State Of IOS Jailbreaking In 2025 - Lars Fröder
Lars Fröder (Celebrate Labs)
Nullcon Goa 2025 · Main Stage
Overview
In this insightful talk, Lars Fröder, a prominent security researcher and developer of widely recognized tools like TrollStore and Dopamine, delves into the intricate world of iOS jailbreaking, offering a historical perspective, a detailed technical breakdown of his contributions, and a stark outlook on its future in 2025. Fröder, who has been involved in iOS development since 2017 and security research since 2022, primarily discusses work undertaken in his free time, highlighting the motivations behind jailbreaking and the escalating challenges faced by the community.

Key moments
- 0:00 Introduction and motivations for iOS jailbreaking
- 2:40 Deep dive into iOS code signature structure
- 4:47 Explaining entitlements and app permissions on iOS
- 6:00 The signature blob and Code Directory (CD) hash
- 8:00 Understanding iOS trust levels for process isolation
State Of IOS Jailbreaking In 2025 - Lars Fröder
Speakers: Lars Fröder, Security Researcher, Celebrate Labs
Conference: Nullcon
YouTube: https://www.youtube.com/watch?v=lU2lxGtLN6k
Overview
In this insightful talk, Lars Fröder, a prominent security researcher and developer of widely recognized tools like TrollStore and Dopamine, delves into the intricate world of iOS jailbreaking, offering a historical perspective, a detailed technical breakdown of his contributions, and a stark outlook on its future in 2025. Fröder, who has been involved in iOS development since 2017 and security research since 2022, primarily discusses work undertaken in his free time, highlighting the motivations behind jailbreaking and the escalating challenges faced by the community.
The presentation meticulously unpacks the fundamental mechanisms of iOS code signing, a critical security pillar enforced by Apple, before dissecting two of Fröder's pivotal tools: TrollStore and the Dopamine jailbreak. TrollStore represents a novel approach to persistent application installation on specific iOS versions by exploiting a sophisticated code signing bypass. Dopamine, on the other hand, is a more traditional, full-fledged jailbreak designed to achieve comprehensive system control by overcoming advanced hardware and software mitigations.
This talk is crucial for security researchers, iOS developers, and anyone interested in the inner workings of Apple's security architecture and the cat-and-mouse game between platform hardening and exploitation. It not only explains complex vulnerabilities and exploitation techniques but also provides a sobering assessment of the future viability of public jailbreaks, suggesting that the era of widespread, readily available iOS jailbreaks may be drawing to a close due to Apple's relentless security enhancements.
Background
▶ Watch: Introduction and motivations for iOS jailbreaking (0:00)
The primary motivation behind iOS jailbreaking, as articulated by Fröder, is to enable users and researchers to run unsigned or third-party software on iPhones and iPads outside the confines of the official App Store. While recent regulatory changes in the EU are beginning to introduce alternative app distribution methods, jailbreaking predates and offers far more extensive capabilities. Beyond simply installing non-App Store applications, jailbreaking provides enhanced introspection capabilities, allowing researchers to deploy tools like Frida and lldb for in-depth system analysis and debugging. End-users often seek jailbreaks to install system extensions that modify or extend core system functionalities in ways not permitted by Apple.
At the heart of iOS security is mandatory code signing. Every piece of software executable on an iPhone must be cryptographically signed in a manner compliant with Apple's stringent requirements. This system forms the basis of Apple's control over its ecosystem and, by extension, its 30% App Store fee. Fröder outlines three primary methods for code signing:
- Ad-hoc signed binaries: Used for files shipped with the operating system itself, these lack a traditional signature blob.
- App Store distribution: Developers submit binaries to Apple, which then signs and distributes them.
- Developer accounts: Allows developers to sign and install applications for a limited duration (7 days normally, or 1 year with a $100 annual fee).
The binary format used on Apple platforms is Mach-O. A Mach-O file contains a header, followed by load commands that describe its internal sections. Crucially, the LC_CODE_SIGNATURE load command points to the location of the code signature within the file. This code signature is a complex structure composed of several sub-blobs:
- The Code Directory (CD) is the most critical. It contains cryptographic hashes (e.g., SHA-1, SHA-256) of all executable pages within the binary. A single binary can contain multiple Code Directories with different hash types. The CD serves as a comprehensive hash of all interesting parts of the file, effectively providing a unique identifier.
- Entitlements are a property list (or DER-encoded equivalent) that describe the permissions a binary can execute with. These dictate access to kernel drivers, file paths, sandbox restrictions, and debugging capabilities. Entitlements are checked by the kernel or other processes at runtime.
- The Signature Blob contains cryptographically signed hashes of the Code Directories, typically signed by an Apple or developer certificate. Ad-hoc signed binaries, as mentioned, have an empty signature blob. A key detail for later exploits is that a file can potentially have multiple signers. The Code Directory Hash (CD hash), a hash of the Code Directory itself, uniquely identifies an executable or library and is recalculated during validation to ensure file integrity against the signed value.
Every executable and dynamic library on iOS requires a valid code signature to run. This enforcement occurs when functions like posix_spawn or execve are called to launch a file.
Beyond basic code signing, iOS employs trust levels to enforce more granular isolation between different process types. These trust levels dictate:
- Whether a process can
dlopenor map a library with a lower trust level. - Whether a process can obtain a task port (granting read/write access to address space) to another process with a higher trust level.
Three relevant trust levels are identified:
- Level 8 (System Binaries): Processes whose CD hash is found in a kernel-maintained list of trustworthy binaries (the trust cache). No further checks are performed once a match is found.
- Level 7 (App Store Applications): Processes validated by the
CoreTrustkernel driver (via theAppleMobileFileIntegritybridge) as being legitimately signed by an App Store certificate. - Level 5 (Developer Signed Applications): Processes whose developer certificate is verified as valid by the user-space service
amfid, provided Developer Mode is enabled (introduced in iOS 16).
In essence, processes running with lower trust levels have restricted access to resources or other processes operating at higher trust levels, forming a crucial layer of defense in depth.
Key Findings
▶ Watch: Deep dive into iOS code signature structure (2:40)
Lars Fröder's talk highlights two major contributions to the iOS jailbreaking landscape: TrollStore and the Dopamine jailbreak. Both tools represent significant achievements in bypassing Apple's robust security mechanisms, each with distinct capabilities and target use cases.
TrollStore emerged as a groundbreaking utility that leverages a specific code signing bypass vulnerability (CVE-2023-41991) within the CoreTrust kernel extension. This bug allows for the persistent installation of arbitrary, untrustworthy applications on supported iOS versions (initially patched in iOS 17.0.1 and 16.7). Unlike traditional jailbreaks that often require re-execution after a reboot, TrollStore's bypass is a logic flaw in code signature validation, enabling installed applications to persist across reboots. This provides a "somewhat persistent" installation method without fully jailbreaking the device. However, a key limitation is that only explicitly signed binaries—those processed by TrollStore—can execute, and it cannot provide system-wide tweak injection or spawn background services (launch daemons).
The Dopamine jailbreak was developed to address the limitations of TrollStore and provide a more comprehensive solution for achieving full system control. Dopamine targets iOS versions 15 through 16.5 on all devices, leveraging a combination of powerful exploit primitives: a kernel read/write vulnerability (kfd, patched in 16.7) and a Page Protection Layer (PPL) bypass (demonstrated by Kaspersky, patched in 16.6/16.5.1). By gaining these low-level capabilities, Dopamine can automate the code signing bypass process, allowing any unsigned binary to execute system-wide, spawn launch daemons, and facilitate system-wide tweak injection—features characteristic of a "traditional" jailbreak.
A critical finding revealed in the talk is the increasingly challenging state of iOS jailbreaking in 2025. Fröder points out that key exploit classes, such as physical use-after-free bugs prevalent in iOS 16, have been largely eradicated in iOS 17.3. Furthermore, the Persona Management entitlement, which TrollStore utilized to gain root privileges, was patched in iOS 18.0. Apple also introduced SPTM (Secure Page Table Monitor) in iOS 17.0 as a more hardened replacement for PPL, further complicating kernel-level memory manipulation. Fröder concludes that the community currently possesses "zero out of four" necessary exploit types for an iOS 17/18 jailbreak, leading to a pessimistic "ETA never" for future public kernel exploitation unless unforeseen changes occur.
Technical Deep Dive
▶ Watch: Explaining entitlements and app permissions on iOS (4:47)
The technical core of Fröder's presentation revolves around the intricate mechanisms of iOS code signing and how TrollStore and Dopamine exploit or bypass them.
TrollStore: The CoreTrust Code Signing Bypass (CVE-2023-41991)
The TrollStore bypass hinges on a complex logic bug within the CoreTrust kernel extension, which is responsible for validating App Store application signatures. This vulnerability, initially discovered by a friend named Alfie and later reconstructed and implemented into TrollStore, exploits several quirks in CoreTrust's signature validation logic:
- Multiple Signers and Single Return Value: A single code signature can contain multiple signers. The bug manifests because
CoreTrustiterates through and checks every signer, but it writes all return values to the same attribute storage. In practice, this means only the last signer's validation result is effectively considered, while all preceding signers are skipped or overwritten. - First Signer Data Return: Despite checking the last signer,
CoreTrustreturns the Code Directory Hash (CD hash) of the first signer back toamfid(the AppleMobileFileIntegrity daemon). - App Store Check on First Signer: Crucially, the check for whether a binary is "App Store signed" also relies on the data from the first signer.
To exploit this, TrollStore constructs a specially crafted code signature with two signers:
- Stolen SHA-1 Code Directory: A SHA-1 Code Directory is "stolen" from any valid App Store application. This stolen CD is designed to be completely invalid for TrollStore's actual binary, as its page hashes won't match.
- Custom SHA-256 Code Directory: A SHA-256 Code Directory is generated by TrollStore to be perfectly valid for its own binary. The kernel preferentially uses SHA-256 over SHA-1, which is key here.
- Signature Blob Construction:
- First Signer (TrollStore's Certificate): This signer is controlled by TrollStore. It signs a blob containing the CD hashes for both the SHA-1 (stolen, invalid for its code) and SHA-256 (custom, valid for its code) Code Directories.
- Second Signer (Stolen App Store Signature): This signature is stolen from the same App Store app from which the initial SHA-1 Code Directory was taken. For this signer, the SHA-1 slot for the main Code Directory will be correct (matching the stolen SHA-1 CD), but its SHA-256 slot will contain an invalid hash (as it was never meant for TrollStore's custom SHA-256 CD).
When CoreTrust validates this signature:
- It checks the second (stolen App Store) signer. The SHA-1 portion of this check passes because the stolen SHA-1 CD hash matches the signature.
- Due to the bug, the validation state is effectively determined by this last signer.
- However,
CoreTrustreturns the CD hash of the first signer (TrollStore's controlled certificate) toamfid. - The App Store certificate check also uses the first signer's data, which TrollStore controls.
This convoluted logic allows TrollStore to appear as a valid App Store application to amfid and the kernel, despite running arbitrary code. Furthermore, because TrollStore controls the SHA-256 Code Directory, it can declare any entitlements it desires, granting extensive permissions, though not higher trust levels (e.g., it cannot obtain a task port to a system process).
TrollStore Application: The TrollStore app itself is signed using this bypass. It then leverages the Persona Management entitlement, which allows it to spawn a different process as root. This grants it the necessary privileges to apply the same CoreTrust bug to any IPA file opened within it. TrollStore extracts the executables from the IPA, applies the crafted signature, and installs them system-wide, making them appear as legitimate App Store applications that persist across reboots.
Dopamine: Full System Control and Automated Code Signing Bypass
While TrollStore offered persistence, it couldn't provide system-wide tweak injection or run background services. The Dopamine jailbreak was developed to achieve these capabilities, requiring a more profound level of system control. Modern jailbreaks face significant challenges:
- W^X (Write XOR Execute) memory protection: Kernel code is strictly read-only and executable, preventing direct patching.
- Pointer Authentication Codes (PAC): Sensitive pointers (e.g., in kernel structures) are cryptographically protected, preventing modification without a bypass.
- Page Protection Layer (PPL): Critical kernel memory pages are additionally protected, making them harder to modify even with kernel read/write.
Dopamine's approach is data-only, avoiding direct kernel code modification by instead hooking user-space code. It relies on two fundamental exploit primitives:
- Kernel Read/Write: Achieved using the
kfdkernel exploit, patched in iOS 16.7. - PPL Bypass: Demonstrated by Kaspersky, patched in iOS 16.6 and 16.5.1 on some devices, but working on all devices up to 16.5.
These primitives are essential because all code signing enforcement mechanisms are protected by PPL. Dopamine targets iOS 15 to 16.5.
Dynamic Trust Cache Manipulation:
The key to Dopamine's code signing bypass lies in manipulating the dynamic trust cache.
- Static Trust Cache: Embedded in the operating system, protected by KTRR (Kernel Trust Region Register), making it completely read-only at runtime.
- Dynamic Trust Cache: Loaded into memory after the system boots (e.g., for Xcode debugging images). Crucially, it is only protected by PPL, not KTRR.
With a PPL bypass, Dopamine can:
- Allocate its own trust cache structure in kernel address space.
- Write arbitrary CD hashes into this custom trust cache.
- Insert this custom trust cache into the kernel's linked list of dynamic trust caches.
This grants the highest trust level execution for any binary whose CD hash is added, along with any desired entitlements. Furthermore, any library added to this dynamic trust cache can be mapped by every process, including system processes, which is vital for jailbreak functionalities.
Automated System-Wide Code Signing Bypass:
To automate this and allow any binary to execute, Dopamine employs a multi-component strategy:
launchdHook:launchd(pid 1) is the system'sinitprocess, managing all user-space processes. Dopamine injects a dynamic library intolaunchdand hijacks its inter-process communication (IPC) mechanisms. Thislaunchdhook acts as the Jailbreak Server, endowed with the PPL read/write primitive. All other processes communicate with this server for jailbreak services.- System Hook via
dyldPatching: To inject a system hook into every process, Dopamine patches the dynamic linker (dyld).
- The
DYLD_INSERT_LIBRARIESenvironment variable (Apple's equivalent ofLD_PRELOAD) is normally ignored system-wide. Dopamine'sdyldpatch makes this variable work universally. - When a new process spawns, its patched
dyldis the first code to execute. It immediately contacts the Jailbreak Server, which then performs necessary patches (e.g., weakening the process's sandbox) and injects Dopamine's system hook library into it. - The system hook then intercepts calls to
posix_spawnandexecve. Before a binary is spawned, its path is sent to the Jailbreak Server, which calculates its CD hash and adds it to the dynamic trust cache. The environment variables for the child process are also modified to includeDYLD_INSERT_LIBRARIES, ensuring the system hook propagates.
- Library Validation Bypass via
fcntlHook: Binaries often depend on dynamic libraries loaded at runtime. To ensure these libraries also bypass code signing, Dopamine hooks thefcntlfunction withindyld.fcntlis used to attach signatures to files. By interceptingfcntlcalls, Dopamine extracts the library's path, sends it to the Jailbreak Server for trust cache injection, and then calls the originalfcntl. This effectively disables Library Validation system-wide.
The combined effect of these hooks and dyld patches results in a complete code signing bypass: any binary or library can execute system-wide with highest trust levels.
Tweak Injection:
A common user-facing feature of jailbreaks is tweak injection, allowing third-party developers to modify system processes. Dopamine enables this by adding an extra dlopen call for the TweakLoader library. This library, typically provided by a third-party package, handles the logic for discovering and loading other tweak libraries into running processes, granting extensive customization capabilities.
Demo / Proof of Concept
▶ Watch: The signature blob and Code Directory (CD) hash (6:00)
Fröder presented several demonstrations of his work:
For TrollStore, a proof of concept was shown where a binary signed using the CoreTrust bug printed a "nice troll face" to the command line, illustrating the successful execution of an arbitrarily signed application.
For the Dopamine jailbreak, the demonstration showcased the full user experience. This included:
- The Dopamine application itself, which features a prominent "Jailbreak" button to initiate the process.
- A Graphical User Interface (GUI) package manager (similar to Cydia or Sileo), allowing users to browse, install, and manage third-party software and tweaks.
- An example of a terminal application running on the jailbroken device, demonstrating the ability to execute arbitrary binaries and interact with the underlying iOS file system with elevated privileges.
These demonstrations visually confirmed the practical application and functionality of both TrollStore's persistent app installation and Dopamine's comprehensive system-wide control.
Defensive Implications
▶ Watch: Understanding iOS trust levels for process isolation (8:00)
The detailed analysis of iOS code signing and the sophisticated bypass techniques employed by TrollStore and Dopamine underscore the continuous and escalating cat-and-mouse game between Apple's security engineering efforts and the jailbreaking community.
From a defensive standpoint, several key implications emerge:
- Apple's Hardening is Effective: The talk clearly articulates how Apple's successive mitigations—such as KTRR (Kernel Trust Region Register), PAC (Pointer Authentication Codes), PPL (Page Protection Layer), and its successor SPTM (Secure Page Table Monitor)—are significantly raising the bar for exploitation. The shift from PPL to SPTM in iOS 17, for instance, represents a more hardened approach to protecting sensitive kernel memory. The fact that key exploit classes like physical use-after-free have been "mostly killed" in iOS 17.3, and the Persona Management entitlement (used by TrollStore for root access) was patched in iOS 18.0, demonstrates Apple's proactive patching and architectural improvements.
- Importance of Timely Updates: The vulnerabilities exploited by TrollStore (CVE-2023-41991) and Dopamine (
kfdand Kaspersky's PPL bypass) have all been patched in later iOS versions (e.g., 16.7, 17.0.1, 16.6). For end-users and organizations, the most effective defense against these specific exploits is to maintain devices on the latest patched iOS versions. This mitigates the risk of devices falling victim to these publicly known and utilized jailbreak techniques.
- Jailbroken Devices as Security Risks: The capabilities offered by jailbreaks—running unsigned code, achieving system-wide tweak injection, modifying sandboxes, and gaining root privileges—fundamentally undermine iOS's security model. For enterprises, the presence of jailbroken devices on their networks or accessing corporate resources poses a significant security risk. Such devices are more susceptible to malware, data exfiltration, and unauthorized access due to the weakened security posture. Organizations should implement robust Mobile Device Management (MDM) solutions and jailbreak detection mechanisms to identify and restrict access for compromised devices.
- Sophistication of Code Signing Bypass: The
CoreTrustbug exploited by TrollStore highlights that even seemingly robust security mechanisms can have subtle logic flaws that lead to severe bypasses. Defenders need to be aware that code signing, while a strong defense, is not infallible. The multi-layered approach taken by Dopamine, involvinglaunchdhooks,dyldpatching, and dynamic trust cache manipulation, illustrates the depth of technical expertise required to achieve system-wide code execution and how core system components can be subverted.
- Future Outlook: Fröder's pessimistic "ETA never" for future public jailbreaks on iOS 17/18 signifies a potential turning point. If public kernel exploitation becomes prohibitively difficult or impossible without state-sponsored resources, the landscape of iOS security research and exploitation will shift dramatically. This makes the existing, patched vulnerabilities and the historical context provided in the talk even more valuable for understanding past security challenges and future trends.
Key Takeaways
- iOS Code Signing Complexity: Apple's security relies heavily on a multi-layered code signing architecture, including Mach-O format, Code Directories (with SHA-1/SHA-256 hashes), Entitlements, and Signature Blobs, enforced at binary execution and library mapping.
- TrollStore's Sophisticated Bypass: TrollStore leveraged a complex logic flaw (CVE-2023-41991) in the
CoreTrustkernel extension, exploiting how multiple signers are handled and returned, to persistently install arbitrary applications on iOS versions up to 17.0. - Dopamine's Comprehensive Control: The Dopamine jailbreak achieves full system control on iOS 15-16.5 by combining powerful kernel read/write (
kfdexploit) and Page Protection Layer (PPL) bypass primitives, overcoming hardware-enforced W^X memory and PAC protections. - Automated Code Signing Bypass: Dopamine automates system-wide code execution by manipulating dynamic trust caches, patching the
dyld(dynamic linker) to enableDYLD_INSERT_LIBRARIES, hookinglaunchdas a Jailbreak Server, and interceptingposix_spawn,execve, andfcntlcalls. - Bleak Future for Public Jailbreaking: The talk presents a pessimistic outlook for future public iOS jailbreaks (iOS 17/18 and beyond), citing Apple's effective mitigation of key exploit classes (e.g., physical use-after-free), patching of critical entitlements (Persona Management), and the introduction of hardened protections like SPTM.
- Security vs. Customization: While jailbreaking offers unparalleled introspection and customization capabilities, it fundamentally weakens the iOS security model, posing significant risks for users and organizations, and is becoming increasingly difficult to achieve on modern iOS versions.
About the Speaker(s)
Lars Fröder is a dedicated security researcher based in Germany. His journey into the iOS ecosystem began with iOS development in 2017, transitioning to focused security research in 2022. He is currently employed at Celebrate Labs, though the significant work discussed in this presentation, including the development of TrollStore and the Dopamine jailbreak, was undertaken in his personal time. Over the years, Fröder has also developed several system extensions designed for use with jailbreaks, solidifying his reputation as a key contributor to the iOS security and jailbreaking community. He also acknowledged the crucial contribution of "Alfie" who initially discovered and reversed the CoreTrust bug that TrollStore exploits, presenting some of that work on Alfie's behalf.
Reviews
Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT
Fröder is the real deal — he built both tools under discussion, and the CVE-2023-41991 CoreTrust walkthrough is one of the cleanest explanations of a multi-signer logic confusion bug I've seen presented publicly. The Dopamine architecture (launchd hook as jailbreak server, dyld patch to universalize DYLDINSERTLIBRARIES, fcntl interception for library validation bypass) is presented with enough precision that a competent researcher could actually implement it. The 'ETA never' conclusion on iOS 17/18 public jailbreaks is sobering and, based on the exploit-class graveyard he walks through, well-earned.
Heather Calloway (CISO) — WEAK
Technically credible and well-structured, but this talk is pure exploit engineering with no meaningful bridge to operators, defenders, or decision-makers. The defensive implications section is thin and generic — it does not change how any security program actually runs.