New Apple Security Flaw Can Never Be Patched: Some bugs get fixed with a routine software update. This one can’t be — not ever. Security researchers have uncovered a hardware-level vulnerability baked into the silicon of several older iPhones, iPads, and Apple Watch models, and because the flaw lives in code burned into the chip during manufacturing, no iOS update can touch it.
Table of Contents
What’s Actually Affected
| Device Category | Models |
|---|---|
| iPhones | XR, XS, XS Max, 11, 11 Pro, 11 Pro Max, SE (2nd gen) |
| iPads | Air (3rd gen), mini (5th gen), iPad (8th & 9th gen) |
| Apple Watch | Series 4, Series 5, SE (1st gen) |
| Other | Apple TV 4K (2nd gen), Studio Display |
The common thread across all of these is the chip generation: A12, A13, S4, and S5 silicon. Notably, older A11 devices like the iPhone 8 and iPhone X aren’t affected, and anything running an A14 chip or newer is safe — Apple appears to have closed this particular door starting with that generation.

What’s Actually Going On Under the Hood
Security firm Paradigm Shift published a detailed report on an exploit they’re calling usbliter8, which targets SecureROM — the unchangeable boot code that runs the instant a device powers on, before iOS even loads. Because that code is permanently etched into the processor during manufacturing, there’s no software patch that can rewrite it. It’s the digital equivalent of a flaw cast into a building’s foundation rather than something fixable by repainting a wall.
The reassuring part: the Secure Enclave, which guards your passcode and encryption keys, isn’t affected by this exploit. So the data that actually matters most — your stored credentials and biometric data — stays protected.
| Should You Worry? | Reality Check |
|---|---|
| Random theft on the street | Very unlikely — needs technical skill + direct device access |
| Remote hacking over the internet | Not possible with this exploit |
| Passcode/encryption compromise | Secure Enclave is untouched |
| Real risk for average users | Low, if you use a strong passcode |
| Real risk for high-value targets | Worth taking seriously |
Who Should Actually Be Concerned
For most everyday users with a strong passcode who don’t hand their phone to strangers, the practical risk here stays low — this isn’t something that can be triggered remotely or silently over Wi-Fi. But if you’re running one of these older devices for work, storing sensitive client data, or operating in a higher-risk environment, it’s a legitimate reason to think about upgrading.
Paradigm Shift worked with Apple ahead of publishing the report, and Apple’s own guidance lines up with that: if security is a serious concern, a newer device is the only real fix. If you’re shopping around for that upgrade, our budget iPhone SE vs iPhone 13 comparison is a useful starting point for understanding what you’d be stepping up from.
The Bottom Line
This isn’t a “drop everything and panic” situation — it requires physical access and real technical skill to exploit, and your most sensitive data stays protected either way. But it is a genuine reminder that hardware vulnerabilities, unlike software bugs, don’t go away with an update. If you’re still running an iPhone 11 or earlier and security is a real priority for you, this is one more data point nudging you toward newer hardware.
Sources: Gizmochina, citing Paradigm Shift’s published research.





