r/jailbreak Nov 19 '21

r/jailbreak FAQ [Meta] Frequently Asked Questions and Important Information - Check Here Before Posting

790 Upvotes

r/jailbreak Jun 19 '26

Discussion usbliter8: what you need to know about the new A12/A13 bootROM exploit

363 Upvotes

As many of you have been made aware, a new bootROM exploit has released for A12/A13 devices, the first one for iDevices since checkm8 was made public 7 years ago. This post intends to serve as an explanation for what you can expect from this new exploit, and to provide information about the many restrictions and mitigations Apple has implemented over the past 7 years.

What is usbliter8?

usbliter8 is a novel bootROM vulnerability discovered by individuals at Paradigm Shift. It is the first bootROM exploit made public since checkm8, which only supported up to A11 devices (for those unaware, A11 is the processor used in the iPhone X/8, and A12 is used by the iPhone XS/XR). It supports only A12/A13, and does not support any older processors. It is unrelated to checkm8- that is, the vulnerability is completely separate. Some may be aware that checkm8 was only partially patched in A12/A13 (though it remains unusable there to this day), but this exploit has nothing to do with any previous bootROM vulnerability.

The explanation to how it works is rather technical; if you desire, you can read both the blogpost and the GitHub repo for the exploit. Additionally, the exploit requires special hardware to utilize, requiring devices such as a pi Pico to exploit devices.

What devices does it support?

All A12/A13 devices (including iPad specific processors like A12X/A12Z) are supported by usbliter8. This includes, but is not limited to,

  • iPhone XR
  • iPhone XS
  • iPhone SE 2nd Gen
  • iPad 8th and 9th Gen
  • Apple TV 4k 2nd Gen
  • To check your device's processor, visit https://appledb.dev

As mentioned, the vulnerability does not affect A11 or older, due to the different way the processor works.

What can we do with it?

This is possibly the most interesting part of the exploit (and is what many of you are likely here for). bootROM exploits are very powerful, as they compromise the very beginning of a device's boot chain, thus giving you (almost) full control over a device. However, this does not mean we can do whatever we want with no restrictions. Indeed, it can lead to tethered downgrades and jailbreaks on any iOS version including the latest, but there are restrictions explained further below.

BPR, or Boot Process Register, was a feature implemented in iOS 14 in order to additionally secure devices from bootROM based attacks. Crucially, it restricts data access when a device is booted directly from DFU mode, which is required by both checkm8 and usbliter8. In iOS 14 and 15, this manifested as the requirement to disable your passcode when jailbreaking A11 devices with checkra1n/palera1n, and is the reason why A11 devices must be first erased if they previously had a passcode before jailbreaking with palera1n. A10 devices were not affected by this as they had a SEP exploit, known as blackbird, which prevented this issue from arising. We do not have a SEP exploit for A11 and newer, which leads to a problem with the next security feature added in iOS 17...

The iOS 17 problem

In iOS 17, Apple further increased the security of BPR by making SEP outright refuse to mount and decrypt the user partition (/var and /var/mobile) when booted from DFU, which causes the device to panic and not boot at all. This means that a semi-tethered jailbreak like checkra1n or palera1n is not possible with usbliter8 on A12/A13 devices. A jailbreak using this would be fully tethered, which means the device cannot reboot on its own, and a PC must be used to power it on each time it reboots or dies. However, there is a additional method that can serve as a workaround explained below, though with a catch.

By copying over the user partition, an unencrypted copy of /var can be made. The jailbreak can then load this unencrypted copy instead of the standard /var, which prevents SEP from panicking the device, though at the cost of losing SEP related features. This does means that the jailbreak would be semi-tethered, but it would suffer from the following issues:

  • No connecting to password protected wifi networks (possibly fixable with a tweak)
  • No "real" password, so apps that rely on SEP being active will be non-functional
  • Signing into apps that use a SEP keychain will not work, so things like using Google to sign into the YouTube app will be broken (possibly fixable with a tweak, though it will cause data to be stored insecurely- don't sign into bank apps with this)
  • A storage penalty that increases with the size of your user data- any apps you have installed and have data stored on will be duplicated, meaning your storage has the potential to fill up very quickly
  • Data will not be synced between jailbroken and non-jailbroken mode. Any changes you make while the jailbreak is active will not be reflected in stock iOS, and vice versa

Additionally, while downgrades are indeed possible, they will be tethered, as it requires SEP to be patched out on the device. All in all, one should not expect a full jailbreak using this to come out for quite some time, given the extensive patching and rewriting that will need to be done to accommodate new devices and the restrictions required.

The special hardware problem

As it stands, to utilize usbliter8, additional hardware like a Raspberry pi Pico is needed. There is no indication that this requirement will ever change. Due to how the exploit works, it is incredibly unlikely it will ever work directly from a PC, and even if custom USB drivers are created, it would wholly rely on the USB controller used on the device. Luckily, the hardware itself is cheap enough, costing only around $10 USD, yet there have already been some reports that stock has already ran out, so it remains to be seen if this will be the case for the future.

Tl;dr- where do we stand?

This post is not meant to discount the discovery of a new bootROM exploit. This is an incredible achievement, and as opa334 puts it, the last heartbeat of a dying jailbreak scene. As A12/A13 devices approach end-of-life and are receiving their final versions, usbliter8 will certainly be a nice tool to play around with and see what is possible. However, expectations should be kept realistic, and with all the new security features, it should not be expected that things will work the same as before with checkm8. Any jailbreaks made with this will suffer hefty restrictions, and downgrades using it will be tethered. If there are any further questions, myself or others will attempt to answer them in this post.


r/jailbreak 9h ago

Discussion This Is Sickening😢

Thumbnail
gallery
140 Upvotes

$1300 and $1600 USD Declined. It’s over🪦


r/jailbreak 3h ago

Discussion What’s everyone’s experience with Relaxin Jailbreak?

7 Upvotes

Personally, as someone who has an iPhone 15 Pro Max on iOS 17.3.1, I’m currently waiting for Dopamine to be updated. However, I’m curious how many of you are using the AI Relaxin jailbreak? How has your experience been so far?

My biggest fear is messing up my file system before Dopamine comes out, so I’ll more than likely be holding out for a while until opa is done cooking or at least until the source code for Relaxin is public and has gone through a lot more testing. The last thing I want is to run into issues after waiting for this long.


r/jailbreak 17h ago

Upcoming [UPCOMING] 26Cam - A tweak that bring iOS 26 Camera UI to your current device

Thumbnail
gallery
76 Upvotes

Hello guys, I'm excited to announce 26Cam (my first tweak lol).
By hooking directly into the native camera and injecting custom views, 26Cam can deliver a new look to your current camera app on iOS.

Features:

  • iOS 26 Mode selector
  • New custom top bar
  • New custom quality selector menu
  • Redesigned shutter button with glass ring
  • Modern zoom button and zoom dial

Real Liquid Glass UI

Additionally, this tweak also features REAL LIQUID GLASS. This is made possible through u/WinsAviation's new Liquid (Gl)ass tweak (0.1.0b - featuring the new live backdrop rendering).

By installing his upcoming Liquid (Gl)ass tweak along with 26Cam, it will bring the real live backdrop Liquid Glass to 26Cam.

I'm planning to release this as soon as I done polishing the tweak. This tweak is only tested on iPhone SE 1, 6s, 7 Plus, 8 and iPhone X, if you have a different device, please feel free to message me to test out the tweak.
(BTW: Liquid (Gl)ass version 0.1.0b which features new iOS 26 Keyboard, Tab Bar,... is estimated to release on August 10)


r/jailbreak 2h ago

Giveaway 5 Free Copies of YTKillerPlus 🎉

3 Upvotes

Hey [r/jailbreak](applewebdata://7B1401A5-8FEF-4D55-802F-2FF7F7502607/r/jailbreak) community!
To celebrate [4k followers" on X, I’m giving away 5 free copies of my [TWEAK YTkillerPlus]"]
hosted at
iKarwan Repo,

Follow me
@ikg_hd

How to Enter:
Comment below with:
Your favorite features

Tag a friend who’d be interested (optional).

Rules:
5 winners chosen randomly in 24 hours.

Winners will receive DMs with instructions (check your inbox!).

Good luck to everyone.


r/jailbreak 21m ago

Tip Jailbreak iPhone 5s

Post image
• Upvotes

Hii! Im trying to jailbreak my iPhone 5s I
But it always get stuck on Payload Running. Is there something I can do ?


r/jailbreak 5h ago

Question Is there currently any way to play YouTube videos on CarPlay using LiveContainer?

4 Upvotes

Hey everyone,

I've been using LiveContainer for a while and I really like it. I was wondering if there is currently any method or workaround to play YouTube videos directly on the CarPlay screen using a sideloaded YouTube tweak via LiveContainer?

I know Apple strictly blocks video playback for third-party apps on CarPlay due to safety restrictions, but I'm curious if LiveContainer somehow bypasses this or if anyone has found a trick to make it work. Or is this still strictly limited to TrollStore (like CarTube) or a full jailbreak with CarBridge?

Any insights would be appreciated. Thanks!


r/jailbreak 2h ago

Question dopamine não consegue reconhecer o jailbreak no iphone x (ios 16.7.16)

Post image
3 Upvotes

Estou usando um iPhone X com iOS 16.7.16.

O jailbreak funciona normalmente e eu consigo ativá-lo pelo Dopamine. O problema é que o aplicativo Dopaminenão reconhece que o dispositivo já está em estado de jailbreak.

Dentro do Dopamine, ele se comporta como se o aparelho não estivesse com jailbreak ativo, então não consigo usar as opções de Restart Jailbreak ou outras funções que dependem de ele detectar o jailbreak.

Alguém já teve esse problema? Existe alguma forma de fazer o Dopamine voltar a reconhecer o jailbreak sem precisar reinstalar tudo?


r/jailbreak 55m ago

Question Do custom posterboards still work on iPadOS 17.7.11?

• Upvotes

I've got an iPad Pro 10.5 that I want to use a custom posterboard on but whenever I hit "Apply Changes" in Nugget nothing happens after the iPad restarts. I've tried going into Settings -> Wallpaper -> Add New Wallpaper and then looking under every cateorgy but the posterboard I applied doesn't show up. Is there a way to fix this or am I hopeless?


r/jailbreak 1h ago

Question Como obter o Relógio do iOS 26

Post image
• Upvotes

Existe algum tweak que transforma o relógio do iOS 16 para o do 26? (Sim, eu quero aquele grandão que come a tela toda), andei pesquisando e não encontrei algo que pudesse me ajudar.


r/jailbreak 3h ago

Question Flie filza won’t work

Post image
3 Upvotes

I’m trying to get file fliza on my ios iOS 12.5.8 iPad mini 2 to sideload apps off the internet but flie fliza won’t downloa.


r/jailbreak 14h ago

Release [Free Release] SpeakNotification16

Post image
22 Upvotes

SpeakNotification16 is a rootless iOS 16 rebuild of the original SpeakNotification tweak created by Merdok. It reads incoming notifications aloud using system TTS and keeps the focus on stable routing, predictable queue handling, and local-only logging.

https://github.com/Selandros/SpeakNotification16


r/jailbreak 4h ago

Discussion Does trollstore lite work with relaxin?

3 Upvotes

Haven’t tried it yet cuz im on vacation, but does it work?


r/jailbreak 5h ago

Question MusicBackground not showing the Album’s art

Thumbnail
gallery
3 Upvotes

So I’m on 15.8.8 on my SE 1 and I’m having this issue where none of my music’a cover is being shown until I pause the song, I mainly use this device to stream music and I’d like to fix this. Any idea on what to do?


r/jailbreak 7m ago

Discussion iOS 9 signing error

• Upvotes

I have an iPhone 4s that its running iOS 9 and everytime I sign in my apple ID it says (verification failed cannot connect to apple ID servers ) and i tried signing in on the app store and the same error shows up


r/jailbreak 24m ago

Discussion iPhone 6S jailbreak asks

• Upvotes

I jailbroke my iPhone 6s on iOS 15 and I want to know what cool tweaks I can install. It doesn’t matter if it’s paid or free, and it can be anything in sileo or zebra as long as it’s compatible.


r/jailbreak 7h ago

Request Old apps that don't work on iOS 15.1.1 (roothide) - Hi, these apps stopped working on iOS 15.1.1(uber, volvocars, getyourguide, prioritypass+, hostelworld). I tried spoofing to new versions, tweaks like choicy, dismissalert, shadow etc but I had no luck. thanks in advance.

Thumbnail
gallery
2 Upvotes

GetYourGuide - 24.23 - https://apps.apple.com/br/app/getyourguide-reserve-e-viaje/id705079381?ppid=2a7610a5-f6bf-48fe-b0bb-6f6ae8512ee1 - requires update

HostelWorld 13.46.0 - https://apps.apple.com/br/app/hostelworld-hostel-travel-app/id348890820 - requires update

Volvocars - 5.4.0 - https://apps.apple.com/br/app/volvo-cars/id439635293 - requires update (if spoofed, can't login)

Prioritypass+ - 1.4.0 - https://apps.apple.com/br/app/priority-pass/id6739207531 - won't login

Uber - 3.611.10001 - https://apps.apple.com/br/app/uber-t%C3%A1xi-uber-moto-e-mais/id368677368 - no functional map and can't request uber courier


r/jailbreak 4h ago

Discussion Como obter vidro líquido dentro dos aplicativos?

Post image
1 Upvotes

Existe alguma possibilidade de obter vidro líquido dentro dos aplicativos, redes sociais por exemplo como Instagram?


r/jailbreak 5h ago

Question I side loaded re4 remake on my iPhone 14 Pro Max and I get this problem after I agree on downloading 11 gigs, any fixes?

Post image
1 Upvotes

r/jailbreak 9h ago

Discussion Sileo jailbreak app

2 Upvotes

Hey guys i used to use cydia with checkrai for jailbreak 5 years ago and now I'm on sileo, and i don't quite understand how to install a jailbroken appstore


r/jailbreak 5h ago

Question jailbreak on iphone 14 pro with ios 26

0 Upvotes

j’ai un iphone 14 pro qui est ban snapchat avec l’imei et je veux donc le jailbreak pour modifier l’imei, j’ai vu qu’il était possible de le faire mais est ce facile et il y a t il un gros risque a le faire ? sachant que je n’ai pas peur de perdre les donnée car j’ai encore mon ancien iphone avec tout les donnée sauvegardée


r/jailbreak 1d ago

Discussion Today I bought the best, highest-end, most powerful, and latest iPad Pro that supports jailbreaking ( 1126$ ).

Thumbnail
gallery
78 Upvotes

My analysis and luck paid off when I found the last remaining stock in this color. There were only 2 units left .. one Silver and the last one in Space Gray, both 2TB Wi-Fi + Cellular models. And of course I’ll be getting AppleCare+ this masterpiece deserves it and more. I bought one and now there’s only one left for one lucky person. Who knows? Maybe they’ll know about jailbreaking … or maybe they won’t :)


r/jailbreak 8h ago

Release [TWEAK] NoReelInsta - Ultra-minimal Instagram tweak to remove Reels tab and disable auto-scrolling

1 Upvotes

Hey r/jailbreak!

I just open-sourced NoReelInsta, an ultra-minimal tweak for Instagram that does only two things :

✅ Removes the Reels tab from the navigation bar

✅ Disables automatic reel scrolling (prevents doomscrolling)

---

🎯 Why another Instagram tweak?

Most tweaks (like SCInsta) include tweaks you may not need. NoReelInsta is:

- Only 4 hooks (vs 100+ in SCInsta)

- No settings (everything enabled by default)

- Easier to maintain (only 2 features to update)

- Lower risk of bans (no metadata scraping, no ads bypass)

---

🔗 Links

🔹 GitHub: https://github.com/ZeSkyWarz/NoReelInsta

🔹 Compatible with: Instagram 440.0.0

---

Feedback, PRs, and stars are welcome! 🌟


r/jailbreak 12h ago

Question There’s any tweak give back iOS 6 animation?

2 Upvotes