opa334@infosec.exchange retweeted
🚨 Meet the first speaker of #POC2026 Lars Fröder (@opa334dev) - “iOS Jailbreaking: From P(PL)ast to PreS(PTM)ent” This is just the beginning. More POC2026 speakers will be revealed soon — stay tuned. 👀 Our CFP is still open until September 30.
20
175
12,644
opa334@infosec.exchange retweeted
We out here (and under SPTM) #coruna
53
95
517
95,317
opa334@infosec.exchange retweeted
Hi @Apple! 🥰 Looks like you're using Dopamine internally on iOS 26, would you kindly submit a PR to the GitHub repo? Oh, and don't forget to unban @opa334dev's developer account, that would help future Dopamine releases!
iOS 26.6 SpringBoard sandbox profile 😂?
6
47
626
120,254
opa334@infosec.exchange retweeted
Wen eta Apple official Dopamine fork?
iOS 26.6 SpringBoard sandbox profile 😂?
7
115
19,815
opa334@infosec.exchange retweeted
iOS 26.6 SpringBoard sandbox profile 😂?
3
24
268
174,417
opa334@infosec.exchange retweeted
On that note, enforcing boatloads are unlocked when devices are no longer supported by the manufacturer would be a great first step. I dread to think how many TFLOPs of compute end up in landfill every year because the software it’s forced to run makes it effectively useless.
I think — genuinely — the only hope for jailbreaking at the point is if the EU forces manufacturers to have unlocked bootloaders. It is deeply fucked up to me that you can buy a $1000 computer and are not allowed to install your own software on it.
5
3
85
60,543
opa334@infosec.exchange retweeted
I think — genuinely — the only hope for jailbreaking at the point is if the EU forces manufacturers to have unlocked bootloaders. It is deeply fucked up to me that you can buy a $1000 computer and are not allowed to install your own software on it.
“Semi-jailbreak” makes me immensely sad
6
11
196
108,004
Instead of warning about exploit source code that does nothing harmful whatsoever, how about doing something about all the countless fake jailbreaks hosted on your platform that all link to the similar sites (e.g. pangu8(.)com) that sell fake software for real money? @github
25
50
571
69,296
Me and others have reported countless of repos over the years, but nothing has happened regarding this whatsoever. None of my tickets ever even got a response... One time it told me to subscribe to GitHub Pro for someone to look at it...
4
2
119
24,741
opa334@infosec.exchange retweeted
sha256(quark.txt) = b29efa7b27e15d32e42d2acf7c5963aed2b53fbbf27177e4c654930421dddbe5 #coruna
11
38
341
83,886
opa334@infosec.exchange retweeted
My analysis of CVE-2025-43520, the kernel vulnerability exploited by DarkSword (patched in 26.1): gist.github.com/Muirey03/8c8…
4
46
291
43,341
With the recent discovery of the #coruna exploits, I want to reiterate that all future Dopamine Jailbreak development updates will not be shared on X.
29
60
564
116,908
Additionally, I understand I can't prevent it, but I would at least nicely ask people to not mirror any of my posts to X.
3
2
91
25,865
Lastly, I will come back one last time under this tweet in 24 hours to answer any good faith questions about the situation / my abandonment of this platform. #ama
10
3
83
22,902
opa334@infosec.exchange retweeted
Coruna's seedbell PAC bypass abused the fact that dyld didn't protect certain __DATA_CONST regions in the dyld shared cache as read only after populating GOT entries etc (I think to support certain objc method list types), (1/4)
2
21
221
30,332
opa334@infosec.exchange retweeted
So, let's talk about that Coruna exploit kit stuff now, shall we? Let's first establish a few basic grounding points, though, before people over-hype this too much: 1. There is zero guarantees that anything comes from this. Everything here requires stuff to be deobfuscated before it could ever be beneficial for anything. This process inherently requires effort, and it's the type of thing that isn't guaranteed to go anywhere. Additionally, while everything in this post is as accurate as current information tells us, there are things here that are subject to change or subject to validation. 2. Even if anything of note comes from the Coruna exploit kit, this is not a major major advancement. The bugs that this chain kit uses were all patched by 16.7.6/17.5. Additionally though, the last kernel exploit was patched in 16.7.5/17.2.1, which means that the highest possible advancement for jailbreaking is: - EoL (16.x): iOS/iPadOS 16.7.5 - 17.x: iOS 17.2.1/iPadOS 17.2 Which, to be clear, is not nothing - it would allow for the first proper jailbreak for arm64e 16.6-17.2.1, and it would also end the 2+ year streak of no arm64e advance or no jailbreak-relevant exploits. But it isn't going to take us to 18.x or even late-17.x. Now that we've gotten that all out of the way, let's lay some groundwork here. The Coruna exploit kit is a Chinese/Russian spyware kit, involving 23 different bugs designed to target devices running iOS versions 13.0 - 17.2.1. You can read more about this spyware kit as spyware at the following two links: Google Cloud Article: cloud.google.com/blog/topics… iVerify Article: iverify.io/blog/coruna-insid… Now, Google and iVerify didn't directly publish any samples themselves about this (whether this will change in the future or not, I wouldn't know). But, some of the links that it was mentioned that the spyware was on are still operating and are still actively able to infect devices. This is how various individuals have been able to get samples and begin to look into them. Now, again, there are still a lot of things that need to be figured out before anything truly comes from this, but for now, let's focus on a few of the interesting things about this exploit kit: 1. The "PPL Bypass" bugs (for 17.x) appear to also work on SPTM devices. Some additional context: iOS/iPadOS 17 replaced PPL with SPTM and TXM on some devices. On the relevant versions here (M4 was introduced in 17.4 and iOS/iPadOS 18 shift M2 to SPTM), this encompasses out to: - PPL Devices: A12-A14/M2 - SPTM Devices: A15-A17 This change doesn't affect necessarily the flow of bugs (they usually will require PAC Bypasses) but it can potentially break certain bugs that would work for a PPL Bypass. Based on what we have seen, however, it appears these bugs do work on SPTM devices, which does mean - if anything comes from this - this will likely work on all devices for 17.0-17.2.1. 2. There's enough bugs here for a WebKit jailbreak (and TrollStore installation method for relevant versions). The entire goal of every chain that can be exploited with this kit is that it is designed to be a one-click exploit - you go to a malicious website and immediately have your crypto logins, location, camera roll, and other stuff siphoned off to China or Russia (depending on which type you get exploited by). Now, as we've established, this is a full kit of exploits for a variety of versions starting with 13.0, and the kit is ultimately able to accomplish a one-click up to/including 16.7.4 (EoL) and 17.2.1 for all devices. Because of that, all the bugs that would be needed for a WebKit-based jailbreak for 13.0-16.7.4/17.0-17.2.1 are present. Now, of course, that would require someone to put in the effort to exploit all of these bugs in a WebKit environment, but the option for someone to do that still exists. Additionally, for those on TrollStore versions (14.0b2-16.6.1/16.7 RC (20H18)/17.0): As it would be possible to achieve a WebKit-based jailbreak, that also inherently means a WebKit-based TrollStore installer would also be viable. (Note: If one did happen, it would obsolete almost every other method except for TrollHelperOTA (as that doesn't exploit a WebKit bug or kernel bug at all)).
10
29
160
32,296