iOS Jailbreak (iPhone, iPad, iPod Touch, Apple TV)

46 readers
1 users here now

We stand in solidarity with numerous people who need access to the API including bot developers, people with accessibility needs (r/blind) and 3rd...

founded 2 years ago
MODERATORS
276
 
 
This is an automated archive made by the Lemmit Bot.

The original was posted on /r/jailbreak by /u/Stunning_Ocelot7820 on 2025-05-28 21:28:32+00:00.

277
 
 
This is an automated archive made by the Lemmit Bot.

The original was posted on /r/jailbreak by /u/LunaAzure on 2025-05-28 14:20:40+00:00.

278
 
 
This is an automated archive made by the Lemmit Bot.

The original was posted on /r/jailbreak by /u/MediumContributi0n on 2025-05-28 06:02:39+00:00.


So with the APAC decoder (CVE-2025-31200) bug, it seems the developer working on the POC has managed to achieve an arbitrary write and has made a pull request around 20 minutes ago to add the new changes! Who knows if it’ll prove to be useful for jailbreak or not but nonetheless it’s still cool, thought people would wanna check it out :)

https://github.com/zhuowei/apple-positional-audio-codec-invalid-header

Edit: changed the URL as the branch has now merged to main :)

279
 
 
This is an automated archive made by the Lemmit Bot.

The original was posted on /r/jailbreak by /u/Jdm965 on 2025-05-27 19:52:55+00:00.

280
 
 
This is an automated archive made by the Lemmit Bot.

The original was posted on /r/jailbreak by /u/Mineking0115 on 2025-05-27 16:41:44+00:00.

281
 
 
This is an automated archive made by the Lemmit Bot.

The original was posted on /r/jailbreak by /u/iPhone_modder on 2025-05-26 10:31:10+00:00.


I have confirmed that all tweaks that ZeroCalorie app does has been enabled.

Home-bar is gone, and removed few blurs, then added a respring app. Looking good! 😌

Since the exploit only runs in memory hence once you restart you will need to enable your tweaks again. Which isn’t a problem as it takes less than 1 min for that. Enable tweaks and then respring.

Procedure followed :

1). Took iTunes backup -encrypted

2). Downgraded to iOS 18.3 RC as still being signed so do it now if you all want to…

3). Supervised device and moved to iOS 18.3.2 (latest iOS where the tweak work— Delay OTA . Tweaks will NOT work after 18.3.2. So you can stay at iOS 18.3 if you want. I wanted to be the on the last latest firmware update).

4). Removed Supervision after iOS 18.3.2 OTA update.

5).Restore backup.

I do have certificate so I was able to reinstall all my apps (side loaded) app very easily after backup restored as iTunes will not restore sideloaded apps, but will restore its appdata which was nice! 😊

If you want to try some new tweaks definitely downgrade while the iOS 18.3 RC is still signed.

Tweak https://github.com/C4ndyF1sh/ZeroCalories/releases/tag/0.3.1

Or

https://github.com/GeoSn0w/iDevice-Toolkit/releases

iOS 18.3RC

https://ipsw.dev/product/iPhone

Original Reddit post!

https://www.reddit.com/r/jailbreak/comments/1kqo278/guide_downgradeupgrade_to_1832_for/

EDIT—-

To restore higher iOS backup to lower iOS I.e from iOS 18.5 to iOS 18.3.1 follow this process

Make sure you make a copy of the backup and keep it in another safe place on PC hard drive so that if plist method — corrupts your backup you still have another copy saved .. this is just a precaution.

https://www.reddit.com/r/iPhoneXR/comments/1gl66mb/downgrade_ios_18_to_ios_17_guidesigned/

282
 
 
This is an automated archive made by the Lemmit Bot.

The original was posted on /r/jailbreak by /u/canadadry7799 on 2025-05-25 17:01:25+00:00.

283
 
 
This is an automated archive made by the Lemmit Bot.

The original was posted on /r/jailbreak by /u/PlentySignificant943 on 2025-05-25 10:38:23+00:00.


https://github.com/kekeimiku/LuckySpeeder

Demo Video: https://github.com/user-attachments/assets/7937883f-74ab-450e-8a96-cf7ce4b8da43

284
 
 
This is an automated archive made by the Lemmit Bot.

The original was posted on /r/jailbreak by /u/mahmood1999 on 2025-05-24 15:12:59+00:00.

285
 
 
This is an automated archive made by the Lemmit Bot.

The original was posted on /r/jailbreak by /u/TM6008 on 2025-05-24 13:45:19+00:00.

286
 
 
This is an automated archive made by the Lemmit Bot.

The original was posted on /r/jailbreak by /u/sahilscraft on 2025-05-23 17:43:01+00:00.

287
 
 
This is an automated archive made by the Lemmit Bot.

The original was posted on /r/jailbreak by /u/Timeclock949 on 2025-05-20 18:47:16+00:00.

288
 
 
This is an automated archive made by the Lemmit Bot.

The original was posted on /r/jailbreak by /u/it_again on 2025-05-20 16:36:33+00:00.


Are we back in the untethered game!! This is awesome. Super hopeful.

iOS 14 about to make its resurgence.

https://x.com/alfiecg_dev/status/1923076832645075276

What are some iOS 14 compatible tweaks you like? What are new tweaks that are > iOS 15 that you would like seen ported?

289
 
 
This is an automated archive made by the Lemmit Bot.

The original was posted on /r/jailbreak by /u/Kitchen_Ad494 on 2025-05-19 21:40:08+00:00.


As you may already know, there’s an exploit affecting iOS versions 16.0 through 18.3.2 that can zero out files.

This exploit is not useful for jailbreaking, but it does enable some basic tweaks.

Here are a some apps currently available that make use of this exploit:

Guide to upgrade or downgrade to iOS 18.3.2:

  1. Download and install the iOS 18.3 RC IPSW for your iPhone from: https://ipsw.dev/product/iPhone
  2. Supervise your device.
  3. Use the DelayOTA profile to update from iOS 18.3 RC to iOS 18.3.2: https://dhinakg.github.io/delayed-otas.html
  4. Remove supervision.

That’s it — your device should now be running iOS 18.3.2.

290
 
 
This is an automated archive made by the Lemmit Bot.

The original was posted on /r/jailbreak by /u/WeekendSad1115 on 2025-05-18 18:31:44+00:00.

291
 
 
This is an automated archive made by the Lemmit Bot.

The original was posted on /r/jailbreak by /u/Commercial-Pause-917 on 2025-05-18 04:24:36+00:00.


https://github.com/Akuma1tko/ChatGPT-WebView/releases/tag/v1.0.2

Tip jar: cash.app/$modigitss

I put together a lightweight iOS app that acts as a dedicated wrapper for ChatGPT’s web app using WKWebView. The project is now up on GitHub for anyone to clone, tweak, or install manually.

After OpenAI sunset (murdered) version 1.2024.200, I had enough. Safari sucked, Add to Home Screen wasted space, and 3DAppVersionSpoofer didn’t work. The TrollDecrypt .plist edit method doesn’t work on <16.4 either.

⚠️ What it’s not:

This isn’t optimized for loading heavy chats with tons of images, zip files, or long histories. Those can still bog down due to WKWebView limitations — so don’t expect full app-level performance on those. This is best used for snappy, on-the-go prompts.

🔧 Features:

• Spoofs the native app’s user-agent to bypass restrictions

• Preserves login sessions via persistent cookies

• Dark mode support

• Launch screen and App Icon included

• Xcode + manual install friendly (no Apple Developer Program needed)

• TrollStore compatible (tested)

💬 Suggestions and contributions welcome!

This is meant to be a foundation. If you’re a dev who knows how to speed up WebKit rendering or cache control, I’d love to see forks that push this further.

Hope this helps someone out. It’s been frustrating having no good ChatGPT access on iOS 16, so this is at least a stopgap.

Update 1: Sorry for the accidental clickbait. I built it for iOS 15 but didn’t have a device to test on, so I didn’t realize the layout breaks due to older WebKit/CSS rendering (like flexbox issues). Looks like it’s really an iOS 16+ build for now. I’m working on a proper iOS 14–15 workaround though. Appreciate everyone reporting issues.

Update 2: After speech-to-text was confirmed stable, voice mode is now fully functional in this latest build.

⚠️ Hold-to-Speak is still in progress Currently working on restoring the classic "tap and hold" behavior to trigger speech input. Right now, voice mode functions as a tap-to-start interaction only no crashes, just limited UX until I finalize a workaround.

292
 
 
This is an automated archive made by the Lemmit Bot.

The original was posted on /r/jailbreak by /u/saratikyan on 2025-05-18 01:21:10+00:00.

293
 
 
This is an automated archive made by the Lemmit Bot.

The original was posted on /r/jailbreak by /u/Dangerous-Big3125 on 2025-05-17 12:04:32+00:00.


Kernel Crash on iOS 18.3.2, This Might Actually Mean Something

I just came across a kernel panic log from an iPhone 11 Pro running iOS 18.3.2 (build 22D82), and it looks very promising. This isn’t just some random crash, the log shows a failure in CPU 5 tied to a kernel static region, which could mean there’s a real vulnerability here.

What makes it even more interesting is that this crash happened on a clean, untouched device. No jailbreak, no modifications, just straight-up iOS. That’s pretty rare.

The log points to an instruction at 0xfffffff0180a2878, which is deep in kernel-level code. That’s exactly the kind of spot attackers look for when trying to find a way to gain root access.

Also, for the curious: the device was running iBoot version 11881.80.57. That info could be useful if someone wants to reproduce the issue or build a tool around it.

Some folks are speculating it might be a use-after-free bug or a buffer overflow, either one would be a big deal. Nothing confirmed yet, but it’s definitely worth watching.

TL;DR: This could be the start of something big for iOS 18.3.2 jailbreakers. Maybe not today, maybe not tomorrow, but this kind of crash doesn’t just happen for no reason.

294
 
 
This is an automated archive made by the Lemmit Bot.

The original was posted on /r/jailbreak by /u/theNoah_99 on 2025-05-16 15:37:47+00:00.

295
 
 
This is an automated archive made by the Lemmit Bot.

The original was posted on /r/jailbreak by /u/TypicalLab7370 on 2025-05-16 08:26:17+00:00.


so basically opa334 appeared on nullcon goa basically said there is no hope for jailbreaks for iOS 17,18 or anything after unless you are on a checkm8 exploitable device (eg. a7-a10x i believe) there is almost no hope. So goodbye r/jailbreak I will see you in a few years to see where things are by then. Also link to the YouTube vid https://youtu.be/lU2lxGtLN6k

EDIT:if you are on a newer device above ios 17 check out the sideloaded community

296
 
 
This is an automated archive made by the Lemmit Bot.

The original was posted on /r/jailbreak by /u/Faezan on 2025-05-15 09:48:51+00:00.


Seeing Tateu around made me really happy. And there is no update post so I took this opportunity to post it also thank the OG dev /u/Tateu.

You can find his tweak in his Repo: https://tateu.net/repo/

Tweak description: https://www.tateu.net/repo/html/?p=moorebarx15

297
 
 
This is an automated archive made by the Lemmit Bot.

The original was posted on /r/jailbreak by /u/sigjnf on 2025-05-14 10:16:02+00:00.

298
 
 
This is an automated archive made by the Lemmit Bot.

The original was posted on /r/jailbreak by /u/CoolstarLikesHentai on 2025-05-13 04:55:27+00:00.


Since someone was asking about this, and there is no official guide that has everything available all in one place, I thought I'd make this post.

  1. Download Sideloadly on your computer.
  2. Install TrollStore on your iPhone using Sideloadly.
  3. Download RootHide BootStrap .tipa on your phone. Use the ReadMe (archived) to learn how to use.
  4. Enjoy tweaking. Use RootHide Patcher from the Roothide repo (https://roothide.github.io/) on Sileo or Zebra tweak manager to patch any arm (rootful) or arm64 (rootless) tweaks you want to arm64e (rootless-roothide). For rootful tweaks, you will have to use Derootifier for arm (rootful) tweaks first, and then RootHide Patcher afterwards. Just can’t change SpringBoard, which I never cared about after turning 16 lol. You also don’t really have to worry about any jailbreak detection. When installing Filza (thru TrollStore), just make sure to download the “No URL” version from tigisoftware’s website.
  5. If you want to change SpringBoard, use MisakaX or Nugget. Or install Serotonin.

Optional

  1. Install Serotonin alongside RootHide BootStrap using TrollStore. It has SpringBoard injection.
  2. Use NathanLR instead. I've never used it, but it is much easier to use if you don't know exactly what you're doing. You don't have to convert any rootless tweaks, only rootful one's with Derootifier, and you can inject tweaks into SpringBoard and System Daemons. Here's a guide on how to install it.
299
 
 
This is an automated archive made by the Lemmit Bot.

The original was posted on /r/jailbreak by /u/Jealous-Sale-1331 on 2025-05-13 02:04:23+00:00.

300
 
 
This is an automated archive made by the Lemmit Bot.

The original was posted on /r/jailbreak by /u/opa334 on 2025-05-13 11:46:56+00:00.

view more: ‹ prev next ›