Unpatchable iPhone 11 Exploit Leads to Legal Dispute

In June 2026, cybersecurity firm Paradigm Shift disclosed a significant boot ROM vulnerability affecting Apple’s A12 and A13 chips, which power devices like the iPhone XS and iPhone 11 series. This type of vulnerability is particularly concerning because it resides in the chip’s read-only memory, making it impervious to software updates and leaving affected devices permanently exposed.

Shortly after the disclosure, Paradigm Shift removed the detailed blog post following a lawsuit filed by digital forensics company Magnet Forensics. The lawsuit, submitted in a Georgia federal court, alleges that the vulnerability revealed by Paradigm Shift closely mirrors work conducted by Mario Del Gaudio, a former Magnet Forensics employee who later joined Paradigm Shift. Magnet Forensics contends that Del Gaudio’s involvement led to the unauthorized exposure of its trade secrets.

Boot ROM vulnerabilities are particularly critical because they can provide attackers with deep access to a device’s core functions, potentially allowing for persistent exploits that are difficult to detect and mitigate. The inability to patch such vulnerabilities through standard software updates underscores the importance of robust hardware security measures during the design phase.

This legal confrontation highlights the complex interplay between cybersecurity research and intellectual property rights. While the discovery and disclosure of vulnerabilities are essential for improving security, they can also lead to contentious disputes over proprietary information and the origins of such findings. The outcome of this case may set important precedents for how vulnerabilities are reported and how companies protect their intellectual assets in the rapidly evolving tech landscape.