Back to news

Unpatchable iPhone Chip Flaw and Android Botnet Expose Hardware Trust Gaps

Two separate disclosures this week reveal that device-level security assumptions — from Apple silicon to budget TV boxes — are under serious, sustained attack.

Unpatchable iPhone Chip Flaw and Android Botnet Expose Hardware Trust Gaps

What happened

Researchers at Paradigm Shift released a functional exploit called usbliter8 that achieves arbitrary code execution within the SecureROM of Apple's A12 and A13 processors — firmware etched permanently into the chip at the point of manufacture, and therefore beyond the reach of any software patch. Separately, investigators from several cybersecurity firms traced the four-year-old Popa botnet — which has quietly conscripted millions of Android-based consumer TV boxes into a proxy network used for ad fraud, credential theft, and large-scale data scraping — to NetNut, a residential proxy service operated by a publicly traded Israeli company. Both disclosures arrive within the same news cycle, underscoring a widening pattern of exploitation at the hardware and firmware layer.

Why it matters for your business

The usbliter8 vulnerability cannot be closed by Apple or any enterprise MDM platform; every affected device will remain permanently exposed for its operational lifetime, making physical access controls and device retirement policies newly urgent for security teams managing fleets of older iPhones or iPads. The Popa botnet case raises a different but equally pressing concern: corporate networks that permit unmanaged consumer devices — including employee-owned streaming boxes or home-office hardware — to touch internal resources are effectively granting unknown third parties a foothold. The NetNut connection also complicates due-diligence processes for businesses that license residential proxy infrastructure for market research or ad verification, since the legal and reputational exposure of traffic routing through compromised consumer devices is significant. Procurement and vendor-risk teams should audit any residential proxy relationships immediately.

What to watch next

Apple has not publicly confirmed whether A14 or later chips share any architectural characteristics with the affected SecureROM code, and that question will shape how broadly enterprises need to revise their device-trust posture. On the botnet front, regulators in Israel and the European Union are expected to examine whether NetNut's corporate structure provided adequate disclosure to investors about the origin of its proxy traffic. Law enforcement action against the Popa infrastructure itself, and any resulting civil litigation, could set meaningful precedent for how residential proxy networks are legally classified going forward.

Sources

Want this kind of clarity applied to your own systems?

HashWhales can review your website, infrastructure, security posture, and growth bottlenecks, then send a prioritized action plan.

Free AuditChat on WhatsApp