Magnet Forensics sued former contractor Mario Del Gaudio and competitor Paradigm Shift Technology S.L. in federal court in Georgia, alleging they misappropriated trade secrets tied to an iOS zero-day affecting Apple A12 and A13 chips. According to the complaint, Del Gaudio worked on the vulnerability while under contract with Magnet and later researched the same flaw for Paradigm Shift after leaving. Paradigm Shift subsequently published research on the issue, then removed the post after the lawsuit was filed.
The disputed vulnerability is described as a boot ROM flaw affecting devices including the iPhone XS and iPhone 11 families, making it effectively unpatchable through normal iOS software updates. Magnet argues the public disclosure destroyed part of the exploit's commercial value for government surveillance and forensic customers and caused ongoing damage, turning the case into a high-profile dispute over ownership and disclosure of offensive mobile exploitation research.

Get the actors, campaigns, and ATT&CK mapping behind it.
3 events from the most recent confirmed update back to the earliest known activity.
After Magnet Forensics sued, Paradigm Shift removed its blog post describing the A12/A13 boot ROM vulnerability. The removal is reported as a response following the legal action, but no specific date is given.
In June 2026, Paradigm Shift Technology S.L. allegedly published research about an iOS zero-day affecting Apple A12 and A13 chips, making the vulnerability public. Magnet Forensics claims this disclosure reduced the exploit's commercial value and could enable Apple to patch it.
On 2026-07-07, Magnet Forensics filed a lawsuit in the U.S. District Court for the Northern District of Georgia against former contractor Mario Del Gaudio and Paradigm Shift Technology S.L. The complaint alleges misappropriation of trade secrets related to an iOS zero-day affecting Apple A12 and A13 chips.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.