Sharing details about the jailbreak in a tweet, the researcher revealed that Checkm8 works by serious Bootrom vulnerability. The flaw affects most iPhones and iPads from iPhone 4S to iPhone X (A5 to A11 chips).
Explaining further about the jailbreak in his tweet, Axi0mX stated,
https://twitter.com/axi0mX/status/1177542512996544512
- axi0mX
This exploit and the subsequent jailbreak appear ‘permanently unpatchable’ as it affects the hardware. Thus, fixing the Bootrom flaw would not be so easy without a mass recall of vulnerable devices.
Elaborating on his findings, the researcher said that the flaw basically exists in the implementation of heap itself. As explained,
In S5L8920 bootrom (and some very old versions of iBoot) function malloc is not implemented correctly. When it is unable to allocate memory, instead of NULL it returns a pointer to memory address 0x8. Callers check if returned pointer is NULL and then treat that pointer as valid.More details about the exploit are available in his write-up.
Let us know your thoughts in the comments.8/ It will also be better for security researchers interested in Apple's Bug Bounty. They will not need to keep vulnerabilities on hand so that they have access they need for their research. More vulnerabilities might get reported to Apple right away.
— axi0mX (@axi0mX) September 27, 2019