Checkm8

checkm8
CVE identifierCVE-2019-8900
Date discoveredSeptember 27, 2019; 6 years ago (2019-09-27)
Date patchedNone (Unpatchable in hardware)
Discovereraxi0mX
Affected hardwareApple A5 to A11 SoCs (iPhone 4s to iPhone X)
Affected softwareiOS, watchOS, tvOS
Used bycheckra1n, palera1n

checkm8 is an unpatchable Boot ROM exploit for iOS devices, first disclosed in 2019 by axi0mX, an independent iOS security researcher.[1] It affects all devices from iPhone 4s to iPhone X and requires the device to be in DFU mode to be exploited.[1] It has been integrated into iOS jailbreaking tools.

Technical details

checkm8 is a Boot ROM exploit that utilises a Use-After-Free (UAF) vulnerability in the Boot ROM. The exploit is used in DFU mode, which allows a signed image to be sent to the device (most commonly used for firmware recovery of the device).[1] The exploit manipulates memory allocation in DFU mode and triggers a dangling pointer, allowing arbitrary code execution at the highest privilege level before software security protections load.[1]

checkm8 is an "unpatchable" exploit that works permanently for compatible iOS devices.[2][3] Apple cannot fix the exploit via an iOS software update because the Boot ROM chip is read-only.[4]

History and release

On September 27, 2019, axi0mX announced "checkm8" on Twitter and released it as open-source on GitHub.[5] In the announcement, axi0mX said that it impacted devices with an A5 chip and up to an A11 chip, and noted the security risks for any devices using these chips.[6]

checkm8 received coverage in multiple tech news publications due to its unpatchable nature.[7][5] It won a Pwnie Award in 2020 for "Best Privilege Escalation Bug".[8]

Affected devices

checkm8 affects all Apple devices with an A5 to A11 chip. The affected hardware configurations include:

  • iPhone 4s to iPhone X
  • iPad 2 to iPad 7th Generation
  • iPad Mini 2 and 3
  • iPad Air 1st and 2nd generation
  • iPad Pro 10.5-inch and 12.9-inch 2nd generation
  • Apple Watch Series 1, Series 2, and Series 3
  • Apple TV 3rd generation and 4K
  • iPod Touch 5th generation to 7th generation[1]

Applications and use cases

Logo of checkra1n, the first major jailbreaking tool developed using the checkm8 exploit

checkm8 is mainly used for jailbreaking affected devices with tools like checkra1n and palera1n.[9] It allows full administrative access to the device. The exploit allowed developers to bypass Apple's code-signing restrictions.[9] The developers of checkra1n also applied checkm8, in combination with another exploit, to the T2 chip in Mac computers.[10][11]

The exploit is also used by forensic tools to perform low-level file system extractions on Apple devices to recover data, system logs and application databases.[12] It also helps examine new realms of data for Apple devices such as Location-Based data, examination of Internet Activities and allows the ability to trace digital footprints.[12]

A group called Checkm8.info, not affiliated with axi0mX, used checkra1n (based on checkm8) to help them remove Activation Lock from iPhones for customers, potentially iPhones that had been stolen.[13]

Limitations and mitigations

checkm8 has had its functions and exploit heavily restricted and limited for newer devices such as devices based on the A11 Bionic chip through iOS 16 updates.[14] iOS 16 includes SEP (Secure Enclave Processor), a patch that prevents access to user data if a screen lock passcode was ever used on the device since the last firmware restore.[14]

checkm8 itself was permanently mitigated in hardware starting with the A12 Bionic chip and later.[1] A similar exploit named usbliter8 that targets A12, A13 and S4/S5 chipsets was released in July 2026.[15]

See also

References

  1. ^ a b c d e f Bassen, Nikias (October 3, 2019). "Zimperium Analysis of checkm8". Zimperium. Retrieved 2026-08-22.
  2. ^ Kan, Michael (2019-09-27). "'Unpatchable' Flaw Can Jailbreak (and Hack) Older iPhones". PCMAG. Retrieved 2026-08-26.
  3. ^ Goodin, Dan (2019-11-15). "What the newly released Checkra1n jailbreak means for iDevice security". Ars Technica. Retrieved 2026-08-26.
  4. ^ Newman, Lily Hay (2019-09-27). "Unfixable Exploit Is the Latest Apple Security Upheaval". Wired. ISSN 1059-1028. Retrieved 2026-08-26.
  5. ^ a b Gallagher, Sean (2019-09-27). "Unpatchable bug in millions of iOS devices exploited, developer claims". Ars Technica. Retrieved 2026-08-26.
  6. ^ "checkm8 IOS Vulnerability". Lookout. September 30, 2019. Retrieved 2026-08-22.
  7. ^ Lee, Alex (2019-10-01). "The iOS Checkm8 jailbreak is hugely significant, but not for you". Wired. ISSN 1059-1028. Retrieved 2026-08-22.
  8. ^ "Pwnie Awards 2020 winners include Zerologon, CurveBall, Checkm8, BraveStarr attacks". ZDNET. December 10, 2020. Retrieved 2026-08-26.
  9. ^ a b Goodin, Dan (2019-09-28). "Developer of Checkm8 explains why iDevice jailbreak exploit is a game changer". Ars Technica. Retrieved 2026-08-22.
  10. ^ Newman, Lily Hay (2020-10-11). "A powerful iPhone jailbreak also cracks Apple's Mac security chip". Wired. ISSN 1059-1028. Retrieved 2026-08-26.
  11. ^ "Hackers claim they can now jailbreak Apple's T2 security chip". ZDNET. October 5, 2020. Retrieved 2026-08-26.
  12. ^ a b Kovalyk, Artem (2023-01-03). "iOS Forensics Advanced Logical File System Extraction and CHECKM8 for iPhones Part 1 of Cellebrite Solutions 2023 Update Summary". Cellebrite. Retrieved 2026-08-22.
  13. ^ Cox, Joseph; Franceschi-Bicchierai, Lorenzo (2022-05-31). "The Underground Company That Hacks iPhones for Ordinary Consumers". VICE. Retrieved 2026-08-25.
  14. ^ a b Katalov, Vladimir (2022-09-23). "iOS 16: SEP Hardening, New Security Measures and Their Forensic Implications". ElcomSoft blog. Retrieved 2026-08-22.
  15. ^ "A12 usbliter8 BootROM sigpatches". ElcomSoft blog. 2026-07-15. Retrieved 2026-08-26.

Content Disclaimer

Informasi ini disarikan dari Wikipedia dan disajikan kembali untuk tujuan edukasi. Konten tersedia di bawah lisensi CC BY-SA 3.0. Kami tidak bertanggung jawab atas ketidakakuratan data yang bersumber dari kontribusi publik tersebut.

  1. The information displayed on this website is sourced in part or in whole from Wikipedia and has been adapted for the purpose of restating it. We strive to provide accurate and relevant information, however:
  2. There is no guarantee of absolute accuracy. Wikipedia is an open, collaborative project that can be edited by anyone, so information is subject to change.
  3. It is not intended to constitute professional advice. The content displayed is for informational and educational purposes only. For important decisions (e.g., medical, legal, or financial), please consult a professional.
  4. Content copyright. Wikipedia is licensed under the Creative Commons Attribution-ShareAlike License (CC BY-SA). This means that content may be reused with appropriate attribution and shared under a similar license.
  5. Responsible use. Any risk arising from the use of information from this website is entirely the responsibility of the user.