#palera1n
1 messages · Page 83 of 1
you are forgeting one key detail: We are exploiting the bootrom for testing'
if you have a new bootrom exploit then you are sitting on something worth thousands of dollars
those are not common
right now we are testing with the current bootrom exploit aka the exploit palera1n as some of us have devices that are below a12
the current bootrom exploit cannot be exploited untethered
it is a tethered exploit
even if you bypass the signing checks with it, you cannot boot the os without a pc
did I not mention saying that shsh blobs are only requested during install
you are misunderstanding how the process works
the bootrom verifies the installed apticket every time the device turns on
then the device wont boot if I forgot to update simple as that
no?
why would that be the case
when you flash a firmware that blob is “converted” into an apticket, which is stitched into the firmware
BUT THEN AGAIN ITS NOT DONE AFTER THE FIRMWARE IS INSTALLED
wouldnt we able to grab the stiched apticket
palera1n support ios 16.7.10?
If the device is supported yes
do you have a device that supports palera1n
like this exploit is only for specific devices which is not decided by version
like my device is a A10 device so its supported
iphone 8
thats a supported device no matter the version
my jailbreak doesn't work for some reason
do you have a password on
no
did you turn it off
password should not matter for iphone 8
16.7.10
apple pay
thats only for a11 devices
which is the iphone 8
its only for a11 devices like iphone x
a8 I think
the iphone 6 is a8
I think you mean iphone se
the icon does not appear
the se1 is a9
one sec
did you remove a passcode
yes
did you reset the phone after
no
I dont think its required
if you try the jb won't appear
lol
I want to make sure something
bros got an sep bypass for a11
nooooooooooooooooooooooo I think you are confusing it with the iphone se
bro
reset settings
not work reset settings
did you do factory reset
whyyyyyyyyyyyyyyyyyyyyyyyyyy
jailbreak
oh by the way while I was anylzing how ipados installation worked I noticed something I am sending the file now
tf do you know that the p1 team doesn't
i'd like to hear
cause I did not check wether the iphone 8 is actualy a11 or not
appledb.dev
not work
what doesn't work
WORK
it works?
idk
what
you can restore a backup without a password
since you said you removed it before you reset, if you backed up then you could restore that
and then what
i have to ask, are you aware of how private key cryptography works?
that is the underlying concept behind firmware signing and installation and fundamentally you have to understand that to even consider exploiting the downgrade process
they dont understand anything
we’re all here to learn
Anybody have an A10x iPad Pro running iPadOS 17.x? I have a few questions.
what's your questions
Does the small swipe keyboard lag on this hardware on iPadOS 17? The swipe keyboard works great for me on iPadOS 14.3, but my iPad 9 on 17.0 has keyboard lag that it didn’t have on iPadOS 15.4. And I don’t know if the difference is the RAM, or the whole 17.0 being kinda shit. I’m considering getting a battery replacement unit for my 10.5 iPad Pro, and I expect it will come with 17.x
Also, is PaleRa1n pretty stable? How often do you have to reboot?
i'd say its more stable than even dopamine with physpuppet or other low success rate exploits
physpuppet has a high success rate
tbf most issues can be blamed on kfd as a base rather than the actual exploit themselves
(but also inherently, a checkm8-based jailbreak will be more stable than any semi-untether)
ok but its worse than landa
false
physpuppet as a bug is amazing (and also only 8 lines)
like it's basically a slightly worse sockpuppet (which was essentially the best vuln we've ever had)
a lot of it comes down to this
So I was banned in the palera1n server... idk why I can't think of anything I did, if some mod for Palera1n could tell me at least why I was banned, and if theirs a way/chance of me to apeal.. (DM me then ping me here pls)
I sent @shut stone a DM about it, but his about me says he doesn't read DMs requests and to ping him, I've been waiting for him to come online for like a week now bc I don't want to like disturb him if he's not on, but I think he's always invisible...
unbanned (you got banned for raid phrase)
oh lol, thanks!
are there any videos i cant watch to jailbreak with paler1n i have iphone x i have mac, every adapter i keep running into issues with this step (Run palera1n -l
Make sure your device is plugged in when entering this command
When ready, press Enter and follow the on screen instructions to enter DFU mode) no instruction pop up and instead a pop up tells me to restore and update my iphone, if anyone can help and guide me through there is bread in it for you lmk ty
bruh I anlysed the firmware install and the device only goes once in dfu mode
that doesnt change any part of what i said
still if the installation is not verified by apple after installation thats techincly why this exploit could work
Its just that there is no pe that uses this exploit
it is though
i said before, every single time you turn the device on it verifies the apticket installed on the system
but I have noticed that the apticket is first sent to the client and then to the deivce for some reason
though that descovery has been made and thats how tsssaver works
except that's not a downgrade exploit
we can't create our own blobs or apticket, we can only save for signed versions
except for the fact that the verification happens at the bootrom level which is exploitable for A11 devices and below
and if the apticket is stiched to the os woudnt it be valid still
yes, a tethered bootrom exploit
we already have ways to bypass the firmware signing check on certain checkm8 devices, but you need a pc to turn on the device
!t blobsfaq
What's a blob?
They're like golden tickets, but instead a digital signature made by Apple that was saved at the time when the signing window was open. If you possess one (or many), keep them safe.
How do they work?
They can be used in a program called futurerestore to restore to a firmware in which the SEP/Baseband is compatible. To check SEP/Baseband compatibility, check /tag sepbb.
Make sure to not use misleading sites. Stick to reputable sites like ios.cfw.guide and AppleDB.
Regardless of SEP/Baseband compatibility, any/all blobs should be saved for future downgrading abilities.
Can I use other people’s blobs?
No. Blobs are a file containing a special key specifically for that one device to allow downgrading to a specific firmware. Due to the way they work, only Apple can create them for your own device.
Can I save them now?
In general, yes. Blobs can be saved at any time, but it is crucial to save them when Apple releases new firmware, because they can only be saved for versions that are currently signed. There is one exception to this: if you are jailbroken and Apple has unsigned the version you're currently on, you may save onboard blobs for that version.
but the bootrom exploit give you root access to the device right?
it lets you exploit the device on boot, but that doesn't mean the changes are persistent
DOESNT THE BOOTROM EXPLOIT GIVE ME ROOT ACCESS TO THE DEVICE
again the changes are not persistent
there's a whole chain of firmware checking that goes on when you turn the device on
with checkm8, yes you can modify some of these checks
but now the device knows that the chain has been modified and won't boot without being exploited
but since checkm8 needs a pc to exploit the device, your device is a brick until you plug it in to a pc
iOS Firmware + APTicket (blob) = iOS Signed Firmware (apple private key)
BootROM (containing apple public key) — VALIDATE —> iOS Signed iBoot (signed with private key pair) — VALIDATE —> iOS Signed Firmware (sig. priv key) + SSV — VALIDATE —> iOS Signed BB/SEP/Other firmwares (sig. priv key) — BOOT —> Sandboxing, userland, etc. —> Lock screen (iOS Firmware running) — VALIDATE APPS —> AMFI, amfid, other fun stuff —> Apps running!
but I am not planing on modifying the kernel cache SEP and baseband would it still boot like the downgrade checks only happen post installation so if I use the latest kernel cache SEP and baseband I should be fine
and I am only focused on trying to migergrate the downgrade checks that allow the os to downgrade.
all modifications are done post installation and are reverted pre installation
if you don't patch anything out the downgrade won't be possible
Bruh I AM PATCHING THE PE THAT DOES THE INSTALLATION
...which would make the whole thing tethered
again
you still go back to the fundamental issue that modifying anything in the boot process will require a pc to boot
I never said I am modifying the iboot or anything of the atual os.
I am only patching the pe that does the installation
what are you referrring to
preinstalled envioment
and how do you expect to do any sort of downgrade without touching iboot or dfu?
I am only touching dfu
when I said "I never said I am modifying the iboot or anything of the atual os." is dfu part of ios
no cause dfu does not load a os
it is used to flash an os
Do you think I dont know that
no
and dfu isnt part of a os
so I never said I wont be touching dfu
and the moment you try and touch dfu you change the boot process, making the boot tethered
um even a shsh downgrade requires a pc so I dont get your point
the difference is with an shsh downgrade you can boot without a pc
but when I am modifying the boot process I am using a custom pe not a mofied iboot which is installed
so start the downgrade so I still dont get your point
again im not sure what you mean by preinstalled environment because that's not really a term that exists in ios
I am talking ouside ios my guy
well you haven't really explained how this preinstalled environment works
well its job is to install ios via a script. once I have acces I might be able to share a dump of it with you
well the apple's version
so are you trying to downgrade with or without blobs
I am trying to modify the script to make it without blobs
what you're describing is tether downgrading and there are some tools to do it
but you should still keep working on it, it's a good learning experience
what i was planing on doing was try to do a downgrade via the bootrom exploit while not modifying the boot chain
what a great project, keep us updated once you develop a POC
tbh I need to modify the dump I have currently
best of luck
Hey if you’re willing to do it that’s awesome
Good luck
Any one have a tutorial fpr how to have a rooted jailbreak on iphone 7 running ios 15
check palera1x if you have windows installed
Is there any tutorial on how to use it? I have tried to use it but didn't really know how, I have dopamine installed atm
What I'm looking for is called Untethered Jailbreaks on wiki where I need to do the exploit only once
Untethered jailbreaks can be considered the holy grail of all jailbreaks. They only require the exploit to be ran once either via a website, an app or a computer.
parlera1n and palera1x are bootrom jailbreaks so they are tempoary
tbh its going to be best if you use parler1n/parler1x jaibreak cause I dont think that any newer jailbreaks would work on the device
I have tried to use them but didn't manage to make it work, if you know if there is a tutorial or a video on how to use them I would be thankful
did you install bindfs
thats a required step in getting the rooted jailbreak working
What is bindfs
me when apple discovers that I have found a way of bypassing apple's ios/ipados installation verification without the need of saving shsh blobs
https://tenor.com/view/ドロン-忍法-パッと消える-poof-disappear-gif-15682669
!t bindfs
!t bindfsfaq
!t help
!t blobsfaq
What's a blob?
They're like golden tickets, but instead a digital signature made by Apple that was saved at the time when the signing window was open. If you possess one (or many), keep them safe.
How do they work?
They can be used in a program called futurerestore to restore to a firmware in which the SEP/Baseband is compatible. To check SEP/Baseband compatibility, check /tag sepbb.
Make sure to not use misleading sites. Stick to reputable sites like ios.cfw.guide and AppleDB.
Regardless of SEP/Baseband compatibility, any/all blobs should be saved for future downgrading abilities.
Can I use other people’s blobs?
No. Blobs are a file containing a special key specifically for that one device to allow downgrading to a specific firmware. Due to the way they work, only Apple can create them for your own device.
Can I save them now?
In general, yes. Blobs can be saved at any time, but it is crucial to save them when Apple releases new firmware, because they can only be saved for versions that are currently signed. There is one exception to this: if you are jailbroken and Apple has unsigned the version you're currently on, you may save onboard blobs for that version.
BindFS is a tool used in the context of jailbroken iOS devices. It allows you to create a bind mount, which is essentially a way to mirror a directory to another location. This can be useful for various purposes, such as redirecting file paths or managing file system permissions.
me when i have no proof of backing up my claim
that's like saying haha i got checkm8 to work on A13
I just havent gotten around to testing it
yeah so how about you test it first and then bloat about how you found a downgrade method
Wait is that possible??
How can you skip it?
But is there any tutorial on how to use the software I haven't understood how
it's not
its simple to use
help the dump I have gotten is encrypted
k
Can anyone help me with the making of a pe that will install ios without shsh blobs
I genuinely don’t think you understand what private cryptography is
The bootrom verifies apple’s private key with a burned in public key
You can’t just fabricate your own blobs
I AM NOT TRYING TO DO THAT
then figure it out
yourself
i love how you go around saying "I have a found a downgrade exploit" when in fact you found nothing so far and everything is speculation
Whitename behavior
🫃
wtf
piracy :/
how come you have ios 21.4
early tesetr
someone is trying to make a giant leap in downgrading iOS versions
One message removed from a suspended account.
no
im testing ios 22 right now on my iphone 18 pro max ultra
good luck
Hey, I have a question, I saw for a bunch of weeks that it’s possible to have palera1n like uncover so that you don’t need you’re pc to jb the phone. Is that true or some scam shit what I saw?🤔
scam
Oh… okay
Palera1n is based on an hardware exploit so it will be impossible with only software on your phone
How to jailbreak ipad 4 with windows laptop
Do you have any kind of laptop or pc?
Can i install in windows
U will need to flash it to an usb stick and then live boot
There is no direct support for windows
Will palera1n work on ipad 4 with ios 10.3.4
I have tried ra1n usb that did not work on ios10.3 4
Like stated on the website u can sideload it with sideloadly
So yes it will work on windows
Anyone know how to get clash of clans working?!?
Palen1x
@silent anchor
You get that? @silent anchor
yea
but i tried installing kali instead of that
tried many times
on other ssd
and like
user and pass
fails
while its correct
im doing the other method
is it possible on vm
?
no
don’t do that
kali is quite possibly the worst distro you can use to try and install palera1n
How does one know that -C even worked to remove a Created BindFS if re-doing -B says it already exists
Linux mint is fine
!t whyrootless
Hey @bold locust, have a look at this!
Why rootless > rootful:
- There isn't any storage penalty (such as the 2-5 GB bindfs or 10GB+ fakefs storage penalty) compared to stock iOS
- Most future development of both tweaks and palera1n will primarily be rootless
- In general, rootful tends to have more and harder to troubleshoot issues in comparison to rootless
Yes, tweak compatibility for older tweaks may be better than rootless, but many older tweaks can be patched in various ways to work with a rootless setup.
why does the palera1n app not show
What device and iOS verison?
oh wait
ok I figured out it's just -f --force-revert that will remove the BindFS as well
didn't work anyways, but Rootless works fine
I am just not exactly sure what you are meant to do with it after 
like u install it and when you reboot you just make it boot Rootless again, or what happens

Supershocked
Choicy?
!t palera1nupdate
palera1n has received updates to support both iPadOS 17 and 18, however this comes with some misconceptions. palera1n is different from app-based jailbreaks such as Taurine, unc0ver, Dopamine, etc, as it uses the checkm8 bootROM exploit. In simple terms, this means that the exploit targets the read-only low level hardware of the phone, meaning it is completely unfixable by Apple, and can only be fixed by releasing newer devices.
However, this also means palera1n will only ever support older devices on 17+, namely A10X iPads and older (as there are no checkm8-supported iPhones that received iOS 17 or newer). Compatibility for iPadOS 17+ is limited to the following devices:
- iPad 6th Gen
- iPad 7th Gen (17 & 18)
- iPad Pro 10.5 inch
- iPad Pro 12.9 inch 2nd Gen
@oak escarp @sturdy rampart I uninstalled the official App Store version and installed a official ipa that was patched to not crash jailbroken
Official іра
Not much you can do there
you kind of just have to factory reset your device
My iPhone is on iOS 16.7.10
The jailbreak I used was Palen1x ISO.
I have a jailbroken phone and I’m playing Clash of Clans 🤓
!t palera1n
Guide to installing palera1n
Sadly you can't look up a jailbreak with GIR iirc
@sick compass I am sorry I didn't know
Reminds me of “fresh frozen” when talking about food instead lol
do /jailbreak
wait till you find out this simply using choicy would be enough!
when i reset everything will my iphone get locked again with the old icloud ? I only have a windows pc
we dont help with icloudbypassed devices
Is it possible that when I tried to jailbreak the iPhone 8 it could have bricked? My terminal (I use Linux) got lagged and it said that I was putting the device into restore mode and it got lagged and I couldn't do anything and I turned off the terminal and I haven't been able to exit restore mode for 2/3 days I don't know what to do through on Windows nothing I couldn't do anything, exit restore mode or flash the system, and iTunes doesn't even show the device... What to do?
What’s the current best tool to downgrade to older versions tethered for checkm8 devices?
!t reboot
Hey @cursive quail, have a look at this!
This will force reboot the device. For normal rebooting instructions, see the normalreboot tag.
iPhone 8 or newer (including all notched devices, iPhone SE 2020 and newer):
- Press and release volume up
- Press and release volume down
- Press and hold the side button for 10-20 seconds until the Apple logo appears
iPhone 7:
- Press and hold the volume down and power buttons for 10-20 seconds until the Apple logo appears
iPhone 6S/SE 2016/iPad 8th or older:
- Press and hold the home and power buttons for 10-20 seconds until the Apple logo appears
Is there a jailbreak for iOS 18 /ipad 8th generation
Downgrade and dualboot status of almost all iOS devices - ios-downgrade-dualboot.md
can iphone xs max or iphone 13 pro max downgrade to IOS 16?
no
ok
I have a question. I keep getting this error performing usb device reset device disconnect detection might not work until a manual cable replug. How do I fix this? I tried replugging the cable back into the usb port but it still gives me that error.
I have choicy what are your settings at? I’d rather use the App Store than wait for the patched ipas every update
@oak escarp
you completely toggle off tweak injection
I tried Choicy, Shadow and one more I think but I forgot which one not at the same time but I still get the clash crash of being jailbroken
Does anyone know?
What device and version?
Ipad 6th gen 17.7. I have an AMD cpu on my main setup so I am unable to use this setup for the process. My Poweredge r720 has an intel CPU so I am trying to use that atm. I am using an ubuntu VM in proxmox for the jailbreak process.
Does it let you jailbreak the device at all? If yes, try unplugging and replugging the device when it says Checkmate!
No, it won't let me. It has this error.
I tried replugging the cable back in and it still gives that error no matter what.
I believe the error is the VM
Your VM software doesn't support USB Passthrough
See if you can run a live linux boot from a USB or run it directly on proxmox
On proxmox I setup the Linux VM so that it can recognize the USB port but oh well. I will try on my EndeavourOS boot. Give me a moment to see if it works.
This is what I get on EndeavourOS. I have an AMD CPU so I figured that was the reason.
Yeah that error is due to AMD
Thats what I figured cause I saw it mentioned on the site saying AMD CPUs have issues. Something related to USB controllers iirc.
Is there any other way I could potentially do this jailbreak without having to get a computer that has an intel cpu? I am not able to go out a get a laptop at this moment.
You could keep trying on AMD it just has a very low success rate
Or boot palen1x from the intel cpu computer on proxmox
palen1x is meant for windows but in this situation it would still work, its just linux but only lets you run palera1n
A complete iOS jailbreaking guide, from stock to jailbroken.
Ok, Thank you for helping. I will keep trying and let you know if I run into anymore issues.
No problem
I forgot to ask. On the EndeavourOS I am running where it says Setup Packet was not accepted in the image above that I posted. Do I just let that keep on going until it is successful?
I am a bit new to this. So I apologuise for the many questions.
Not sure since I don't own any computers with an AMD cpu
Probably just let it keep going
All good
Ok will do. Thanks!
I wonder if iOS 15.8.3 on a A10 did something
or if versions of palra1n past 1.0.7 changed something regarding BindFS
Technically it should work but something doesn't. I kinda do wanna use -L to log what -B did, but at the same time idk.
Rootless however works fine.
Jailbreak ios 16.7.4 iphone 8 give me
How to get Xr features and dynamic island on iOS 16.7.10 iPhone 8 with no pc
!t guide
Hey @indigo drum, have a look at this!
Send me link
@indigo drum
omg same ios version!!!!
ye it did
if u are on something line less than A11 and iOS 15 you need to use the iso version 1.1.5 or less
before 2.0

I tried for a few hours and had no success. I am going to hold off on doing this any further until I get an intel computer. Thank you very much for helping me earlier.
No problem!
Thats just rude
Should I do rootful or rootless on a iphone x on latest ios?
!t whyrootless
Hey @uncut nymph, have a look at this!
Why rootless > rootful:
- There isn't any storage penalty (such as the 2-5 GB bindfs or 10GB+ fakefs storage penalty) compared to stock iOS
- Most future development of both tweaks and palera1n will primarily be rootless
- In general, rootful tends to have more and harder to troubleshoot issues in comparison to rootless
Yes, tweak compatibility for older tweaks may be better than rootless, but many older tweaks can be patched in various ways to work with a rootless setup.
thanks ❤️
Which Linux distro will work 100%? Ubuntu gives <Error>: Timed out waiting for download mode (error code: -status_exploit_timeout_error)
Guide to installing palera1n
palen1x
Ubuntu usually doesn't work/isn't recommended iirc
!t palen1x
palen1x allows you to use palera1n-c on Windows computers via live-booting. You will need a USB flash drive or SD card for this.
hey all, i need some help with palerara1n- i installed it on iOS 16.7.4 on an iphone 8. it install fine but i keep finding that it will occasionally go into safe mode- i uninstalled and reinstalled the plugin i thought it was but it wasn't it. Also, whenever rebooting and re-jailbreak it remains in safe mode. What can i do to escape, this time it seems as if i'm stuck there.
what i have installed: snowboard, trollstore helper/trollstore/trollstore lite, floatingdock XVI, filza, and the other necessary ones that come pre installed with palerara1n
is ios 17.6 on an ipad7 supported ?
yup
perfect, ty
why both trollstore and trollstore lite?
🤷♂️
uninstall trollstore lite
Hi, dose iPhone 12 iOS 18.1 supported? What to do after installing Altstore? Im no pro at this things 🤦♀️
iPhone 12 isnt supported so no
Can we jailbreak iOS 17.3.1 iPhone 15 max pro
no
You think they going to have one ☝️
Isn’t there one for iOS 17 tho
the only thing is the iPad OS 17 and 18 with an jailbreak
for iPhone no
only Trollstore + Bootstrap on 17.0
I got a iPad
which one?
I need to see atm im on vacation I think it’s
if its any of these, u can jailbreak it
iPad Pro
there are multiple pros xD
Need to see when I get back in a week lol 😂
alr
to emulate iOS?
Yea
I don’t think so but if they do be nice to run a jailbreak for an app and then transfer data
well u could kinda use corellium and even jailbreak every version I think but aint cheap
so prob not worth it for a normal usecase
else you would have https://github.com/devos50/qemu-ios but thats also not really useful for anything newer
A QEMU emulator for legacy Apple devices. Contribute to devos50/qemu-ios development by creating an account on GitHub.
and still very much in testing last time i checked at least
u could get a free trial tough for like 60 min or so if u can convince them that u need it
How much
Dam why so much
because its meant for profesional security researchers
and i can imagine, building a fully functional iOS VM for all fairly recent devices on all versions isnt that easy
True
but like i said, if u only need it once for a short time u could get a free trial
Isn’t this for iPod tho
yeah thats why i said its not really useful
just pretty much the 2 systems able to emulate ios in any way that i know
i used it when i did not have iphone (now i have a jailbroken iphone)
Same I have other iPhone on iOS 14 just sucks cause some them app need to be on iOS 17 I used to know how to bypass but I guess not
they mixed up the free trial options(before you just had to click free trial and type your info)
bruh why tf did they do that
ah yes corelium solo a classic
Dam lol 😂 isn’t there a way to spoof app for higher firmware and if this isn’t channel what channel can I ask
oh yeah, they accepted mine tough couple months ago with this current one
i wanna jail break my iphone 8 with ios 15 on it whats the best route?
i want it for pokemon go
oops wrong channel
no you're in a pretty good channel for that
it doesn't really matter
i'd suggest dopamine for that device
its gonna run pretty poorly
but yeah use dopamine
Does palera1n support iOS 16.7.10 (20H350)?
Depends what iPhone
iPhone X
Yes
When using checkra1n/palera1n on the iPhone 8/X running iOS 14 or later, you will not be able to use any of the following SEP features in a jailbroken state:
- Passcode
- Touch ID/Face ID
- Apple Pay
Additionally, if you’ve ever enabled a Passcode on iOS 16 on the iPhone 8/X, you’ll need to erase all content and settings in order to successfully jailbreak with palera1n.
Thought so
Would it mess with my cellular data ?
No
But keep this in mind ^
Passcode is the 6 digits correct?
What do you mean
Is that it or are there more things not written?
No thats it, nothing else is lost.
You can get the passcode back use FakePass
Perfect
[[FAkePass]]
Fake passcode for checkm8 jailbreaks on iOS 14+ on A11
Do you know how long it would take to install?
I just found about it 1 hour ago and it seems like the only option that’s good
Depends, windows, mac or linux
Windows
note that since you’re on 16, you’ll need to erase all content and settings if you’ve ever set a passcode
https://ios.cfw.guide/using-palen1x/
Maybe 10-25 minutes
A complete iOS jailbreaking guide, from stock to jailbroken.
Before or after jail break?
Do you guys also help with installing tweaks?
Yes
before and moving forward
I can’t just turn it off rn?
you have to erase if you ever set a passcode to use palera1n
thank you Apple SEP mitigations
If you’re on 16.7.10 you can’t use Dopamine
and no you can’t downgrade
(that being said… Sideloadly would likely be fine if that’s your goal)
Would that be permanent ipa signing or temporary?
@solemn verge do you know of a YouTube video on how to install it?
Which one would I install
the one with 64
!t yt
Hey @runic bay, have a look at this!
YouTube is typically a very poor source of information and should be avoided. Many jailbreak YouTubers promote piracy, outdated tweaks, or just flat out fake jailbreaks. Reliable sources: iOS Guide, r/jailbreak Wiki, Apple Database and The Apple Wiki.
that's crazy that !t yt is in his name 😭
@silent anchor ^
😭
read the top of the screenshot brother 
wtf
permanent as long as you are jailbroken
What about for this one which ones do I download?

buddy
what is your operating system do you know that?
Bruh I realized as soon as I sent the picture
My fault is that all I download from this website or more?
!t tsjb
Hey @runic bay, have a look at this!
If you have a device on iOS 16.7.x or iOS 17.0.1+ and it is jailbroken, you can use TrollStore Lite as an alternative to the regular TrollStore. TrollStore Lite is recommended if your device does not support TrollStore, otherwise you should just use that.
You can install TrollStore Lite from Havoc by clicking the link below.
Is there a way to bypass the jb detection from supercell games? Specifically clash royale
disable tweak injection with choicy
thanks
ive disabled tweak injection for the app but it still dosnt work. is there any other settings that i have to enable for it to work?
yup
uninstall it
Hi! I have a question, why does my vnodebypass is failed? I installed dopamine thru trollstore and my jailbreak is Palera1n+rootles iPhone 7 v15.8.3?
how long did you wait on the screen
It instantly changed back to "enable" button
oh my bad, here is what's happening when I click "enable" button
Guys i need jailbreak ios 17.3.1
there is
ios is not ipados
my bad
I thought we are in palera1n so he means iPadOS
why exactly does palera1n say
It has to do with timing issues with AMD CPU’s iirc
don't newer Intel though have a defect though?
e.g. let's say one seeks a new build type thing
That’s different
You can still use palera1n on AMD you’ll just have a lot of issues
like issues as in errors?
on a Reddit post someone said that it worked for them using a different USB Port
seen that newer models support something called "USB 4.0" 🤔
AMD isn't great when it comes to explain features, probably in BIOS one can find a bunch of settings for USB maybe, not sure
this sort of issues are present on the AMD GPU. CS:GO Steam Forums would go wild on issues. Being forced to change the settings, isn't something common that a user should be forced to do
Oh yeah, it was their USB controllers that have weird issues
https://www.youtube.com/watch?v=ET4PFZ9rqlc what a strange thing
because like I think CPUs themselves work the same
it’s a latency issue with AMD
AMD desktop CPUs have some USB controller thing that results in the exploit being really inconsistent
doesn't occur on AMD laptops
do they let one disable it?
disabling the usb controller means no usb
so is the usb controller just screwed
it's not screwed just buggy with this
is it all of the amd cpus?
I don't think so
are newer ones affected
but I haven't seen someone try this on like AMD FX
anything ryzen based is certainly affected
does that mean AMD are bad CPUs? or what would that mean
doesn't mean they're bad it just means it doesn't work with this
the cpus are fine, we're a very fringe use case that amd just doesn't account for
like the latency increase is in literal ms but that's enough to make checkm8 not work
i don't think a cpu should cause issues 🤔 🤷
no clue how the exploit works in detail though
also what USB Latency, like in-general or is it related to the exploit?
still didint work :/
I can use it in iPad Pro M4 ? am new here
no, ipad 7th gen and older only
Ok , thanks
intel and amd have different code for their usb stacks 
amd just has slightly higher latency in theirs which makes checkm8 not work right
did amd not reduce the latency in newer CPU models?
again like i said before this is not an issue in any other application
this issue only crops up when you're running an exploit that needs very low latency
you would never have an issue with amd's usb stack in any other use case
so this latency thing doesn't equal to data is sent less faster through USB on AMD than on Intel? 
nvm
Hello
I’m new at jailbreaks
Please is it good and will my phone not get spoiled. Pls someone should put me on
what iphone & ios
and chances are ur phone won't get "spoiled"
just make a backup first
iPhone 14 Pro Max and my current iOS is 18
yeah unfortunately you can't jailbreak
if you want a jailbreak in the future, don't update your phone
Oh okay
I added you please accept
why
So I can dm you and so that you can put me on very well please.
there's nothing else to say
Ohk.
can a iphone X be upgraded to the newest version or is it apple update locked?
there's a good reason why the latest ios version isnt compatible with iphone X
chances are if u did somehow magically successfully manage to be able to do it
you'll only be met with a bootloop
phone starts up
crashes
repeat
u seem like yk what ur doing so i got a question. if i downgrade my phone to 16.5 RC and jailbreak it, will i be able to customize it to make it look like a newer version cus i really do not like the ios 16 like look
thank god 100% avalible 🙏
unfortunately you can't downgrade from iOS 16 because of the Cryptex(an iphone security feature that prevents downgrading, EVEN IF you save blobs)
yeah its impossible to downgrade
so once ur in iphone 16, there's no going back for now
damn i thought i could. so i have to wait for a jailbreak for ios18? (i got a 12 btw)
yeah it might take awhile though
apple bought all of the jailbreak developers lol
yea thats why i wanted to downgrade it. i used mistakaX to get the dynamic island but because of how the 12 is it gets cut off so i wanted to downgrade to jailbreak the phone and fix all of that
for A12+ processors it's iOS 16.6 max i think
unless there is another way of fixing that but i dont believe there is
unfortunate, but u can always still jailbreak ur phone and customise it
wait maybe 1-2 years and that will change
yea ima be waiting a couple years for a jailbreak lol
by then ima have a new phone
no 18
ohh
it came with 17 and i didnt know so i kept updating
yeah then i guess u gotta wait
iphone X is only 167 dollars rn
thats good but still not worth it i rather just pray to god some goated jailbreak developer drops a jb for 17.6.1
what if i download a IPSW of ios 16.5.1 or whatever it is an then flash it to my phone or will that not work
nop
https://x.com/opa334dev i guess keep an eye out
24, Developer of Dopamine Jailbreak, TrollStore and some jailbreak tweaks. Employed @CellebriteLabs, opinions are my own. Repo: https://t.co/jIxCyNXT1p
basically how do i explain it
when u want to install an update
it communicates with apple's servers
and if apple allows for the iOS version to be installed
they will send a key
which lets u install it
but yk how in #announcements it says
ios version is no longer signed
that means apple has stopped giving out keys for that specific ios version
and the keys are tied to your iPhone hardware information so they can't be shared
and apple has stopped giving out keys for ios 16 altogether so u cant downgrade
u can see here https://ipsw.me/product/iPhone
Download current and previous versions of Apple's iOS, iPadOS, watchOS, tvOS, audioOS and macOS firmware and receive notifications when new firmwares are released.
ipsw are the iOS files
i guess the good news for u is
yea i saw on that site actually i could still download 16 so i thought maybe it would work
u can downgrade to ios 17.7
i can but by the time 17 gets a jailbreak i might be better off forgetting about it and update my phone. or deal with dynamic island being cut off halfway
¯_(ツ)_/¯
or just not use it, i thought there was a way to downgrade so i figured id ask
you can technically downgrade to 17.6 by downloading the 17.6 beta (still signed) and then using delay ota to update to 17.6 stable
How to jailbreak one plus 8t 💀
get outtt
Lmfaooaoaoao
Is there a jailbreak for 17.3.1?
Hi I’m new at this so how can I unlock phones from carrier
call the carrier
no other option
Are you on an iPad 6, 7, Pro 1, or Pro 2?
pro 1 only went up to ios 16
I was too lazy to search it up
with the new troll store version will this make a new jailbreak come then
I’m on 17.1.1
I agree … I’ve been waiting along time waiting for iOS 17 to work
no
No
you can still jailbreak if you had altstore
TrollStore isn’t a requirement for jailbreaking
sideloadly > altstore
no
16.5.1 and A15/16 and M2 is max 16.5
trollstore>>
yea ofc but thats only if u have the exploit available
unlock bootloader then install magisk
or ksu if that's even compatible with the 8t

can you jailbreak on iPhone 13 Pro Max cuz ngl this iPhone 7pro be getting hot
no
palera1n doesnt work on the 13 pro max
what ios version is it on
Hello, I have ipad air 4th gen OS 17.5.1. Do i need a computer to jailbreak Palera1n?
u cant jailbreak
at all
no
never ever
not going to happen
stay on 17.5.1 for 2 more years and maybe u'll have a jb
iPad getting access to iOS 18 while iPhones don’t get 16.7 even 💔 insane ngl
Can u jail break a iPhone xr?
not with palera1n, with dopamine up to iOS 16.5.1
yo how does one jailbreak with iPhone 7plus
What ios
15.8.3
bet ty
16.6.1? a13
!t semijailbreak
Hey @silent anchor, have a look at this!
Recently, some tools have come out for certain devices and versions covered by the CoreTrust bypass. These tools claim to be "semi-jailbreaks" as opposed to a traditional, "full" jailbreak.
The primary difference is that these semi-jailbreaks do not require any sort of PPL bypass, which is a required exploit on "full" jailbreaks in order to run tweaks. As a consequence, this means semi-jailbreaks are limited to devices only supported by the CoreTrust bypass. Additionally, they may suffer from a lack of stability and be prone to crashing or random reboots.
Additionally, these tools are limited as to what they can modify. While certain Springboard tweaks (such as those that modify the lock screen or home screen) and app tweaks work, overall tweak compatibility may be limited. Furthermore, tweaks that require the use of daemons (system processes that run in the background), such as Crane and Aemulo, will not work with any current semi-jailbreak.
Finally, due to the requirement of a userland PAC bypass in iOS 17.0, it is unlikely that any semi-jailbreak will be released for iOS 17.0 soon after a kernel exploit is released. To add to that, as SPTM now manages userland PAC, it may be that semi-jailbreaks will never support A15+ devices on iOS 17.0.
follow this
Guide to installing nathanlr
Do u can remove it after u set it up
Yeah it removes itself after every reboot
But if you fully wanna uninstall it then make sure to remove the tweaks first just to be safe
Respring?
Yeah
Yes
Ok
Its reloads springboard?
For example if you install a tweak most of the time you’ll need to respring your phone for the tweak to work
Yeah I think so
Oh
Yeah its just restart spring board
Ye
Ty
Np
Yeah
palera1n?
Nathanlr
Idk
Is palera1n removable without losing data?
!t rootfs
Hey @silent anchor, have a look at this!
To revert the jailbreak installation on your device, follow the steps below.
palera1n
Rootful: palera1n --force-revert -f
Rootless(default): palera1n --force-revert
If the above methods didn't work, see /tag rootfscli for more options.
Dopamine
Reboot, open Dopamine, open the Settings page, then press "Remove Jailbreak"
Note: Since the rootfs is sealed on iOS 15+, it remains the same across all devices. Thus, "Restore rootfs" means practically the same thing as "Remove Jailbreak"
cool thanks
does palera1n work on ipad 10 ios 18
no
you cant downgrade either
to a jailbreakable version at least
what ios can you jb sith palera1n
A11 and below devices
…
You just remove the tweaks and then you should be able to safely uninstall the jailbreak there should be a guide somewhere
Оk
i use to have palera1n on my jailbroken phone but i lost my usd how do i start over again , i have a new usb just need to know the steps
Palen1x
does the secure rom dump work for iphone 5
where’s the guide to that
Sad that the last iphone that is supported with palera1n no longer has support for the latest version of ios 18
it doesn't even have ios 17
Hey guys, has anyone had any luck with jailbreak detection bypass on the Wizz Air app? I have blobs for iOS 15.8.3 and iOS 14.2
It seems to be quite strict with jailbreak detection and just crashes on launch if the device is jailbroken (though it launches if palera1n is installed but not in the jailbroken state)
What type of jailbreak does palerain have
semi thetrered
did u try disabling tweak injection with choicy? if the app is apperantly not checking any files because it works in non jailbroken state i would assume its checking tweak injection
Good point, I'll try it, but would it be possible then to still use Frida to analyse the app?
i dont know exactly how frida works but i would assume it will have to inject something into the app if thats the case prob no
You could try A-Bypass too but that wont be as powerful as choicy so it might get detected
Ok so then there aren't any tweaks that properly hide injection entirely? I guess apps can do random stuff to see if there are tweaks
Also rootless jb would be easier to hide than rootful right? I am at 15.8.3 but can downgrade to 14.2 and use KernBypass
i dont think that will do a big difference tbh as the app wouldnt have the priviliges so check that if rootful anyway
there are couple ones that work with most general apps like A-Bypass or Choicy but more advanced ones mostly have specific ones
sadly ur app prob isnt big enough to be in GIRs list
Alright then I'll just play around with A-Bypass and Choicy and see if I can come up with a way to run Frida and bypass detection
But probably it's not going to work
Thanks for the help
i mean if u are good enough in reverse engineering, you could just try frida without choicy and then find out what the app is checking
Honestly it's not something I want to invest a massive amount of time in (it's a small favor for someone else) so I was just checking for a general solution
alr then just try choicy or A-Bypass
“work” in what way
Hello all
I recently installed palera1n on my iPad. Installed Filza with zebra 1.1.36. I can transfer files to my MacBook using chrome with filza but unable to transfer files to my iPad. Please help.
can i jailbreak my iphone 7 with ios 15.8.3?
are u on linux/mac or windows
@vital apex

Windows
!t palen1x
Hey @old geyser, have a look at this!
palen1x allows you to use palera1n-c on Windows computers via live-booting. You will need a USB flash drive or SD card for this.
click on palen1x tutorial
You can transfer files through your iCloud if your devices are synced and connected with your Apple id. From your Mac book put them on iCloud - and open the files app that’s preloaded on your iPad and click iCloud Drive and your files should be there.
Is there an option in Palera1n to disable tweak injection without the phone being jailbroken? My SpringBoard is stuck in a respring loop because of a tweak
palera1n -S i think
for safemode
A friends off mine askes if you can jailbreak iPhone XS max with ios 17.6.1. I thought it wasn't. Thanks in advance
you cant
Thanks, that was what I thought
Thanks. Is there a way to fix this? Filza on my iPhone works fine.
I’m not sure im understanding what your trying to or want filza to work together with. What are you asking if there a way to fix what?
You said you can transfer files to mb using chrome with filza.
You should have to use chrome at all to transfer files between your devices.
You can just ari drop the files back and froth between all of them. Let me know what you’re trying to achieve.
Hi sorry for being not clearer before. I am trying to move files from my PC to ipad using chrome - filza web address but it doesnt work. However moving files from ipad to PC seem to be working.
A15 ios 16.6.1 possible?
is it possible to get parler1an on my phone using a pavilion g7 ?
Any computer made in the last 20 years will work https://ios.cfw.guide/installing-palera1n/
Guide to installing palera1n
As long as it has an Intel CPU you should be fine
Also what ios verison and device do you have?
Hello
Can someone please help?
Filza installed thru tigisoftware repo on palera1n - zebra - iOS 17.3.1 iPad 7 rootless. Unable to transfer files from pc to iPad via Chrome. Files don't show up after I upload them.
Didn’t work, erased all content and settings, re jailbroke and now choicy isn’t showing up.
[[choicy]]
Advanced Tweak Configuration!
get it from this repo
Hi I am on linux ubuntu, have an iphone 8 running iOS 16.7.10 and I tried palera1n and it gets to``` - [10/07/24 04:31:24] <Verbose>: == checkm8 trigger stage ==
- [10/07/24 04:31:25] <Info>: Checkmate!
- [10/07/24 04:31:25] <Verbose>: Device should now reconnect in download mode
- [10/07/24 04:31:25] <Verbose>: DFU mode device disconnected
- [10/07/24 04:31:45] <Error>: Timed out waiting for download mode (error code: -status_exploit_timeout_error)
Unplug it then plug it again when you see “Checkmate!”
Failed to start notification connection. There was an error connecting to the device.
put an * instead of my name its not normaly like that fyi
@silent anchor(sry for the @ have to go soon so just checking) soo have any idea?
thanks
no
You have a JB tho, so I don’t see the point in downgrading
it is for my friend and he wanted trollstore and a jailbreak without needing wipe and no passcode
does he have blobs?
he doesnt know anything
then he cant downgrade
probably not
also it is worth going to 17.7 for more chances for jailbreak
stay the lowest possible
im on 14.4.2 on a 2nd gen ipad pro 11 inch. what do i need to upgrade to so that i can play pogo and jailbreak again?
you upgrade your ipad to a newer one on a jailbreakable ios version
yes i was asking what ios version i should upgrade too lol sorry
well that's the funny part
you can't
so that's why you upgrade your ipad, aka buy a new one on a jailbreakable version
can someone help me
i’m doing the correct steps to enter dfu mode but it dosent let me ??
!t usbcmoment
Hey @fast patio, have a look at this!
Did you manage to get any time? No issue if you hadn't I'm going to sleep soon and remembered to ask
where was this
the palera1n logs or what
trying to install palen1x and it says to download ventoy
i follow directions and it says open “Ventoy2Disk.exe”
i do that and it says please run under correct directory
what am i doin wrong
does it jailbreak or not
also why are u replugging it, does it give you the download mode error, if it doesnt then just leave it like that
Is the exe file in the folder you downloaded it in
Like is it in the same foldder with the other files
There's no palera1n app
Wait the error is ok? I was doing it BCS of the error
Oh also BCS of this why I unplug
I'm on Ubuntu Linux which is my daily driver
yeah thats why sorry
you'll have to use palen1x
!t palen1x
palen1x allows you to use palera1n-c on Windows computers via live-booting. You will need a USB flash drive or SD card for this.
What's the technical reason?
no idea
Alright thanks
I’m running palerain rootless and I installed trollstore via trollstore helper from sileo (havoc repo). Then I installed trollinstallerX via trollstore to get the persistence helper (and reinstalled trollstore through TIX).
If I were to now install Dopamine using trollstore, then reboot, could I rejailbreak using dopamine? This is rather convoluted but if it works it means I can get away without making an apple account.
This should work
Uninstall TrollStore from trollhelper, but keep apps on uninstall. Then with TIX kept, re-install trollstore through TIX and install dopamine through there
TIX rebooted during the installation :/ so I’ll try again tomorrow. Thanks for the reply 😄 Edit: It worked!
Is there a way to get palera1n on A13
never
Fuck
how to fix it ?
- [07/10/24 21:15:11] <Error>: Unable to open device: e00002c5 (error code: -status_open_device_error)
pls teach me
How would I jailbreak ios 17.7 ?Probably a dumb question
if its an iPad 6th Gen, iPad 7th Gen, iPad Pro 10.5 inch or iPad Pro 12.9 inch 2nd Gen then you can use palera1n
if its anything else then u cant
What if its a iphone 11 pro max with ios 17.7?
read
okay
Is pal3rain can use on ipad11 M1.???
no
Thx mam
Hey guys new jb noob here, how would I jb iOS 16.7.7 on iPhone X
!t guide
Hey @river frigate, have a look at this!
Hello, is there a tweak to check the crash logs via sileo on iOS version 16.7.10? Cr4shed/crash reported/krashkop is not working
Thank you 🙂 so I have to remove all data sadly:/ I guess I can’t continue for now
I never jailbroke before but want to jailbreak my old ipad air 2 (A8 chip) is this even possible?😅
Yes but it depends on iOS version
Check out this page on what jailbreak to use https://ios.cfw.guide/get-started/iPad-Air-2.html
Find out what jailbreaks you can use on your iPad Air 2.
The from and to are for iOS version
pongos is hanging on enabling usb?
enabling usb Done! pongos >
thats all it says \
how do i turn it off to restart it
Unplug it and replug it in to start the jailbreak
Weird mine did the same but unplugging it fixed mine…
can I use rufus to flash paler1x instead of ventoy, and if so do I flash it in iso mode or dd mode
ventoy has never worked for me ever I don't want to use it
DD mode
worked for me 
i imagine it didn't due to safe mode but you can enroll keys
re-run palera1n again, generally should work
alright
okay so it split into 3 different drives, and doesn’t show up in winpe
yeah you’re supposed to boot into it
that’s what you’re supposed to do?
using the winpe worked on my laptop but that thing was a Microsoft surface with a single usb port
so I couldn’t really use it
had no hub and the keyboard also didn’t work because Microsoft makes great products
yeah it doesn’t show up
all those “generic massstorageclass” things is my usb hub
oh there we go
gave it a reboot and “usb” and “usb, partition 2” showed up
the second one is marked uefi do I select that one
yeah that worked
oh
it was not mentioned anywhere on the guide that you needed to solder a usb port onto an apple tv for the jailbreak
probably should’ve occurred to me sooner but damn
my iphone 8 goes to dfu and it keeps leaving it
my specs are in my bio if u need them
tbf the guide is portrayed as for iphones/ipads specifically
fair enough
weird how there’s no notes about it on the apple tv 4k’s firmware selection page though
because I need to:
- actually split the guide properly for palera1n
- get the proper guide to show (checkra1n has this same issue)
for the record on Apple TV's you want to run palera1n -f, not palera1n -l
perfect storm of awfulness, I have an Apple TV 4K, an apple tv 2nd gen, Apple TV 3rd, gen, but no 2nd or 3rd gen remote, and an Apple TV HD remote, but no actual apple tv hd
consequences of being unorganized
can i jailbreak an iphone 14 pro on ios 16.6.1
There is semi jb with nathanlr but no full jailbreak
So stuff like Crane doesn’t work
I think you can use a Goldeneye Cable, no?
a goldeneye cable could work
but tbh at this point I’d be happy to just install trollstore
but of course that process isn’t easy either
Is there a jailbreak yet that’s compatible with iphone 14 pro v17.3.1
Is there a way to jailbreak a 13pro on v17.3.1
no
Is it better to downgrade to ios 15 then try?
you cant downgrade
Forced downgrade doesn’t work anymore?
I haven’t jailbroken in a while I came back to iPhone this is all new to me
never did
I’ve done it before in the past way back when ios14 was around
That was when I last attempted
Easy to brick your phone but it’s possible. It’s just a pain
that method no longer works
Well I’m sad now.
What’s the best way to go about it then for v17
there's nothing to do except wait
I figured as much
on and on the same questions "can i jailbreak" "is it compatible with" cant you all read?
well you need 2 clicks to get that info, might be too much for some people
please help decided to re is tall palera1n on my iPhone X so I reset my phone to remove sep then installed and it keeps giving error much help appreciated🙏
wdym by "reset my phone to remove sep"???
also open your phone and click trust
then run palera1n again
I did
Just remove all passwords Face ID Apple ID etc
oh
go into recovery manually then run palera1n
!t recovery
Recovery Mode (not to be confused with DFU Mode) is a mode which allows a device to be reflashed to a fresh install of iOS. You can optionally either keep your data and update to a newer version or restore and start over with a fresh install.
To restore in Recovery Mode
- Enter Recovery Mode
- Connect your device to your PC/Mac and open iTunes/Finder
- A prompt should appear which says “A device has been connected in recovery mode.” Either select “Restore” or “Update”
NOTE: If you use this method you can only restore/updated to a signed version of iOS.
Jsit put it into recovery then run palera1n?
yes
Ok. Will try Tomorrow
probably
Hi, I’m in the process of jailbreaking an iPhone X running 16.7.10, but when going through palera1n and it begins to reboot the phone, nothing has changed on the phone
the palera1n loader app takes a while to load afaik
not sure if there's any trick to make it show quicker
but given that log it looks like it was successful
Did you ever set a passcode before
Do i leave it plugged in whilst it loads?
nvm, it says fail i think
I had a passcode, but before starting the process i deactivated it
You need to reset
Deactivating it wont work
Full factory reset?
ahh
Yes

Erase all content and settings
Wont that install latest ios?

Ur on the latest ios anyways
16.7.10 is already latest for you
Also it doesnt
Okay, I’ll do that now thanks
That worked guys, installed now thanks @silent anchor @flat wave @velvet iris
NEVER set a passcode again, or you have to reset it once more
Don’t use Apple Pay, Face ID, anything like that
Wtf i had sileo and everything, then i restarted the phone and it deleted it all?
Duh you have to do that every time
palera1n is semi tethered
!t jbtypes
Types of jailbreaks:
Tethered
The device must be booted using a computer every time, otherwise it won't boot at all. This type of jailbreak is uncommon. (e.g.: redsn0w, 4039)
Semi-tethered
The device must be jailbroken using a computer every time it's rebooted, otherwise it will boot in unjailbroken state. (e.g.: checkra1n, palera1n)
Semi-untethered
The device must be jailbroken using an app every time it's rebooted, otherwise it will boot in unjailbroken state. A computer is usually used for the initial installation, but it's not strictly necessary. (e.g.: unc0ver, Odyssey, Taurine, Dopamine)
Untethered
The device will stay jailbroken after a reboot, no additional action is required. This type of jailbreak is uncommon. (e.g.: Pangu9, Fugu14)