From getting JTAG on the iPhone 15 to hacking Apple's USB-C Controller

Stacksmashing

DEF CON 32 Main Stage · Day 1 · Main Stage

Overview

This talk, "Ace of the Sleeve: Hacking into Apple's New USB-C Controller," presented by Thomas Roth, also known as Stacksmashing, delves into the intricate process of re-establishing low-level debug access on Apple's latest devices, specifically the iPhone 15 and modern MacBooks. With Apple's transition from its proprietary Lightning connector to the industry-standard USB-C, the established methods for hardware and firmware debugging were rendered obsolete. Stacksmashing's research focuses on uncovering and exploiting Apple's custom implementations of the USB Power Delivery (USB-PD) protocol within their Apple Type-C port controllers, collectively referred to as "Ace."

Watch on YouTube

Visual summary for From getting JTAG on the iPhone 15 to hacking Apple's USB-C Controller by Stacksmashing
Visual summary for From getting JTAG on the iPhone 15 to hacking Apple's USB-C Controller by Stacksmashing

Key moments

  1. 0:00 Introduction and the USB-C debugging challenge
  2. 2:10 Apple's Ace controller and secret VDM functionality
  3. 3:20 Vendor Defined Messages for serial, JTAG, Thunderbolt
  4. 4:50 Achieving serial console on the iPhone 15
  5. 6:00 Uncovering undocumented JTAG/SWD VDM action 0206
  6. 6:25 Successful JTAG connection to iPhone 15 (production locked)
  7. 7:10 Introducing the Tamarin C adapter for deep analysis

From getting JTAG on the iPhone 15 to hacking Apple's USB-C Controller

Speakers: Stacksmashing

Conference: DEF CON 32

YouTube: https://www.youtube.com/watch?v=cFW0sYSo7ZM

Overview

This talk, "Ace of the Sleeve: Hacking into Apple's New USB-C Controller," presented by Thomas Roth, also known as Stacksmashing, delves into the intricate process of re-establishing low-level debug access on Apple's latest devices, specifically the iPhone 15 and modern MacBooks. With Apple's transition from its proprietary Lightning connector to the industry-standard USB-C, the established methods for hardware and firmware debugging were rendered obsolete. Stacksmashing's research focuses on uncovering and exploiting Apple's custom implementations of the USB Power Delivery (USB-PD) protocol within their Apple Type-C port controllers, collectively referred to as "Ace."

The presentation highlights the critical journey from initial reverse engineering to successfully enabling debug functionalities such as serial consoles, JTAG, and SPMI over the USB-C port. This work is not merely an academic exercise; it represents a significant achievement in hardware security research, providing invaluable access for analyzing Apple's closed ecosystems. The implications extend beyond debugging, as a compromised Ace controller could offer a stealthy and persistent attack vector against the main system-on-a-chip (SoC), leaving virtually no trace within the operating system.

Background

▶ Watch: Introduction and the USB-C debugging challenge (0:00)

For years, security researchers and hardware enthusiasts relied on the proprietary Lightning connector to gain low-level access to iPhones. Stacksmashing himself contributed to this ecosystem with the Tamarin cable, an open-source, $20 Lightning debugging interface introduced at DEF CON two years prior. This cable provided functionalities like JTAG, UART, and SDQ, which are crucial for in-depth hardware and firmware analysis. However, Apple's mandated shift to USB-C on the iPhone 15 effectively "threw all of my work away," necessitating a new approach to regain these capabilities.

The USB-C connector, while standard, offers a multitude of pins and capabilities, including USB Power Delivery (USB-PD). This protocol, designed for flexible power and data negotiation, became Apple's chosen vehicle for its custom debug functionality. Early research by other smart people, particularly the Asahi Linux team and the T8012 Dev team, revealed that Apple utilizes the USB-PD negotiation process to implement secret features. Central to this is a tiny microcontroller called the USB-C port controller, or "Ace," which handles all USB-PD communication. These controllers contain firmware that, years ago, was successfully dumped and reverse-engineered. The T8012 Dev team's blog post, for instance, detailed how Apple uses Vendor Defined Messages (VDMs) to change the configuration of pins on the USB-C connector, specifically the Sideband Use (SBU) pins, to enable serial communication. For example, sending VDM action 0x306 to the Ace controller could yield a serial console on a MacBook. This prior work established that Ace controllers were not just for serial, but could also expose JTAG, Thunderbolt, I2C, and on iPhones, SPMI.

The challenge then became how to send these vendor-defined messages, as they require specialized tooling beyond standard USB communication. Again, the Asahi Linux team identified that the back-left port on certain MacBook Pro models was uniquely capable of sending these commands, and they developed tools like vdmtool to facilitate this from one Mac to another. Concurrently, Mark Zier developed the Central Scrutinizer, a Pico-based serial adapter capable of sending these VDMs and providing a UART shell on MacBooks. These foundational efforts laid the groundwork for Stacksmashing's subsequent research into the iPhone 15 and deeper exploration of the Ace controller architecture.

Key Findings

▶ Watch: Vendor Defined Messages for serial, JTAG, Thunderbolt (3:20)

Stacksmashing's research culminated in several critical findings, successfully demonstrating the re-establishment of low-level debug access on Apple's latest hardware:

  1. iPhone 15 Debug Access: Despite Apple's transition to USB-C, Stacksmashing successfully enabled both a serial console and JTAG/SWD (Serial Wire Debug) on the freshly released iPhone 15. This was achieved by sending specific Vendor Defined Messages (VDMs): 0x306 for serial console access and 0x206 for SWD/JTAG.
  2. Locked JTAG on Production Devices: While JTAG access was successfully established, it was found to be locked on production iPhone 15 devices. This prevents actual debugging but confirms the underlying capability and the potential if a non-production device (often prohibitively expensive) were available.
  3. Ace 3 as a Critical Target: The Ace 3 chip on the iPhone 15, positioned between the USB-C port and the main System-on-a-Chip (SoC), was identified as a highly interesting and potent target for compromise. During recovery mode, the Ace 3 can present itself as a full USB device, making it directly addressable. A successful exploit of the Ace 3 could allow for deeply embedded, untraceable attacks on the main SoC.
  4. Deep Dive into Ace 2 Firmware: Extensive reverse engineering of the Ace 2 controller firmware (identified as a re-labeled Texas Instruments TPS65986, specifically the CD3217B12 variant) on M1 MacBooks revealed various command handling mechanisms and even privileged commands like memory read, write, and modify. These privileged commands are locked on production devices but represent a significant internal debug interface.
  5. Open-Source Debugging Hardware: The development of the Tamarin C adapter, an open-source fork of the Central Scrutinizer, provides a robust, bidirectional level-shifted, and power-switched tool for exploring all debug buses on the iPhone 15, including a full JTAG probe and the first public analyzer for SPMI (System Power Management Interface).
  6. Comprehensive Tooling: The creation of Ace tool, a utility for communicating with the Ace controller via the Apple HPM bus and its 4CC commands, along with documentation of VDM command lists, significantly democratizes access to this research.

These findings collectively demonstrate that Apple's move to a standard connector does not inherently remove their proprietary debug capabilities, but rather shifts them to a new, complex, and potentially vulnerable layer of the hardware stack.

Technical Deep Dive

▶ Watch: Achieving serial console on the iPhone 15 (4:50)

Apple's approach to integrating debug functionality into its USB-C devices hinges on extending the standard USB Power Delivery (USB-PD) protocol through Vendor Defined Messages (VDMs). The core of this system is the Apple Type-C port controller, or "Ace," a series of custom microcontrollers (e.g., Ace 1, Ace 2, Ace 3) that manage the USB-C port's functionality and communicate with the main SoC.

USB-PD and Vendor Defined Messages (VDMs)

USB-PD is a standard protocol that operates over the Configuration Channel (CCx) lines (CC1 or CC2, depending on port orientation) of the USB-C connector. It allows devices to negotiate power roles (source/sink) and data roles (host/device), as well as to enter various alternate modes. Apple leverages VDMs, which are specific types of USB-PD messages designed for vendor-specific extensions, to control pin multiplexing and enable debug features.

Apple's VDMs are characterized by their unique USB ID (0x5AC) and a specific header format: 0x5ac8000 | command. Crucially, Apple requires these messages to use non-standard SOP'DEBUG packet start tokens. Standard USB-PD controllers typically do not utilize these tokens, meaning specialized hardware or software capable of generating these packets is necessary to interact with Apple's Ace controllers. The protocol often expects the initiating device to act as a DFP (Downstream Facing Port, i.e., a power source) because Macs typically only act as DFP after the OS has booted. Command replies follow a consistent pattern: request command ID | 0x40. For instance, a reply to command 0x10 would be 0x50. Data units within VDMs are 16-bit, packed high to low in 32-bit VDM words, and zero-terminated.

The Ace Controller Architecture

The Ace controllers are ARM-based microcontrollers. The Ace 2 (specifically the CD3217B12, found in M1 MacBooks and later T2/M-series Macs) is a re-labeled Texas Instruments TPS65986. It connects to the main SoC via I2C. The firmware for these chips can be dumped, and reverse engineering reveals the underlying command structures and functionalities. The Ace 3 on the iPhone 15 is particularly interesting as it can run as a full USB device when the iPhone is in recovery mode, making it a direct and powerful target for interaction and potential exploitation.

Communication from the macOS SoC to the Ace controller occurs over the Apple HPM bus (Host Port Microcontroller bus) using four-byte commands, often referred to as 4CC (four-character code) commands, which are essentially ASCII-encoded integers (e.g., "GAID" or "reset"). Stacksmashing developed the Ace tool to facilitate communication via these commands.

Key VDM Commands and Debug Actions

The Asahi Linux team's extensive reverse engineering provided a comprehensive list of VDM actions. Key commands include:

  • 0x10 (Get Action List): This VDM (5ac88010) queries the Ace controller for a list of supported debug actions on a specific USB-C port. The response provides a series of 16-bit action IDs. For example, an M1 Mac Mini's left-side port might support actions like 0x4606, 0x606, 0x206, 0x301, 0x106, 0x105, 0x303, 0x803, 0x809, 0x103.
  • 0x11 (Get Action Info <actionid>): This command (5ac88011 <actionid>) retrieves detailed information about a specific action, returned in 16-bit short units.
  • 0x306: This action is used to enable a serial console over the SBU pins. Stacksmashing successfully used this to get a serial console on the iPhone 15.
  • 0x206: This action is crucial for enabling SWD/JTAG access. After some experimentation (reversing cable orientation), Stacksmashing achieved a "success message" and identified a debug port ID (4BA02477) on the iPhone 15 using this VDM.

It's important to note that the debug capabilities and supported actions can vary significantly between different Mac models and even between different USB-C ports on the same device. For instance, on a 2020 M1 Mac Mini, the port closest to the edge supports all debug features, whereas on a 2019 16" MacBook Pro, various ports report different sets of supported actions.

Privileged Commands and Firmware Structure

The Ace 2 firmware contains privileged commands such as memory read, write, and modify operations, akin to "peak and poke" functionalities. While these are locked on production devices, their presence indicates a powerful internal debug interface that, if unlocked (e.g., by flipping a single bit as mentioned), could provide deep control over the controller's operation. The firmware organization of Ace 1 (CD3215, likely a TPS65983 variant) and Ace 2 differs, indicating ongoing evolution in Apple's custom silicon and firmware development.

Demo / Proof of Concept

▶ Watch: Successful JTAG connection to iPhone 15 (production locked) (6:25)

The practical application of this research was demonstrated through the development and use of specialized hardware and software tools.

Initially, Stacksmashing leveraged the Central Scrutinizer, a Pico-based serial adapter developed by Mark Zier. This tool was instrumental in his early experiments to understand Apple's custom USB-PD VDMs. By connecting the Central Scrutinizer to the iPhone 15, he successfully achieved a serial console, demonstrating that the principles discovered on MacBooks extended to the latest iPhone.

Building upon this foundation, Stacksmashing developed his own open-source hardware, the Tamarin C adapter. This adapter is a significant enhancement, essentially a fork of the Central Scrutinizer, designed specifically for comprehensive debug access on the iPhone 15. Its key features include:

  • Bidirectional Level Shifters: Essential for safely interfacing with different voltage domains between the debug host and the iPhone.
  • USB Power Switch: Allows the Tamarin C adapter to charge the iPhone during long research sessions, ensuring continuous operation.
  • Full JTAG Probe: Integrates a complete JTAG probe, enabling direct connection to the iPhone's debug interface.
  • SPMI Analyzer: The Tamarin C adapter provides the first publicly released analyzer for the SPMI (System Power Management Interface) bus on the iPhone 15, opening up new avenues for power management research.

Using the Tamarin C adapter, Stacksmashing demonstrated the ability to send the specific VDM action 0x206 to the iPhone 15. This action successfully enabled the JTAG debug port, returning a debug port ID of 4BA02477. While the JTAG port was confirmed to be locked on the production iPhone 15, the ability to enable it simply by sending a VDM is a profound proof of concept. The Tamarin C adapter effectively allows researchers to "explore all the busses on the iPhone 15," providing unprecedented access to low-level hardware communication. The entire project, including the hardware designs and software, is open source, empowering other researchers to replicate and extend this work.

Defensive Implications

▶ Watch: Introducing the Tamarin C adapter for deep analysis (7:10)

The detailed insights into Apple's USB-C controller (Ace) and its debug functionalities carry significant defensive implications for both Apple and its users.

  1. Supply Chain Vulnerabilities: The Ace controller, being a custom piece of silicon (even if based on a commercial TI part), represents a critical component in the device's supply chain. If a malicious actor could compromise the Ace firmware during manufacturing or through a sophisticated hardware implant, it could provide a persistent, undetectable backdoor. Since the Ace controller sits between the USB-C port and the main SoC, it could facilitate covert data exfiltration, injection of malicious commands, or even direct attacks on the SoC without leaving any forensic traces within the operating system.
  2. Firmware Integrity and Authentication: The discovery of privileged commands (memory read/write/modify) within the Ace 2 firmware, even if locked on production devices, highlights the need for robust firmware integrity checks and secure boot mechanisms for the Ace controller itself. Any bypass of these locking mechanisms could expose the device to deep-seated manipulation. Apple's reliance on custom ROMs and firmware for these controllers means they must be as rigorously secured as the main SoC firmware.
  3. USB-PD Protocol Extensions as Attack Surface: Apple's proprietary extensions to the standard USB-PD protocol, particularly through the use of SOP'DEBUG packets and vendor-defined messages, create a unique attack surface. Standard USB-PD security models might not account for these custom commands, potentially leaving gaps for exploitation. Malicious chargers or accessories could be engineered to send these specific VDMs, attempting to unlock debug features or execute arbitrary code on the Ace controller.
  4. Lack of Transparency: The hidden nature of these debug functionalities within a standard connector underscores a broader challenge with closed-source hardware. Without the kind of in-depth reverse engineering performed by the Asahi Linux team and Stacksmashing, these capabilities would remain unknown, making it impossible for external security researchers to identify potential vulnerabilities. This lack of transparency can hinder proactive defense.
  5. Monitoring and Detection Challenges: Due to the low-level nature of USB-PD communication and the Ace controller's position, detecting an attack originating from a compromised Ace controller would be exceptionally difficult. Operating system-level security tools or network monitoring would likely be blind to such activity, as the compromise occurs beneath their visibility layer. Defenders need to consider hardware-level attestation and monitoring, which is a complex and resource-intensive task.
  6. Positive for Researchers: Conversely, for legitimate security researchers and auditors, this work provides invaluable tools and methodologies (e.g., the Tamarin C adapter, Ace tool) to inspect and understand Apple's hardware at a deeper level. This increased scrutiny can ultimately lead to the discovery and remediation of vulnerabilities, improving the overall security posture of Apple devices in the long run.

Key Takeaways

  • Apple's USB-C implementation on devices like the iPhone 15 and MacBooks incorporates extensive, hidden debug functionalities through custom USB Power Delivery (USB-PD) Vendor Defined Messages (VDMs).
  • Researchers successfully re-enabled low-level debug access, including serial consoles (0x306 VDM) and JTAG/SWD (0x206 VDM), on the iPhone 15, proving the existence of these capabilities despite the switch from Lightning.
  • The Ace controller (Ace 2, Ace 3) is a critical, powerful, and potentially vulnerable microcontroller situated between the USB-C port and the main SoC, offering a stealthy attack vector if compromised.
  • Open-source hardware (e.g., Tamarin C adapter) and software tools (Ace tool) have been developed to democratize access to these debug features, enabling broader research and auditing.
  • This research heavily relies on foundational work by the Asahi Linux team and the T8012 Dev team, highlighting the collaborative nature of hardware security research.
  • Compromising the Ace controller could allow for persistent, untraceable attacks on the main system-on-a-chip, posing significant supply chain and firmware security challenges.

About the Speaker(s)

Thomas Roth, widely known as Stacksmashing, is a prominent security researcher specializing in hardware and firmware. He is also a co-founder of the online training platform Hextree.io, which focuses on hardware security. Stacksmashing is active on various platforms, including Twitter and YouTube, where he shares his research and insights into complex hardware vulnerabilities and reverse engineering challenges. His work consistently pushes the boundaries of understanding closed hardware ecosystems.

Reviews

Dr. Zero (Offensive Security Researcher) — MUST SEE

Stacksmashing's work on regaining low-level debug access to the iPhone 15 and modern MacBooks via Apple's custom USB-C controllers (Ace) is a masterclass in hardware reverse engineering. By dissecting Apple's proprietary USB-PD Vendor Defined Messages and building open-source hardware, he's not only re-established critical debug channels like JTAG and serial consoles but also exposed a potent, untraceable attack surface in the Ace controller itself. This research provides invaluable tools and insights for anyone serious about understanding and securing Apple's closed ecosystem.

Heather Calloway (CISO) — STRONG ACCEPT

Stacksmashing's work on Apple's USB-C controller, "Ace," is a deeply technical dive that uncovers a critical new layer of hardware risk. By demonstrating the re-establishment of low-level debug access on the iPhone 15 and MacBooks, this research exposes a stealthy and persistent attack vector that operates beneath the visibility of traditional operating system defenses. For any organization relying on Apple devices, this presentation demands a re-evaluation of hardware supply chain security, device integrity, and the fundamental trustworthiness of endpoints.

→ Top-rated talks at DEF CON 32 Main Stage

All talks from DEF CON 32 Main Stage