Link to this headingJailbreaking an iOS Device
Link to this headingInstalling Jailbreak Apps
- Visit this page to create a throw-away Apple ID. BE SURE TO ASSOCIATE THIS ACCOUNT WITH A THROW-AWAY GMAIL ACCOUNT THAT IS NOT TIED TO THE COMPANY.
- Download/install Cydia Impactor from here.
- Impactor takes care of properly signing and installing the target application onto the iOS device
- To install the app:
- Start Impactor
- Drag the target application IPA file (from GUI application, such as Explorer or Finder) into the Impactor window
- Enter the throw-away Apple ID credentials when prompted
- Navigate (on the iOS device) to Settings > General > Profiles or Profiles & Device Management and tap the profile listed with the email address associated with your Apple ID
- Choose “Trust [APPLE ID]” and tap through warnings
- Choose “Verify App” and tap through warnings
Link to this headingBootloader Jailbreaks
Link to this headingCheckrain (iPhone 5s-iPhone X, iOS 12+)
MAC and Linux:
checkrain Download
Link to this heading32-bit Devices
Link to this headingiOS 9 (before 9.3.5)
- Download the wall.supplies (Home Depot) jailbreak app from internal data store
- Follow the “Installing Jailbreak Apps” instructions
- Open the installed app and enable jailbreak (using “provided offsets”, if prompted)
- This is not a permanent jailbreak. If the device is powered off or rebooted, you’ll need to repeat step 3.
Link to this headingiOS 9.3.5
- Phoenix by tihmstar (TO-DO)
Link to this headingiOS 10
- h3lix by tihmstar and S1guza (TO-DO)
Link to this heading64-bit Devices
Link to this headingiOS 9.3.2-9.3.3
- Download the Pangu jailbreak app from internal data store
- Follow the “Installing Jailbreak Apps” instructions
- Open the installed app and tap the button to jailbreak
- Wait a few seconds and lock the device screen
- This is not a permanent jailbreak. If the device is powered off or rebooted, you’ll need to repeat steps 3 and 4.
Link to this headingiOS 10 (before 10.2.1)
- Download the Yalu jailbreak app from internal data store
- Follow the “Installing Jailbreak Apps” instructions
- IF YOU’RE USING AN iPAD MINI 4 DEVICE, YOU’LL NEED TO OPEN A LARGE PDF FILE BEFORE ADVANCING TO THE NEXT STEP. An example can be found here. Open this file on the device using Safari.
- Open the installed app and tap “go”
- If the jailbreak fails, the device may crash. In which case, you’ll need to reboot and try again. If the device does not crash, simply tap the “retry” button
- This is not a permanent jailbreak. If the device is powered off or rebooted, you’ll need to repeat steps 3 (if you’re using an iPad Mini 4) and 4.
Link to this headingiOS 11 (before 11.4)
Install command line apps in /electra to bypass the Sandbox execution policy
- Download the Electra Jailbreak app. https://coolstar.org/electra/
- Follow the “Installing Jailbreak Apps” instructions
- Open the Installed app and tap “jailbreak”
- This is not a permanent jailbreak. If the device is powered off or rebooted, you’ll need to repeat step 3-4.
- If the jailbreak app doesnt load up that means that the certificate that the app is signed with has expired and has to be resigned using the instructions in Installing Jailbreak Apps
Link to this headingiOS 11.0-13.3
Link to this headingRestoring iOS Versions with SHSH Blobs
Link to this headingDownload the Devices SHSH Blobs
This is the signed update information that makes the device trust the updater
Getting the information needed to download the shsh2 files:
Downloading the Latest SHSH files with the Erase Ticket:
Downloading the Latest SHSH files with the Update Ticket:
Downloading the Latest SHSH files with the Update Ticket with specifying the ap_nonce:
Link to this headingDownload the IPSW Update Package
This is the update package for the version of the iphone what would be used to download the Software Update from apple
This file can be downloaded from IPSW Downloads.
Link to this headingGetting the Nonce Information
The Anonce is the NONC that is shown below
Link to this headingSetting the Nonce Information
- Open unc0ver. (You may get a popup about an untrusted certificate, go to Settings > General > Device Management and Trust your certificate)
- Go to the Settings tab in unc0ver.
- Make sure “Overwrite Boot Nonce” is enabled and that “Boot Nonce” is set to 0x1111111111111111 or what ever is in the SHSH file.
- Go to the Jailbreak tab and press Jailbreak.
- You’re done with this part of the tutorial.
Link to this headingRestoring/Upgrading iOS Version
Restoring/Upgrading iOS Version:
Link to this headingBacking Up the iPhone
Setting a Backup Password (Optional):
Backing up the Device:
Link to this headingPackage Managers
Most Jailbreaks use Cydia as the package manager to install programs for the jailbreaked system.
Chimera Jailbreak uses Sileo