Happy October from Loose Leaf Security! Or, at least, our calendars say it's October even if the weather here in New York still says it's summer. Regardless, it's always security season.
If someone forwarded this to you, you can sign up yourself at https://looseleafsecurity.com/newsletter.
In the news
An unfixable jailbreak: The big news in iPhone security is a "boot ROM" exploit against all devices with the A5 through A11 chipsets - which is every iPhone and iPad on the market up to the iPhone X series. (The A12 chipset, used in the iPhone XS and 11 series onwards, does not have the bug.) The boot ROM is the very first code executed by the iPhone when it turns on and cannot be updated except by buying newer hardware. It's responsible for verifying the authenticity of the firmware and OS (which can be updated) and also supporting emergency updates to the firmware and OS, if they get corrupted.
The bug is in the update code: specifically, to fix an otherwise-unbootable iOS device, you can connect it via USB to iTunes and upload clean firmware to the iPhone. You need to place the phone in Device Firmware Upgrade mode, which …