
Mobile devices have become essential business tools. Employees use them to access email, review documents, join meetings, communicate with clients, and work from virtually anywhere.
But as businesses become more mobile, smartphones and tablets have also become valuable targets for cybercriminals.
Recently, security researchers disclosed a hardware vulnerability affecting several older Apple devices. Because the flaw exists in the device's hardware—not its software—it cannot be fixed with a normal security update.
If your business still uses older iPhones or iPads, here's what you should know.
The Growing Importance of Mobile Security
For many businesses, smartphones now provide access to:
- Microsoft 365 email
- Company files
- Password managers
- Multi-factor authentication (MFA)
- Financial applications
- Customer information
- Internal communication platforms
If one of these devices is compromised, attackers may gain access to far more than just the phone itself.
That's why mobile device security should be part of every organization's cybersecurity strategy.
What Is the usbliter8 Vulnerability?
Researchers at the European cybersecurity firm Paradigm Shift recently disclosed a hardware-level exploit known as usbliter8.
Unlike most security vulnerabilities, this issue is built into the hardware of certain Apple chips. Because it exists in the silicon itself, Apple cannot eliminate the vulnerability through a software or iOS update.
The exploit requires physical access to the device. An attacker must connect the device to another system using a USB connection to attempt the attack.
While this isn't the type of vulnerability that can be exploited remotely over the internet, organizations should still take it seriously—particularly for devices used by executives or employees with access to sensitive business information.
Which Apple Devices Are Affected?
The vulnerability impacts devices that use certain Apple chips, including several older iPhone, iPad, and Apple Watch models.
Examples include:
- iPhone 11 series
- iPhone XR, XS, and XS Max
- iPhone SE (2nd generation)
- iPad (8th and 9th generation)
- iPad mini (5th generation)
- iPad Air (3rd generation)
- 11-inch iPad Pro (1st and 2nd generation)
- 12.9-inch iPad Pro (3rd and 4th generation)
- Apple Watch SE (1st generation)
- Apple Watch Series 4 and Series 5
If your organization still relies on these devices, now is a good time to review your mobile device inventory.
How Businesses Can Reduce the Risk
Although this vulnerability cannot be patched, businesses can significantly reduce their risk by following security best practices.
Review Older Devices
Start by identifying employees who still use affected devices.
Pay particular attention to users who have access to:
- Financial information
- Administrative accounts
- Executive communications
- Confidential client data
In many cases, replacing aging hardware is the safest long-term solution.
Control Physical Access
Because this vulnerability requires physical access, protecting company devices becomes even more important.
Encourage employees to:
- Keep devices with them while traveling
- Avoid leaving phones unattended in public places
- Use only trusted repair providers
- Report lost or stolen devices immediately
Simple physical security practices can dramatically reduce the likelihood of exploitation.
Use Mobile Device Management (MDM)
A Mobile Device Management (MDM) platform allows organizations to manage company devices from a central location.
MDM solutions can help businesses:
- Enforce security policies
- Require device encryption
- Enable remote lock and wipe capabilities
- Manage software updates
- Control application access
These controls help protect company data even if a device is lost or stolen.
Implement Zero Trust Security
Zero Trust assumes that no user or device should automatically be trusted.
By requiring continuous authentication and limiting access based on identity and device health, businesses reduce the impact of a compromised device.
Zero Trust strategies are becoming increasingly important as employees work remotely and access company resources from multiple devices.
Monitor Endpoints for Suspicious Activity
Endpoint Detection and Response (EDR) solutions provide another layer of protection by monitoring devices for unusual behavior.
While EDR cannot eliminate a hardware vulnerability, it can help security teams identify suspicious activity quickly and respond before attackers gain broader access to the network.
Don't Let Older Devices Become Your Weakest Link
Most cybersecurity incidents don't happen because organizations ignore security—they happen because outdated technology quietly remains in service long after the risks have changed.
If your business still relies on older Apple devices, now is the time to review your mobile security strategy, evaluate aging hardware, and strengthen your device management policies.
At Ironside IT, we help businesses throughout South Jersey, the Greater Philadelphia area, and Delaware secure their mobile devices, implement Microsoft 365 and Mobile Device Management solutions, and build cybersecurity strategies that protect both employees and company data.
A proactive approach today can help prevent a much larger security incident tomorrow.

