27 September

What happened on this date in privacy, anonymity networks and censorship. Every year on the same date we add a new look back and keep the earlier ones as they were.

2026

An iPhone startup flaw that updates cannot fix

If you still use an iPhone X or an older model, your phone has a flaw that no software update can fix, and if the phone ends up in someone else's hands, whether your data can be read depends on your passcode. On 27 September 2019, a researcher released an exploit called checkm8 that targets the first code an iPhone runs when it starts up, code stored in read-only memory on the chip, which Apple cannot patch. Ars Technica's interview with the developer reported that it works on 11 generations of iPhones, from the 4S to the X, and needs physical access to the phone. In the same interview, the developer said that iPhones from the 6 to the 8 have a separate Secure Enclave, so anyone without the passcode still cannot read the data. As of May 2026 Apple was still releasing security updates for the iPhone 8 and iPhone X, most recently iOS 16.7.16, but the startup flaw remains. If you still use one of these iPhones, make sure it has a passcode set and the latest system update installed.

Sources