checkm8
| CVE identifier | CVE-2019-8900 |
|---|---|
| Date discovered | September 27, 2019 |
| Date patched | None (Unpatchable in hardware) |
| Discoverer | axi0mX |
| Affected hardware | Apple A5 to A11 SoCs (iPhone 4s to iPhone X) |
| Affected software | iOS, watchOS, tvOS |
| Used by | checkra1n, palera1n |
checkm8 is an unpatchable Boot ROM exploit for iOS devices, first disclosed in 2019 by axi0mX, an independent iOS security researcher.[1] It affects all devices from iPhone 4s to iPhone X and requires the device to be in DFU mode to be exploited.[1] It has been integrated into iOS jailbreaking tools.
Technical details
[edit]checkm8 is a Boot ROM exploit that utilises a Use-After-Free (UAF) vulnerability in the Boot ROM. The exploit is used in DFU mode, which allows a signed image to be sent to the device (most commonly used for firmware recovery of the device).[1] The exploit manipulates memory allocation in DFU mode and triggers a dangling pointer, allowing arbitrary code execution at the highest privilege level before software security protections load.[1]
checkm8 is an "unpatchable" exploit that works permanently for compatible iOS devices.[2][3] Apple cannot fix the exploit via an iOS software update because the Boot ROM chip is read-only.[4]
History and release
[edit]On September 27, 2019, axi0mX announced "checkm8" on Twitter and released it as open-source on GitHub.[5] In the announcement, axi0mX said that it impacted devices with an A5 chip and up to an A11 chip, and noted the security risks for any devices using these chips.[6]
checkm8 received coverage in multiple tech news publications due to its unpatchable nature.[7][5] It won a Pwnie Award in 2020 for "Best Privilege Escalation Bug".[8]
Affected devices
[edit]checkm8 affects all Apple devices with an A5 to A11 chip. The affected hardware configurations include:
- iPhone 4s to iPhone X
- iPad 2 to iPad 7th Generation
- iPad Mini 2 and 3
- iPad Air 1st and 2nd generation
- iPad Pro 10.5-inch and 12.9-inch 2nd generation
- Apple Watch Series 1, Series 2, and Series 3
- Apple TV 3rd generation and 4K
- iPod Touch 5th generation to 7th generation[1]
Applications and use cases
[edit]
checkm8 is mainly used for jailbreaking affected devices with tools like checkra1n and palera1n.[9] It allows full administrative access to the device. The exploit allowed developers to bypass Apple's code-signing restrictions.[9] The developers of checkra1n also applied checkm8, in combination with another exploit, to the T2 chip in Mac computers.[10][11]
The exploit is also used by forensic tools to perform low-level file system extractions on Apple devices to recover data, system logs and application databases.[12] It also helps examine new realms of data for Apple devices such as Location-Based data, examination of Internet Activities and allows the ability to trace digital footprints.[12]
A group called Checkm8.info, not affiliated with axi0mX, used checkra1n (based on checkm8) to help them remove Activation Lock from iPhones for customers, potentially iPhones that had been stolen.[13]
Limitations and mitigations
[edit]checkm8 has had its functions and exploit heavily restricted and limited for newer devices such as devices based on the A11 Bionic chip through iOS 16 updates.[14] iOS 16 includes SEP (Secure Enclave Processor), a patch that prevents access to user data if a screen lock passcode was ever used on the device since the last firmware restore.[14]
checkm8 itself was permanently mitigated in hardware starting with the A12 Bionic chip and later.[1] A similar exploit named usbliter8 that targets A12, A13 and S4/S5 chipsets was released in July 2026.[15]
See also
[edit]References
[edit]- 1 2 3 4 5 6 Bassen, Nikias (October 3, 2019). "Zimperium Analysis of checkm8". Zimperium. Retrieved 2026-08-22.
- ↑ Kan, Michael (2019-09-27). "'Unpatchable' Flaw Can Jailbreak (and Hack) Older iPhones". PCMAG. Retrieved 2026-08-26.
- ↑ Goodin, Dan (2019-11-15). "What the newly released Checkra1n jailbreak means for iDevice security". Ars Technica. Retrieved 2026-08-26.
- ↑ Newman, Lily Hay (2019-09-27). "Unfixable Exploit Is the Latest Apple Security Upheaval". Wired. ISSN 1059-1028. Retrieved 2026-08-26.
- 1 2 Gallagher, Sean (2019-09-27). "Unpatchable bug in millions of iOS devices exploited, developer claims". Ars Technica. Retrieved 2026-08-26.
- ↑ "checkm8 IOS Vulnerability". Lookout. September 30, 2019. Retrieved 2026-08-22.
- ↑ Lee, Alex (2019-10-01). "The iOS Checkm8 jailbreak is hugely significant, but not for you". Wired. ISSN 1059-1028. Retrieved 2026-08-22.
- ↑ "Pwnie Awards 2020 winners include Zerologon, CurveBall, Checkm8, BraveStarr attacks". ZDNET. December 10, 2020. Retrieved 2026-08-26.
- 1 2 Goodin, Dan (2019-09-28). "Developer of Checkm8 explains why iDevice jailbreak exploit is a game changer". Ars Technica. Retrieved 2026-08-22.
- ↑ Newman, Lily Hay (2020-10-11). "A powerful iPhone jailbreak also cracks Apple's Mac security chip". Wired. ISSN 1059-1028. Retrieved 2026-08-26.
- ↑ "Hackers claim they can now jailbreak Apple's T2 security chip". ZDNET. October 5, 2020. Retrieved 2026-08-26.
- 1 2 Kovalyk, Artem (2023-01-03). "iOS Forensics Advanced Logical File System Extraction and CHECKM8 for iPhones Part 1 of Cellebrite Solutions 2023 Update Summary". Cellebrite. Retrieved 2026-08-22.
- ↑ Cox, Joseph; Franceschi-Bicchierai, Lorenzo (2022-05-31). "The Underground Company That Hacks iPhones for Ordinary Consumers". VICE. Retrieved 2026-08-25.
- 1 2 Katalov, Vladimir (2022-09-23). "iOS 16: SEP Hardening, New Security Measures and Their Forensic Implications". ElcomSoft blog. Retrieved 2026-08-22.
- ↑ "A12 usbliter8 BootROM sigpatches". ElcomSoft blog. 2026-07-15. Retrieved 2026-08-26.