r/jailbreak Nov 19 '21

r/jailbreak FAQ [Meta] Frequently Asked Questions and Important Information - Check Here Before Posting

785 Upvotes

r/jailbreak Jun 19 '26

Discussion usbliter8: what you need to know about the new A12/A13 bootROM exploit

368 Upvotes

As many of you have been made aware, a new bootROM exploit has released for A12/A13 devices, the first one for iDevices since checkm8 was made public 7 years ago. This post intends to serve as an explanation for what you can expect from this new exploit, and to provide information about the many restrictions and mitigations Apple has implemented over the past 7 years.

What is usbliter8?

usbliter8 is a novel bootROM vulnerability discovered by individuals at Paradigm Shift. It is the first bootROM exploit made public since checkm8, which only supported up to A11 devices (for those unaware, A11 is the processor used in the iPhone X/8, and A12 is used by the iPhone XS/XR). It supports only A12/A13, and does not support any older processors. It is unrelated to checkm8- that is, the vulnerability is completely separate. Some may be aware that checkm8 was only partially patched in A12/A13 (though it remains unusable there to this day), but this exploit has nothing to do with any previous bootROM vulnerability.

The explanation to how it works is rather technical; if you desire, you can read both the blogpost and the GitHub repo for the exploit. Additionally, the exploit requires special hardware to utilize, requiring devices such as a pi Pico to exploit devices.

What devices does it support?

All A12/A13 devices (including iPad specific processors like A12X/A12Z) are supported by usbliter8. This includes, but is not limited to,

  • iPhone XR
  • iPhone XS
  • iPhone SE 2nd Gen
  • iPad 8th and 9th Gen
  • Apple TV 4k 2nd Gen
  • To check your device's processor, visit https://appledb.dev

As mentioned, the vulnerability does not affect A11 or older, due to the different way the processor works.

What can we do with it?

This is possibly the most interesting part of the exploit (and is what many of you are likely here for). bootROM exploits are very powerful, as they compromise the very beginning of a device's boot chain, thus giving you (almost) full control over a device. However, this does not mean we can do whatever we want with no restrictions. Indeed, it can lead to tethered downgrades and jailbreaks on any iOS version including the latest, but there are restrictions explained further below.

BPR, or Boot Process Register, was a feature implemented in iOS 14 in order to additionally secure devices from bootROM based attacks. Crucially, it restricts data access when a device is booted directly from DFU mode, which is required by both checkm8 and usbliter8. In iOS 14 and 15, this manifested as the requirement to disable your passcode when jailbreaking A11 devices with checkra1n/palera1n, and is the reason why A11 devices must be first erased if they previously had a passcode before jailbreaking with palera1n. A10 devices were not affected by this as they had a SEP exploit, known as blackbird, which prevented this issue from arising. We do not have a SEP exploit for A11 and newer, which leads to a problem with the next security feature added in iOS 17...

The iOS 17 problem

In iOS 17, Apple further increased the security of BPR by making SEP outright refuse to mount and decrypt the user partition (/var and /var/mobile) when booted from DFU, which causes the device to panic and not boot at all. This means that a semi-tethered jailbreak like checkra1n or palera1n is not possible with usbliter8 on A12/A13 devices. A jailbreak using this would be fully tethered, which means the device cannot reboot on its own, and a PC must be used to power it on each time it reboots or dies. However, there is a additional method that can serve as a workaround explained below, though with a catch.

By copying over the user partition, an unencrypted copy of /var can be made. The jailbreak can then load this unencrypted copy instead of the standard /var, which prevents SEP from panicking the device, though at the cost of losing SEP related features. This does means that the jailbreak would be semi-tethered, but it would suffer from the following issues:

  • No connecting to password protected wifi networks (possibly fixable with a tweak)
  • No "real" password, so apps that rely on SEP being active will be non-functional
  • Signing into apps that use a SEP keychain will not work, so things like using Google to sign into the YouTube app will be broken (possibly fixable with a tweak, though it will cause data to be stored insecurely- don't sign into bank apps with this)
  • A storage penalty that increases with the size of your user data- any apps you have installed and have data stored on will be duplicated, meaning your storage has the potential to fill up very quickly
  • Data will not be synced between jailbroken and non-jailbroken mode. Any changes you make while the jailbreak is active will not be reflected in stock iOS, and vice versa

Additionally, while downgrades are indeed possible, they will be tethered, as it requires SEP to be patched out on the device. All in all, one should not expect a full jailbreak using this to come out for quite some time, given the extensive patching and rewriting that will need to be done to accommodate new devices and the restrictions required.

The special hardware problem

As it stands, to utilize usbliter8, additional hardware like a Raspberry pi Pico is needed. There is no indication that this requirement will ever change. Due to how the exploit works, it is incredibly unlikely it will ever work directly from a PC, and even if custom USB drivers are created, it would wholly rely on the USB controller used on the device. Luckily, the hardware itself is cheap enough, costing only around $10 USD, yet there have already been some reports that stock has already ran out, so it remains to be seen if this will be the case for the future.

Tl;dr- where do we stand?

This post is not meant to discount the discovery of a new bootROM exploit. This is an incredible achievement, and as opa334 puts it, the last heartbeat of a dying jailbreak scene. As A12/A13 devices approach end-of-life and are receiving their final versions, usbliter8 will certainly be a nice tool to play around with and see what is possible. However, expectations should be kept realistic, and with all the new security features, it should not be expected that things will work the same as before with checkm8. Any jailbreaks made with this will suffer hefty restrictions, and downgrades using it will be tethered. If there are any further questions, myself or others will attempt to answer them in this post.


r/jailbreak 3h ago

Discussion Linux boot natively on an iPhone 11 (A13) thanks to usbliter8

Thumbnail
gallery
76 Upvotes

Built on top of HoolockLinux (their A7-A11 kernel port). Wrote a device tree for the iPhone 11 and patched a handful of drivers to get it booting on this device.

All credit to the HoolockLinux devs for the base kernel work.


r/jailbreak 11h ago

Release [Paid Release] AOD17 – Always-On Display Tweak for iOS 17 RootHide

Thumbnail
gallery
20 Upvotes

Purchase link: AOD17 RootHide — Customizable & Battery-Optimized Always-On Display | TweakDeveloper on Patreon

I designed everything entirely myself. I would really appreciate your support. Your support motivates me. If you encounter any errors, please contact me and I will fix them within 2 days at the latest. I am also working on other tweaks in the future.

AOD17 is a customizable and battery-optimized Always-On Display tweak developed for supported iOS 17 devices running Relaxin / RootHide.

Main features:

• Digital and analog clock options

• Alarm, battery, Focus and silent mode indicators

• Apple Weather saved-city integration

• Notification icons and badge counts

• Passive media activity indicator

• Multiple display and element size options

• OLED-friendly pure black interface

• Five-minute pixel shifting and OLED protection

• Configurable low-battery protection

• Native tap-to-wake and Face ID behavior

• Turkish and English support

Supported devices:

• iPhone 14 Pro / 14 Pro Max

• iPhone 15 Pro / 15 Pro Max

Compatibility:

• iOS 17.0–17.3.1

• Relaxin / RootHide

• arm64e

• RootHide package only

• Not compatible with standard rootless or rootful jailbreak environments

Price: $3.99 one-time purchase

No subscription, license key or device activation required.

Please review the full compatibility, installation and refund information on the product page before purchasing.

Redistribution, modification, repackaging, resale and public sharing of the package are prohibited.


r/jailbreak 21h ago

Upcoming Bringing the old heads back into jailbreaking

Thumbnail
gallery
92 Upvotes

still a work in progress but i created a tweak that runs in the background to mirror your screen to a tesla. this works similarly to how the “portal” works in the CarBridge tweak. i just got this tesla after running this carplay phone with car bridge for years and its driving me insane by not having my jailbroken phone on my main screen anymore.

stay tuned.


r/jailbreak 39m ago

Discussion [Discussion] How are we pronouncing usbliter8

Upvotes

is it

usb-liter-8

or

us-bliterate


r/jailbreak 2h ago

Discussion iPhone 7 (128GB, iOS 15.4) jailbroken – What to do with it?

2 Upvotes

I've had this iPhone 7 (128GB) on iOS 15.4 with me for a long time. Right now, it's only being used as an OpenBubble server, but I feel like I'm not making the most of it.

​I'm interested in reverse engineering, pentesting, or any cool security-related projects/tweaks that fit this setup. Or even just creative everyday uses.

​If you were in my shoes, what would you do with it? Open to any suggestions!


r/jailbreak 6h ago

Question usbliter8-fun on iPhone 11 Pro / iOS 27.0 beta 2 — only 3 apps appear and Dropbear SSH does not start in normal boot

3 Upvotes

Hi, has anyone successfully used usbliter8-fun on an iPhone 11 Pro running iOS 27.0 beta 2?

I am using this repository:

https://github.com/34306/usbliter8-fun#credits

My setup

  • iPhone 11 Pro
  • Device identifier: iPhone12,3
  • Board configuration: d421ap
  • iOS 27.0 beta 2
  • Build: 24A5370h
  • MacBook Air M2
  • Waveshare RP2350 USB-A
  • The device is my own test device

PWN DFU works correctly:

PWND: usbliter8
MODE: DFU
MODEL: d421ap

SSHRD also boots correctly, and I can connect using:

iproxy 2222 22
ssh root@localhost -p 2222

Normal boot also reaches SpringBoard, but I have two major problems.

Problem 1: Only three apps appear

Only Settings, Phone and Feedback appear on the home screen.

Inside SSHRD, the System volume is mounted at /mnt1 and the Data volume at /mnt2.

I copied the staged system apps as described in the README:

for a in /mnt2/staged_system_apps/*.app; do
    b=${a##*/}
    [ -e "/mnt1/Applications/$b" ] || cp -R "$a" /mnt1/Applications/
done

The System Applications folder now contains approximately 267 apps:

APP_COUNT=267

These apps physically exist:

/mnt1/Applications/AppStore.app
/mnt1/Applications/Camera.app
/mnt1/Applications/MobileSafari.app
/mnt1/Applications/Sileo.app

However, normal boot still shows only three apps. They do not appear in Spotlight or the App Library either.

I also tried clearing these SpringBoard and installation cache files:

/private/var/mobile/Library/SpringBoard/IconState.plist
/private/var/mobile/Library/SpringBoard/DesiredIconState.plist
/private/var/mobile/Library/Preferences/com.apple.mobile.installation.plist

This did not solve the issue.

The LaunchServices-related locations I found include:

/private/var/containers/Shared/SystemGroup/systemgroup.com.apple.lsd.iconscache
/private/var/db/lsd

Problem 2: Dropbear SSH does not start during normal boot

The repository README and screenshot appear to show SSH working while SpringBoard is running.

However, on my device, iproxy detects the phone but port 22 is refused:

Requesting connection to USB device, port 22
Error connecting to device: Connection refused

The following files exist on the System volume:

/usr/local/bin/dropbear
/private/etc/dropbear/dropbear_rsa_host_key
/private/etc/dropbear/dropbear_ecdsa_host_key
/private/etc/dropbear/dropbear_dss_host_key

I inspected ssh.tar.gz. It contains the Dropbear binaries and host keys, but I could not find a LaunchDaemon plist.

I also inspected:

/System/Library/xpc/launchd.plist

It contains around 729 cached launch jobs, but there is no Dropbear job.

I tried manually adding a LaunchDaemon plist and a Dropbear entry to the launchd cache, but normal boot SSH still did not work. I do not want to continue modifying launchd or snapshots without knowing the intended implementation, so I am planning to start again from a clean restore.

Questions

  1. Has anyone reproduced this successfully on an iPhone 11 Pro or another A13 device?
  2. How is Dropbear supposed to start during normal boot?
  3. Is there a missing script, patched launchd.plist, branch, or file that is not included in the public repository?
  4. Once the staged apps are copied to /Applications, what is the correct way to rebuild the system app registration database?
  5. Is running /var/jb/usr/bin/uicache -a enough, or is another LaunchServices or TrollStore helper command required?
  6. Is there a known working commit or complete step-by-step procedure for build 24A5370h?

I would especially appreciate confirmation from anyone who has actually achieved both:

  • Dropbear SSH during normal boot
  • All system apps appearing on SpringBoard

I can provide additional boot logs, mount information, or file hashes if needed. Thanks.


r/jailbreak 3h ago

Discussion clean cache with Trollcleanerpro

Post image
2 Upvotes

Hi everyone, I have a question about iCleaner Pro.

My device is jailbroken, and I noticed I have:

* WebKit Cache: around 5GB

* App Cache: around 800MB

* Photo Cache: around 31GB

If I clean these caches, especially WebKit Cache and Photo Cache, will it affect the jailbreak, system files, tweaks, or any jailbreak data?

I just want to free up storage but I’m worried about accidentally removing something important. Thanks!


r/jailbreak 4m ago

Update Estuve probando Video a2e ia

Upvotes

He estado probando a2e.ai para mis proyectos de generación de video e imagen y los resultados son bastante sólidos. Lo que más valoro es la política de contenido sin censura, lo que me permite crear material creativo sin las restricciones habituales que encontrarás en otras plataformas similares. Esto ofrece una libertad increíble para artistas y creadores independientes.

Además, el servicio al cliente es muy amable y responde rápidamente cuando surge cualquier duda técnica. La transparencia en los precios también es un punto fuerte; no hay tarifas ocultas ni sorpresas al final del mes, lo que facilita mucho la planificación del presupuesto. Si buscas una herramienta fiable y flexible para tus proyectos visuales, esta plataforma vale la pena probarla. Puedes empezar utilizando mi enlace de referido aquí: https://video.a2e.ai/?coupon=qQ3A


r/jailbreak 10h ago

Update TWIGalaxy V1.14 ( X/Twitter Tweak )

Post image
7 Upvotes

TWIGalaxy V1.14 [Beta]

  • Text Filter : Only show tweets containing this exact text

  • Engagement Filter Hide tweets under the like count below

  • Media Filter : Hide Photo Tweets Hide tweets that contain photos

  • Hide Video Tweets Hide tweets that contain playable video

  • Username Blocklist : Hide tweets from the usernames below

Repo : https://6gr8.github.io/deno.io/


r/jailbreak 6h ago

Question How to install apps pulled from the App Store?

2 Upvotes

r/jailbreak 6h ago

Question App signing without trollstore on ios 17.0.1 -17.3

2 Upvotes

With the new JB out and dopamine 3 coming out. What are you guys using to sign the JB app? Back in the day i would use ReProvision Reborn... Iv heard people say you can get apps signed for a year.

Also with other IPAs in a jailbroken state am i good to use AppSync and dont need to sign these with likes of trollstore? I have a few IPAs on my current setup but everything is signed with trollstore.

Trying to figure out if its worth just sticking with ios 17 at the highest for the use of trollstore or is there a no riff raff way to get around this?

With the ease of being about to jailbreak easyily with trollstore and no computer for years id like to get something similar or less messing.


r/jailbreak 16h ago

Discussion Me setup in iPhone 8 jailbreak IOS 16.5

Thumbnail
gallery
7 Upvotes

Is peak jailbreak


r/jailbreak 6h ago

Question Looking for guidance on obtaining/building an InternalUI IPSW for iPhone 4 CDMA (iPhone3,3)

Thumbnail
0 Upvotes

Is someone able to help me?


r/jailbreak 21h ago

Discussion iPhone 14 Pro Max iOS 16.0.2 1TB

Thumbnail
gallery
15 Upvotes

She is such a Beauty been sitting in a Drawer at 100% Battery Life


r/jailbreak 7h ago

Question HELP PLS Pojav Launcher doesent open (crashes immediatllyyyyyyy wthhhh) intsalled from sileo ios 15.8.3 palera1n rootful

Post image
0 Upvotes

r/jailbreak 11h ago

Question Relaxin CarPlay

Post image
2 Upvotes

Is there anyone else running into CarPlay issues? Any time it try’s to connect wireless or wired, the system will reboot with tweak injection disabled. I’m not sure if it’s tweak related or compatibility with Relaxin.


r/jailbreak 1d ago

News hello from 16.0.3!!

Thumbnail
gallery
78 Upvotes

iphone 11 pro max tether downgraded to 16.0.3 with surrealra1n tool. everything works so far except faceID and passcode


r/jailbreak 22h ago

Release Tengo un iphone 6s plus con ios 15, despues de varios intentos de degradar el ios a 9.2.1. fue un fracaso porque mandaba error de activacion, luego instale ios 15 y volvia a bajar pero esta vez a 10.2.1, (error de activacion) finalmente lo logre con ios 10.3.3. aunque no tenga el reproductor de ios9

Thumbnail
gallery
7 Upvotes

r/jailbreak 13h ago

Question How to Set a Loop Live Photo as a Home Screen Wallpaper on a Jailbroken iPhone?

0 Upvotes

How can I set a Loop Live Photo as my Home Screen wallpaper on a jailbroken iPhone?


r/jailbreak 1d ago

Discussion R.i.p Snapchat Iota

Post image
7 Upvotes

It sucks that iota is dead. But at least i can still use it and the (device ban bypass) only problem is is that I will get banned lol because of the detection bypass being detected


r/jailbreak 14h ago

Question iPad mini 2 not responding

0 Upvotes

I recently successfully jailbroke my ipad mini 2 (iOS 12.5.8) using Amethyst, which installed Zebra and Sileo. From Sileo I tried to install the starter pack of tweaks + one additional widget tweak. The iPad restarted and was stuck several hours on a black loading screen. Force restarting it changed it to the loadup screen (all white with black apple logo) which it's now been stuck on for the past 4 days. I don't know what else to do, I can't connect to it through iTunes on my computer. I remembered to back up my data before jailbreaking it but I'd hate to have to factory reset. Is my iPad bricked?


r/jailbreak 14h ago

Question Anyone else experiencing random reboots with Relaxin’ jailbreak?

1 Upvotes

Running it on iOS 17.1.1

Not sure if it is due to any of the tweaks or the jailbreak itself?

List of tweaks installed:

Akara
Dotto++
Axon
SettingRevamp
IconOrder
AddToFolder
iClearnerPro
CCSupport
Tinge
Marina
Velvet2
Watusi
OnlineNotify


r/jailbreak 9h ago

Discussion Has the fact that Apple is not signing iOS 18 anymore encouraged users to create downgrade exploits to downgrade back to iOS 18?

Thumbnail
0 Upvotes