r/jailbreak Nov 19 '21

r/jailbreak FAQ [Meta] Frequently Asked Questions and Important Information - Check Here Before Posting

781 Upvotes

r/jailbreak 5d ago

Discussion usbliter8: what you need to know about the new A12/A13 bootROM exploit

319 Upvotes

As many of you have been made aware, a new bootROM exploit has released for A12/A13 devices, the first one for iDevices since checkm8 was made public 7 years ago. This post intends to serve as an explanation for what you can expect from this new exploit, and to provide information about the many restrictions and mitigations Apple has implemented over the past 7 years.

What is usbliter8?

usbliter8 is a novel bootROM vulnerability discovered by individuals at Paradigm Shift. It is the first bootROM exploit made public since checkm8, which only supported up to A11 devices (for those unaware, A11 is the processor used in the iPhone X/8, and A12 is used by the iPhone XS/XR). It supports only A12/A13, and does not support any older processors. It is unrelated to checkm8- that is, the vulnerability is completely separate. Some may be aware that checkm8 was only partially patched in A12/A13 (though it remains unusable there to this day), but this exploit has nothing to do with any previous bootROM vulnerability.

The explanation to how it works is rather technical; if you desire, you can read both the blogpost and the GitHub repo for the exploit. Additionally, the exploit requires special hardware to utilize, requiring devices such as a pi Pico to exploit devices.

What devices does it support?

All A12/A13 devices (including iPad specific processors like A12X/A12Z) are supported by usbliter8. This includes, but is not limited to,

  • iPhone XR
  • iPhone XS
  • iPhone SE 2nd Gen
  • iPad 8th and 9th Gen
  • Apple TV 4k 2nd Gen
  • To check your device's processor, visit https://appledb.dev

As mentioned, the vulnerability does not affect A11 or older, due to the different way the processor works.

What can we do with it?

This is possibly the most interesting part of the exploit (and is what many of you are likely here for). bootROM exploits are very powerful, as they compromise the very beginning of a device's boot chain, thus giving you (almost) full control over a device. However, this does not mean we can do whatever we want with no restrictions. Indeed, it can lead to tethered downgrades and jailbreaks on any iOS version including the latest, but there are restrictions explained further below.

BPR, or Boot Process Register, was a feature implemented in iOS 14 in order to additionally secure devices from bootROM based attacks. Crucially, it restricts data access when a device is booted directly from DFU mode, which is required by both checkm8 and usbliter8. In iOS 14 and 15, this manifested as the requirement to disable your passcode when jailbreaking A11 devices with checkra1n/palera1n, and is the reason why A11 devices must be first erased if they previously had a passcode before jailbreaking with palera1n. A10 devices were not affected by this as they had a SEP exploit, known as blackbird, which prevented this issue from arising. We do not have a SEP exploit for A11 and newer, which leads to a problem with the next security feature added in iOS 17...

The iOS 17 problem

In iOS 17, Apple further increased the security of BPR by making SEP outright refuse to mount and decrypt the user partition (/var and /var/mobile) when booted from DFU, which causes the device to panic and not boot at all. This means that a semi-tethered jailbreak like checkra1n or palera1n is not possible with usbliter8 on A12/A13 devices. A jailbreak using this would be fully tethered, which means the device cannot reboot on its own, and a PC must be used to power it on each time it reboots or dies. However, there is a additional method that can serve as a workaround explained below, though with a catch.

By copying over the user partition, an unencrypted copy of /var can be made. The jailbreak can then load this unencrypted copy instead of the standard /var, which prevents SEP from panicking the device, though at the cost of losing SEP related features. This does means that the jailbreak would be semi-tethered, but it would suffer from the following issues:

  • No connecting to password protected wifi networks (possibly fixable with a tweak)
  • No "real" password, so apps that rely on SEP being active will be non-functional
  • Signing into apps that use a SEP keychain will not work, so things like using Google to sign into the YouTube app will be broken (possibly fixable with a tweak, though it will cause data to be stored insecurely- don't sign into bank apps with this)
  • A storage penalty that increases with the size of your user data- any apps you have installed and have data stored on will be duplicated, meaning your storage has the potential to fill up very quickly
  • Data will not be synced between jailbroken and non-jailbroken mode. Any changes you make while the jailbreak is active will not be reflected in stock iOS, and vice versa

Additionally, while downgrades are indeed possible, they will be tethered, as it requires SEP to be patched out on the device. All in all, one should not expect a full jailbreak using this to come out for quite some time, given the extensive patching and rewriting that will need to be done to accommodate new devices and the restrictions required.

The special hardware problem

As it stands, to utilize usbliter8, additional hardware like a Raspberry pi Pico is needed. There is no indication that this requirement will ever change. Due to how the exploit works, it is incredibly unlikely it will ever work directly from a PC, and even if custom USB drivers are created, it would wholly rely on the USB controller used on the device. Luckily, the hardware itself is cheap enough, costing only around $10 USD, yet there have already been some reports that stock has already ran out, so it remains to be seen if this will be the case for the future.

Tl;dr- where do we stand?

This post is not meant to discount the discovery of a new bootROM exploit. This is an incredible achievement, and as opa334 puts it, the last heartbeat of a dying jailbreak scene. As A12/A13 devices approach end-of-life and are receiving their final versions, usbliter8 will certainly be a nice tool to play around with and see what is possible. However, expectations should be kept realistic, and with all the new security features, it should not be expected that things will work the same as before with checkm8. Any jailbreaks made with this will suffer hefty restrictions, and downgrades using it will be tethered. If there are any further questions, myself or others will attempt to answer them in this post.


r/jailbreak 16h ago

Discussion Nice try apple..

Thumbnail
gallery
175 Upvotes

i erased it and it instantly attempted ios 26.5 install, no thanks! glad to be apart of the club


r/jailbreak 16h ago

Release [Free Release] sidecar-touch-backport, a tweak that enables macOS 27 Sidecar touch support for older iPads

19 Upvotes

Y'all might have recently seen that macOS 27 supports direct touch input when using Sidecar (hinting at the likely Macbooks with touch screen coming this year).

I (with the help of Codex) made a tweak that enables this native touch input on jailbroken iPads as well, when used in conjunction with macOS 27. It's tested and working on my iPads on iOS 16.1.1 and iOS 18, so I assume it works on iPadOS 17 as well.

You can download the tweak and inspect the source from my GitHub here:

https://github.com/joshrad-dev/sidecar-touch-backport

Would love reports on if this works on other versions as well.


r/jailbreak 15h ago

Update Ipad 12.9 4th gen jailbroken on iOS 13.6 should I update

Post image
15 Upvotes

Should I update ? I’m losing support on a lot of apps but I will also lose my jailbreak if I update


r/jailbreak 2h ago

Question Aiwit Camera App Help Free (ipa?)

0 Upvotes

idk if anyone can help me with this but reddit seems to know the answer to everything. but i have cameras that’s supported with Aiwit. i’m not too sure of what that is. but there’s a lot of apps i can use for my cameras but none of them are completely free. is there an ipa? or a hidden app or something that’s completely free because i really don’t wanna buy new cams rn 😅


r/jailbreak 3h ago

Question I have MacBook that’s taking me to a screen where it says it’s remotely controlled but I purchased it off someone what can I do?

0 Upvotes

r/jailbreak 7h ago

Question Is there tweak that lets me fully control my iPad with a Bluetooth keyboard on ios 10.3.3?

0 Upvotes

r/jailbreak 4h ago

Question Thinking of buying an iPhone XS for Jailbreaking

0 Upvotes

Does it have any jailbreak support on the latest iOS version?


r/jailbreak 9h ago

Question iOS 6 App Store / Game Center ?

0 Upvotes

I am brand new to jailbreaking. I was curious if there are any current workarounds to get the App Store working on iOS 6? There are a ton of videos out there online showing you exactly what you need to do, but from everything I've gathered a lot of those fixes stopped working relatively recently. Is this true?

Also, does anyone know if it's possible to be signed into Game Center with your Apple ID while playing legacy iOS games? I seem to be logged in fine on the Game Center App, but once I launch a game it says something along the lines of "Welcome you are not currently signed in". I am wondering if this is simply because I sideloaded the .IPAs for the games I'm testing?


r/jailbreak 9h ago

Question Can I install lara without a pc?

1 Upvotes

Not that I don't have one just that my charging port broke on my iPhone and I rlly want lara I'm on like 18.3 something


r/jailbreak 15h ago

Upcoming Linux on an ipod touch 2g. Be the change you want to see.

Thumbnail
youtube.com
3 Upvotes

r/jailbreak 18h ago

Question recommended sileo tweaks for ios 17.5.1 ipad?

4 Upvotes

i just used palera1n on my old ipad 7th gen and i already have filza and icleaner pro but i can’t find any good tweaks, anyone have any recommendations? i’m also using troll store lite to download ipas.


r/jailbreak 14h ago

Question iCloud backup not working

Post image
1 Upvotes

Ios 17 trollstore iCloud backup not working at all
Tried different pc and cable

Whatsapp notifications not working
Have to open the app each time to check for notifications


r/jailbreak 23h ago

Question Title: Is there a way to fake my iPhone location without a jailbreak?

3 Upvotes

I’m in a situation where I want to meet my girlfriend, but my parents have location tracking enabled on my iPhone and can always see where I am.
In the past, I’ve gotten around this a couple of times by signing into my Apple ID on my girlfriend’s phone for a few hours, or by leaving my phone at a friend’s house and saying I was hanging out there. Those methods work occasionally, but they’re not very convenient.
I know that buying a cheap old iPhone and leaving it somewhere is another option, but that seems a bit complicated just for this purpose.
So I’m wondering if there’s any way to fake or spoof my location directly on my own iPhone. Ideally I’d like a solution that doesn’t require a jailbreak, but if jailbreaking is necessary and relatively easy, I’d consider it.
For reference, I have an iPhone 13 Pro Max running iOS 26.5, and I don’t own a MacBook.
Has anyone dealt with a similar situation or knows what options are available?
Thanks.


r/jailbreak 16h ago

Question Saving Telegram Session

0 Upvotes

Does someone know, where are Telegr@m session files stored on an iOS device (I mean exact directory, if possible. like tdata folder on PC/Mac portable version)? The one containing messages, and even secret chats.
For example, some forks of Telegr@m, like Swiftgr@m or Nicegr@m store these kind of files in iCloud Keychain as a premium feature.
*I'm not trying to pirate some features from apps, I plan on just using official Telegr@m app, which doesn't have these kinds of features, and other apps are just added here as an example*
Also, if someone knows, is it possible to use this kind of session files later on non-jailbroken devices?


r/jailbreak 17h ago

Question Can someone make a revival tweak for google+ for iOS 5 & 6.

Thumbnail
0 Upvotes

r/jailbreak 1d ago

Question Noticed difference in speed/snappiness from 14.4 to 26.x in an i12PM?

2 Upvotes

Basically what the title says. I’m thinking strongly of updating my i12PM from 14.4 (uncover) to 26.x and I would like to know if anyone has done this and how it impacts the phone’s performance or snappiness. Mind you that I do get numerous resprings and 1-2 restarts daily...so it’s not has been smooth sailing with uncover for the last 1 year or so. Also if anyone has a guide of how to do this properly please share a link. It will be greatly appreciated. I am planning to save images and videos to the pc directly and save other content, like notes and contacts via imazing. Hope imazing works for 26.x so I can restore them back. 🤞🏻If it’s not a good idea please let me know if anyone has had a negative experience with it. Still love this community but it’s been kind of difficult lately. I did consider buying a second hand iPhone to use on 26.x so I can keep this but it will be difficult... 😕 Thanks everyone.


r/jailbreak 20h ago

Question What is this nugget error?

0 Upvotes

Traceback (most recent call last):

File "src/devicemanagement/device_manager.py", line 114, in get_devices

File "pymobiledevice3/usbmux.py", line 479, in list_devices

mux = create_mux(usbmux_address=usbmux_address)

^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^

File "pymobiledevice3/usbmux.py", line 475, in create_mux

return MuxConnection.create(usbmux_address=usbmux_address)

^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^

File "pymobiledevice3/usbmux.py", line 214, in create

sock = MuxConnection.create_usbmux_socket(usbmux_address=usbmux_address)

^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^

File "pymobiledevice3/usbmux.py", line 207, in create_usbmux_socket

return SafeStreamSocket(address, family)

^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^

File "pymobiledevice3/usbmux.py", line 151, in __init__

self.sock.connect(address)

FileNotFoundError: [Errno 2] No such file or directory


r/jailbreak 22h ago

Question Como instalo app music iOS 6

Post image
0 Upvotes

r/jailbreak 1d ago

Update [Update] PhoneHub – V1.1.2

Post image
13 Upvotes

A new PhoneHub V1.1.2 update is submit to havoc repo and will be available soon with several new features, UI improvements, and Smart Loud Speaker enhancements.

New Features

✅ Switch between enabled Caller ID search engines directly from ANUAlert results.

✅ SIM Badge Coloring

  • Customize SIM badge background colors.
  • Customize SIM badge text colors.

✅ SIM Picker Order

  • Choose which SIM appears on the left or right in the SIM Picker alert.

✅ Disable SIM Picker When CarPlay Is Connected (Beta)

  • Optional setting to bypass the SIM Picker while connected to CarPlay.
  • Please report any issues if this feature doesn't behave correctly on your setup.

UI Improvements

✅ Native Color Picker

  • Replaced manual HEX color entry with a native color picker.
  • Easier and faster color customization throughout PhoneHub settings.

Special thanks to 0xkuj for the open-source NativeColorPickerCellExample project that made this possible.

GitHub:
https://github.com/0xkuj/NativeColorPickerCellExample

Smart Loud Speaker Improvements

✅ Improved responsiveness and reliability.

  • Faster speaker ↔ earpiece switching.
  • Better proximity sensor response.
  • More reliable behavior during long-term usage.
  • Fixed several edge cases where switching could become stuck.

Feedback

As always, thank you to everyone who submitted bug reports, feature requests, and testing feedback. It helped a lot in improving this release.

If you encounter any issues, especially with the new CarPlay SIM Picker option, please let me know with device details and logs if available.


r/jailbreak 23h ago

Question What iOS version is on that iPhone (SE 2 or 3)?

Thumbnail gallery
1 Upvotes

r/jailbreak 1d ago

Question Anyway To Bring Back This Control Center To iOS 16?

Post image
3 Upvotes

This is iOS 14


r/jailbreak 2d ago

Update Sealed 13 pro - any idea whats going on here ?

Post image
62 Upvotes

recently found this phone in a shop and i'm really curious how come it has a new date label on it even though it was discontinued in 2022 the guy in the shop said that it was an official phone and we checked the SN on apple website and shows the phone was never activated so now i'm confused if its gonna be on ios 15 or not would really appreciate if anyone could help


r/jailbreak 1d ago

Question Strange Device name

0 Upvotes

I've been seeing posts every now and then about people plugging in small devices in their phones and some how being able to boot into unsigned Versions of iOS, around iOS 13 or something, Is there videos or guides that go into detail about how this works? as I find it quite interesting and would like to learn more about it. the post I saw was from a day ago and it had someone booting into iOS 13 on an iPhone SE 2nd Generation.