None
EN
When USB Reaches The Root Of Trust
['Doug Carson', 'Technical Paper Link', 'Tom Katsioulas', 'Alex', 'Matt Bailey', 'Alexis R. Ware', 'Yağız Boz', 'Murugavel Ganesan', 'F. Chen', 'B.S. Deepaksubramanyan']
Semiconductor Engineering
How the USB controller became an entry pointThe exploit targets the USB Device Firmware Upgrade mode used before the operating system is loaded.
Its starting point is a flaw in the Synopsys DesignWare USB controller integrated into the affected Apple processors.
USB controllers, cryptographic accelerators, processor cores, memory interfaces, and communications blocks may all be supplied externally and integrated into a larger design.
A USB controller is not itself the root of trust, but it processes externally controlled data while the root of trust is active.
The recovery interface served an important resilience function, but its interaction with the USB controller and memory protections created an exploitable path into SecureROM.