«We’ve added bootloader-level low-level extraction support for the second-generation Apple TV 4K. While the older 4K model was compatible with the checkm8 exploit, the second-generation is based on a newer SoC that required a newer exploit, usbliter8. The exploit requires a custom adapter that uses a microcontroller board with our custom firmware. Extracting the Apple […]»
24 September, 2026Vladimir Katalov
«iOS Forensic Toolkit 10.11 adds bootloader-level extraction for the Apple Watch Series 4, the Apple Watch Series 5, and the second-generation Apple TV 4K. This article gives the full procedure for each of the two Apple Watch devices. The method uses usbliter8, an exploit of the SecureROM, the read-only boot code in the chip. checkm8 […]»
23 September, 2026Vladimir Katalov
«Seven years after checkm8, iOS Forensic Toolkit 10.11 adds bootloader-level extraction for the Apple Watch Series 4 and Series 5, as well as the second-generation Apple TV 4K. In each case the result is the full file system image and the decrypted keychain. This is the first time that the low-level extraction boundary has moved […]»
22 September, 2026Oleg Afonin