface... Future hacks will more and more target the code embedded in the silicon. https://twitter.com/...
  • @dangoodin001 Dan Goodin on x
    Good writeup for anyone trying to understand the security consequences of the Checkm8 exploit. https://twitter.com/...
  • @ihackbanme @ihackbanme on x
    and... the sandbox is now (mostly) free. #StillWIP #ToBeContinued #FreeTheSandbox https://twitter.com/...
  • @icj_ Callum Jones on x
    Congratulations. An incredible achievement. https://twitter.com/...
  • @_klutchkyle_ Kyle on x
    Huge thanks to @axi0mX. These exploits are worth a fortune and to see @axi0mX share it for free is unbelievable. https://twitter.com/...
  • @dinodaizovi Dino A. Dai Zovi on x
    Holy ... I didn't think that we'd see another of these... https://twitter.com/...
  • @mcgrewsecurity Wesley McGrew on x
    If you open your window, you can hear the parties at Cellebrite and XRY from your office https://twitter.com/...
  • @evanderburg Eric Vanderburg on x
    Checkm8: unpatchable iOS exploit could lead to permanent jailbreak for iOS devices running A5 to A11 chips http://i.securitythinkingcap.com/ RF1gS2
  • @campuscodi Catalin Cimpanu on x
    NEW: New Checkm8 jailbreak released for all iOS devices running A5 to A11 chips -works on iPhones 4S up to iPhone 8 and X -doesn't support A12 and A13 chipsets -code available on GitHub -uses “a permanent unpatchable Bootrom exploit” https://www.zdnet.com/... https://twitter.com/…