A A.I CyberSecurity Scoring
A
Company Information
Website:https://www.appletreepartners.com
Employees number:33
Number of followers:5,412
NAICS:52391
Industry Type:Venture Capital and Private Equity Principals
Homepage:appletreepartners.com
A Risk Score (AI oriented)
Between 700 and 749
AVenture Capital and Private Equity Principals
Updated:
18/06/2026
18/06/2026
748/1000
Moderate
Ba
A Global Score (TPRM)
xxxx
AVenture Capital and Private Equity Principals
Score locked

AModerate
Current Score
748Ba (MODERATE)
01000
1 incidents
0 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
745
Vulnerability
18 Jun 2026 • A
Apple: New iPhone BootROM Vulnerability Exposes Apple SoCs to Full Chain-of-Trust Compromise
Critical BootROM Vulnerability 'usbliter8' Exposes Apple A12/A13 Devices to Unpatchable Exploits
748
CRITICAL-3
APP1781807037
Critical BootROM Vulnerability "usbliter8" Exposes Apple A12/A13 Devices to Unpatchable Exploits
Researchers at Paradigm Shift have uncovered a severe BootROM vulnerability, dubbed usbliter8, affecting Apple devices powered by A12, S4/S5, and A13 system-on-chips (SoCs). The flaw stems from a hardware-level bug in the Synopsys DWC2 USB controller, combined with a firmware misconfiguration, enabling attackers to achieve full application processor boot-chain compromise. Due to the immutable nature of BootROM code, no software patch can address the issue.
The vulnerability arises from a mismatch in how the DWC2 USB controller handles USB Setup packets. The controller stores up to three packets in memory before resetting the DMA base address (DOEPDMA register) to its starting position. However, while the controller increments the address by the size of written data after each operation, the reset always decrements it by a fixed 24 bytes. This discrepancy creates a buffer underflow, allowing controlled writes to unintended memory regions in 12-byte steps.
Exploitation varies by SoC generation. On A12 and S4/S5 devices, the DMA buffer’s proximity to the USB task’s stack enables direct corruption of a saved Link Register (LR), granting attackers program counter (PC) control during a scheduler context switch. A return-oriented programming (ROP) chain then redirects DMA writes into the boot trampoline, bypassing write protections and executing shellcode with full privileges.
The A13 SoC introduces additional hurdles, including Pointer Authentication (PAC), but researchers bypassed these protections through a multi-stage attack. By overwriting DART heap metadata, neutralizing checksum protections, and suppressing reboots via a panic counter overwrite, they achieved arbitrary code execution. The exploit leverages a firmware oversight only the IB key is enabled for PAC allowing attackers to load function pointers from controlled memory. Once EL1 execution is achieved, the exploit injects a custom USB request handler, patches the device’s serial number with a “PWND” identifier, and maintains stability by restoring corrupted heap allocations.
On A13 devices, the attack’s memory corruption necessitates a full SecureROM restart. Researchers achieve this by copying the ROM into SRAM, remapping it via custom MMU tables, and hooking ROM page table entry generation to preserve address space consistency. The custom handler enables two privileged operations: SoC demotion (temporarily lowering production mode) and unsigned iBoot booting, effectively bypassing Apple’s Secure Boot chain.
Affected Devices:
- Apple A12 (iPhone XS, XR, iPad Pro 2018)
- Apple S4/S5 (Apple Watch Series 4/5)
- Apple A13 (iPhone 11 series)
As the vulnerability resides in immutable silicon, the only mitigation is migrating to A14 or later hardware. While Apple’s Secure Enclave Processor (SEP) provides an additional security layer, usbliter8 expands potential attack vectors against it. Paradigm Shift coordinated disclosure with Apple Product Security, and the full proof-of-concept exploit is publicly available in their research repository.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
MAY 2026
745
APRIL 2026
745
MARCH 2026
745
FEBRUARY 2026
745
JANUARY 2026
745
DECEMBER 2025
745
NOVEMBER 2025
745
OCTOBER 2025
745
SEPTEMBER 2025
745
AUGUST 2025
745
JULY 2025
745
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for A ??
What was A's A.I Rankiteo Cyber Score in May 2026 ??
What was A's A.I Rankiteo Cyber Score in April 2026 ??
What was A's A.I Rankiteo Cyber Score in March 2026 ??
What was A's A.I Rankiteo Cyber Score in February 2026 ??
What was A's A.I Rankiteo Cyber Score in January 2026 ??
What was A's A.I Rankiteo Cyber Score in December 2025 ??
What was A's A.I Rankiteo Cyber Score in November 2025 ??
What was A's A.I Rankiteo Cyber Score in October 2025 ??
What was A's A.I Rankiteo Cyber Score in September 2025 ??
What was A's A.I Rankiteo Cyber Score in August 2025 ??
What was A's A.I Rankiteo Cyber Score in July 2025 ??
What is the average per-incident point impact on A's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with A ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view A's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?