Researchers have booted a jailbroken build of iOS 27.0 beta 2 on an iPhone 11 Pro by combining the usbliter8 SecureROM exploit with a heavily modified custom firmware workflow. The demonstration targets A12 and A13 devices through DFU mode, requires physical access and specialized USB hardware, and shows that flaws in Apple’s immutable bootrom can still be used to undermine the boot chain on older hardware even after major iOS upgrades. Because the attack abuses SecureROM code, it cannot be fully fixed through a standard iOS software update.
The project reportedly introduced build-specific patches for build 24A5370h and altered kernel, userland, and system services to bypass protections including USB Restricted Mode, sandbox controls, and AMFI trust-cache checks. The modified device was able to load altered boot components and support capabilities such as SSH access, a bootstrap environment, and Sileo, but the jailbreak remains highly experimental and can disrupt SEP-dependent features, passcode support, Wi‑Fi, baseband, Bluetooth, and Apple services. No CVE, CVSS score, Apple advisory, or public evidence of in-the-wild exploitation was reported in the cited coverage.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
Researchers demonstrated a jailbroken build of iOS 27.0 beta 2 running on an A13-based iPhone 11 Pro using the usbliter8 SecureROM exploit and a heavily modified custom firmware workflow. The proof of concept required physical access, DFU mode, and specialized USB hardware, and showed that immutable bootrom flaws can still bypass parts of Apple's boot chain on older hardware.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecryptika.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.