There’s a nasty word floating around Apple’s silicon lately, and it’s not one Cupertino wants to hear: unpatchable. The exploit in question is called usbliter8, and it reportedly digs into several Apple SoCs at a level that no software update can quietly seal off. Now it’s at the center of a lawsuit that reads like a corporate thriller.
Magnet Forensics has filed suit against Paradigm Shift Technology over the publication of usbliter8. The claim isn’t simply that the exploit exists — it’s how it allegedly came to be. According to Magnet, the vulnerability was developed using trade secrets misappropriated by a former engineer. In plain English: the company says someone walked out the door with proprietary knowledge, and that knowledge ended up baked into a working exploit that’s now out in the wild.
Why does this matter beyond the two companies trading legal blows? Because “unpatchable” is a very specific and very uncomfortable category of flaw. When a weakness lives deep enough in the hardware — in the SoC itself rather than in the operating system layered on top — vendors can’t just push an over-the-air fix and move on. Mitigations become awkward, partial, or dependent on future silicon revisions. That’s exactly the kind of exploit that gets forensic firms, security researchers and, yes, lawyers very interested.
The players themselves are telling. Magnet Forensics operates in the digital forensics and investigation space, the corner of the industry where extracting data from locked or secured devices is the whole business model. An exploit that touches Apple’s chips is enormously valuable in that world — which is precisely why questions of who owns it, who built it, and who was allowed to publish it are worth going to court over.
- The exploit: usbliter8, described as unpatchable and affecting several Apple SoCs.
- The plaintiff: Magnet Forensics, alleging trade-secret misappropriation.
- The defendant: Paradigm Shift Technology, over its publication of the exploit.
- The core allegation: a former engineer allegedly took proprietary knowledge that fed the exploit’s development.
What the suit doesn’t do is settle the technical questions the rest of us actually care about — how deep usbliter8 really reaches, which chips are on the hook, and what, if anything, users can do about it. Those details will likely surface as the case proceeds, assuming the parties don’t reach for a settlement first.
For now, it’s a reminder that hardware-level security is only as strong as the people who know its secrets. A patch can close a software hole overnight. A leaked idea, once it’s out, is a very different kind of problem — and one that increasingly ends up in front of a judge rather than a release-notes changelog.