ZeroHour
CyberScooppublished ()ingested @gregotto1

'Unpatchable' iOS exploit sends jailbreak enthusiasts into a frenzy

mediumAI safety & security exploited in the wildimportance 45
Full article653 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

'checkm8' takes advantage of a flaw that can't be patched by Apple.

iphone jailbreak
Photo by Paul Hudson/Flickr (CC BY 2.0)

A researcher released an “unpatchable” iOS exploit Friday that could make any iPhone from model 4S to 11 susceptible to a permanent jailbreak.

First pushed to Twitter by a researcher known as @axi0mX , the exploit works on devices with Apple chipsets from A5 to A11, which have powered iPhones and iPads since 2011. Apple’s newer chip models — A12 and A13 — are not affected.

EPIC JAILBREAK: Introducing checkm8 (read "checkmate"), a permanent unpatchable bootrom exploit for hundreds of millions of iOS devices.

Most generations of iPhones and iPads are vulnerable: from iPhone 4S (A5 chip) to iPhone 8 and iPhone X (A11 chip). https://t.co/dQJtXb78sG

[email protected] (@axi0mX) September 27, 2019

The exploit, known as “checkm8,” takes advantages of flaws in Apple’s secure boot ROM (bootrom) and allows users to remove restrictions imposed on the devices by Apple or various telecom carriers.

On a normal device, users are confined to using Apple’s App Stores and company-approved software. Jailbroken phones give users a little bit more control while sacrificing the safeguards the company programs into devices by default.

Once used on a device, checkm8 then allows for users to downgrade their devices to previous iOS versions, run a device with a second operating system (dual booting), or run a custom-made firmware.

“If you’re an iOS security researcher, this will likely be the most exciting thing you’ll hear all year—possibly even for your entire career to-date,” writes Thomas Reed, a MalwareBytes security researcher.

A public bootrom exploit is extremely rare, and cannot be fixed with a software patch. The last one publicly released, “limera1n,” was issued by noted device jailbreaker George “geohot” Hotz.

There are some caveats to the exploit: access to the device is needed, along with a certain level of technical skill. The researcher responsible for checkm8 told ZDNet that he was having trouble getting it to work on older devices.

Apple did not respond to a request for comment.

More Scoops

Darksword exploit kit
(Getty Images)

Second iOS exploit kit now in use by suspected Russian hackers

The kit, named DarkSword, has a variety of possible implications, the research from iVerify, Lookout and Google suggests.

The Apple logo appears on a mobile phone screen in this photo illustration in Brussels, Belgium, on Feb. 26, 2026. (Photo by Jonathan Raa/NurPhoto)

Possible U.S.-developed exploits linked to first known ‘mass’ iOS attack

The Apple Inc logo is displayed outside a retail store at the Third Street Promenade in Santa Monica, California on March 20, 2023. (Photo by PATRICK T. FALLON/AFP via Getty Images)

Apple discloses actively exploited zero-day affecting iOS, iPadOS and macOS

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/iphone-jailbreak-checkm8/