downgraded my XR from 18.7.9 to 17.0, unsigned. Tether booted, real activation, and jailbroken and sep two majors newer. 17.0's kernel asks the sep for a special bag it can't grant and hard panics, so i patched it to ask for one it can. also patched relaxin's libxpf myself when it choked on my kernelcache.
needs to be recreated on the xs now.
Jailbreak IOS 27? Sileo and bootstrap fully installed running on iOS 27,
After some late-night debugging success!
Used same like usbliter8-fun base with key fixes to get it booting cleanly.
Credit goes @wh1te4ever
Photos credit @Little_34306 🤝
I’ll be sharing a detailed tutorial soon to help the community. 👀
Uhh so I just found a sandbox escape that lets you edit MobileGestalt on iOS 27, thanks to GPT-5.6 Sol Ultra. Not a drill! Evidence is Dynamic Island on an iPhone 11. Nothing to do with usbliter8 – done entirely from a sandboxed app. Maybe hold until 27 is public?
🔒How to recover the PIN before first unlock? We found a new path and talked at #POC2025 and #QPSS26 .
📒Here is the detailed blog: https://t.co/NzVBvHUxJ7
THIS DOES NOT SEEM TO BE A DRILL
A BOOTROM EXPLOIT FOR A12, A13, S4/S5, AND A12X/Z (UNTESTED)
HAS BEEN FOUND AND RELEASED
https://t.co/NpHzMCAE8R
https://t.co/LUgJZTldqP
#jailbreak#ios#a12#a13#checkm8#iphone
Here is my little article about Apple SNR & UDT firmware patches that allow you to use them as Kanzi & Chimp
THIS KNOWLEDGE IS POTENTIALLY DESTRUCTIVE, BE CAREFUL WITH WHAT YOU ARE DOING
https://t.co/K5RQ7DWp56
Automatically intercept all YOUR HTTP/HTTPS network Traffic with 1 click in Any iOS✨
- 3 lines of Swift/URLSession hook
- No proxy/cert on iOS, ZERO config
- Any HTTP client (URLSession default)
- Full WebSocket (URLSessionWebSocketTask)
- Bonjour/mDNS
Socket 1.2 (by staturnz) has just been released, switching the kernel exploit to oob_entry (100% reliable, should never fail), as well as adding a patch to nuke sandbox and updating the default repositories/Zebra
Download: https://t.co/5mHJ7fjMnG
Guide: https://t.co/DHF9Vhjivu
Here's the vphone-aio for anyone cannot setup. I uploaded the whole VM into github so maybe cloning it might take a while.
Follow the steps to run it. Also the VM already included rootless jailbreak environment and a few tweaks on it.
https://t.co/YfsFLAcxc0
Finally got this virtual iPhone running iOS 26.1 up and running on macOS. It's jailbroken and going to help with security research a ton. Big thank you to @wh1te4ever for this.
This is not for the average user and is complicated to set up. Highly recommend Codex and/or Claude to assist.
For those interested, the project is here:
https://t.co/ygp2iV8kuv
And the writeup is here:
https://t.co/WaYM6QiFLD
I have posted a write-up for those who are interested in building virtual iPhone.
If have any further questions, please feel free to reach out via DM, Thanks.
https://t.co/YRTlxbKNKb
The pccvre tool, which is Apple Private Cloud Compute Virtual Research Environment tool for Apple Intelligence, now displays PCC Agent Worker and PCC Agent