A federal judge has ordered a public iPhone exploit taken offline after Magnet Forensics argued it wasn’t independent security research at all, but instead a stolen trade secret.
U.S. District Judge Victoria Marie Calvert partially approved Magnet’s request for a preliminary injunction. She directed Paradigm Shift and former Magnet exploit engineer Mario Del Gaudio to delete the usbliter8 article, code, technical details, and related materials in their possession by 11:59 p.m. Eastern on July 23.
By July 23, Paradigm Shift had replaced the original article with a page indicating the blog post was unavailable. The preliminary injunction will continue throughout the litigation unless the court removes it in a separate order.
Magnet’s July 7 complaint asserts that usbliter8 originated from a confidential A12 and A13 SecureROM access capability integrated into a commercial forensic product. The company alleges Del Gaudio acquired the technique while employed by Magnet and later shared it through Paradigm Shift.
Paradigm Shift originally presented usbliter8 as newly published security research before releasing it on June 18.
We reported at the time that the exploit affects devices including the iPhone XS, iPhone XR, iPhone 11 lineup, and second-generation iPhone SE. The court hasn’t made a final ruling on liability.
Calvert found that Magnet had established a likelihood of success on its trade-secret and contract claims for purposes of the preliminary injunction, based on evidence the defendants didn’t contest at the July 16 hearing.
The iPhone exploit requires physical access
Usbliter8 targets SecureROM, the immutable code that starts Apple’s secure boot process. It combines a flaw in a USB controller with security settings used on A12 and A13 devices to execute code while a device is in Device Firmware Update mode.
Because SecureROM is built into the processor during manufacturing, Apple can’t replace the vulnerable code through an ordinary software update. It may still be able to develop mitigations that interfere with exploitation or reduce its usefulness.
The flaw doesn’t create a remote attack or automatically expose everything stored on an iPhone. Using usbliter8 requires physical access to the device, a USB connection, DFU mode, and programmable hardware capable of sending specially constructed USB traffic.
The exploit can run unsigned code before the operating system starts, but it doesn’t directly compromise the Secure Enclave or automatically reveal a user’s passcode and encrypted data. Additional vulnerabilities or forensic techniques would be needed to cross those protections.
Those requirements make usbliter8 especially relevant to forensic investigations involving seized devices. Magnet sells investigation products to law enforcement agencies, intelligence services, government bodies, and private organizations.
Magnet says usbliter8 came from a secret capability
Del Gaudio worked as an exploit engineer placed with Magnet from November 2023 through November 2024. He signed an agreement covering confidential information, intellectual property, and continuing restrictions that survived the end of his placement.
Magnet says Del Gaudio had access to a zero-day capability internally called “MSG,” which targeted the same A12 and A13 SecureROM vulnerability later described in the usbliter8 publication.
According to the complaint, Magnet engineers discussed the vulnerability in meetings attended by Del Gaudio by April 2024. The company says it integrated MSG into one of its products in May 2024 and that Del Gaudio used the capability dozens of times while testing another tool.
Magnet says Del Gaudio had access to a zero-day capability internally called “MSG.”Magnet supplied additional details in a July 17 declaration addressing questions Calvert raised at the July 16 hearing. The company’s director of iOS research said Del Gaudio attended restricted sessions during a company gathering in Denver from March 11 through March 15, 2024.
Fewer than 20 people attended the smaller iOS sessions, according to the declaration. Magnet said the group discussed the SecureROM vulnerability, MSG’s technical architecture, and its development into an access capability for the company’s products.
Magnet links Del Gaudio to the publication
After his placement ended in November 2024, Del Gaudio became affiliated with Paradigm Shift, according to the complaint. The Spanish security company published “Introducing usbliter8: An A12/A13 SecureROM Exploit” on June 18.
A preserved screenshot connected Del Gaudio’s name and photograph to the @NotHdesk account associated with the research, according to Magnet. The company also says the account was linked to an email address known to belong to him.
Those details form part of Magnet’s case that Del Gaudio had access to MSG and was connected to the usbliter8 publication. The public record doesn’t include source-code comparisons, file-transfer records, or a detailed technical analysis showing exactly how MSG and usbliter8 match.
The original usbliter8 article was deliberately omitted from the complaint because Magnet argued that attaching it would further distribute the information it sought to protect. The company offered to provide the material privately for the court to review.
On June 18, Magnet sent Del Gaudio a cease-and-desist demand and contacted Paradigm Shift the next day. The demand sought removal of the article and code, identification of anyone who received the information, preservation of evidence, and return or destruction of Magnet material.
In letters dated June 22 and June 28, Paradigm Shift’s attorneys disputed Magnet’s claims and pressed the company to identify the information it considered a trade secret. Magnet filed the lawsuit on July 7 after the parties failed to reach an agreement.
Neither Del Gaudio nor Paradigm Shift appeared at the July 16 injunction hearing, despite receiving electronic notice. Calvert therefore considered an uncontested record when deciding whether temporary relief was warranted.
The court questioned whether the flaw should remain secret
Magnet argues that publication let competitors study the technique without making the same investment. The company also says Apple could reduce the exploit’s value through mitigations, while the disclosure may weaken customer trust in Magnet’s ability to protect sensitive capabilities.
The dispute raises a security question over whether companies should keep zero-days secret for forensic use or disclose them so manufacturers and device owners can respond.
Magnet argues that publication let competitors study the technique without making the same investment.Calvert described the public-interest issue as the most difficult part of the case. The judge addressed concerns about companies and government actors stockpiling zero-day vulnerabilities rather than reporting them to affected manufacturers.
The court also questioned whether consumers were better protected by knowing about the vulnerability once its existence had become public. Calvert concluded the court couldn’t resolve that policy debate through an unopposed preliminary injunction motion.
Paradigm Shift, as reported by MacRumors, said it informed Apple Product Security before publishing on June 18. The order doesn’t prevent Apple from using information it already has to mitigate the vulnerability.
Since Apple already has the disclosure, the injunction can’t fully restore the secrecy Magnet claims gave the capability commercial value. However, Calvert found that removing the material could still limit further harm and prevent Paradigm Shift from using the research for promotion.
The central trade-secret question remains unresolved
Magnet also sought extensive forensic access to the defendants’ computers, accounts, and storage. Calvert declined to grant that relief outside the normal discovery process.
The court observed that Magnet accepted Del Gaudio might not have required company hardware or files to replicate the capability. In Magnet’s view, familiarity with the research could have been enough.
A key question remains for future steps, such as whether Del Gaudio copied protected Magnet data or drew on technical understanding and experience kept after departing the firm.
The injunction covers material held by the defendants but can’t remove copies already downloaded or shared elsewhere. The case now turns on whether usbliter8 represents independent research or the disclosure of Magnet’s confidential forensic capability.

