Researcher says that Macs with T2 chips are vulnerable to a variant of the checkm8 exploit, which could jailbreak certain iPhones and was unpatchable
Jailbreak involves combining last year's checkm8 exploit with the Blackbird vulnerability disclosed this August.
Context & Ripple Effects
In September 2019, a researcher released code for checkm8, a permanent unpatchable bootrom exploit covering iPhones from the 4S to the X, while noting it required physical device access and lost persistence after reboot. The new report extends that work to the Mac: by pairing checkm8 with the Blackbird vulnerability disclosed this August, the researcher says T2-equipped Macs can be attacked through the same class of flaw.
The stakes are set by Apple's own shipping cadence — the related coverage notes Apple debuted six Mac models with T2 chips after checkm8 became public, and a week later researchers demonstrated a modified USB-C cable used to hack the T2 chip. The same unpatchable-silicon pattern resurfaces in 2024 with an M-series flaw that leaks secret keys during cryptographic operations.
First-order effects
- Owners of T2-equipped Macs face a vulnerability that, like the original checkm8, cannot be fixed in software — the exposure persists for the life of the hardware, though it requires physical access.
- The jailbreak community gains a documented path to T2 Macs by chaining last year's checkm8 release with Blackbird, extending a technique previously confined to A5–A11 iPhones.
Second-order effects
- Apple's only real mitigation is hardware: with bootrom code unpatchable, every T2 Mac already sold stays exposed, and the USB-C cable demo shows attackers turning the flaw into a physical tool rather than a lab technique.
- Security buyers and enterprises evaluating Macs must weigh silicon-level flaws that outlive OS updates, pressuring purchasing decisions toward newer chip generations.
Third-order effects
- If the pattern holds — T2 in 2020, M-series key extraction in 2024 — unpatchable hardware vulnerabilities become a structural feature of Apple's silicon, shifting security assurance from software patches to chip-generation refreshes.
- Physical-access exploits of this class push the industry toward treating supply chain and device custody as the primary defense boundary, since firmware fixes arrive only with new hardware.
The trend: Apple's custom silicon keeps producing unpatchable, hardware-level vulnerabilities — from the checkm8 bootrom to the T2 to M-series key extraction — making chip generation, not software updates, the real security boundary.