Exclusive: iOS 5+ Untethered Jailbreak

For you non-believers, a new video will be up later today.

@reagentx, a popular photographer, programer, and violinist has finally has released the details of his iOS 5 untethered jailbreak to the public. This jailbreak is untethered and currently works on iOS 5. Due to the sheer awesomeness of the method and tools used to operate the jailbreak, it could potentially jailbreak every iOS that will be released in the future.

For those of you following him on twitter you would have noticed him writing about the exploit from almost his existence on twitter. Sure it still has bugs (like the wifi one) but every day it grows closer. Whether or not this becomes a public release, I’m sure that the CDT can learn from this. So you people who are dying to download cracked apps…you’ll get your fix, through us or through the Chronic Dev Team.

I have no release date for this tool because it is still being actively worked on. What I do have is a Youtube video demonstrating the fact that it is untethered and it actually works.

Note that safari doesn’t work on a tethered jailbreak unless The device is booted tethered. The fact that safari had cydia.com is regardless to the point made in this video.

Words from the dev.:

Henceforth, the iOS 5 beta software was unable to be untethered jailbroken by any known application/exploit. We do know that it was susceptible to Comex’s PDF exploit, but because of a leak that was not possible anymore.

We all also know that iOS 4.3.3 was the last operating system to be released that could be jailbroken untethered.

Well, this gave me an idea. What I’d one was able to unpack the vulnerable parts of iOS 4.3.3 and keep the functionality of iOS 5? That would be difficult though.

And it proved so. This was not an easy task. I had to be able to crack the ipsw’s open, remove the vulnerable parts, and replace them inside an iOS 5 ipsw. Instead of modifying the ipsw (requires root) I made it create a new ipsw, on the desktop.

All you have to do is then custom-restore (you have to have a dev account) and then email the 4.3.3 PDF to yourself. I tried making visiting jailbreakme.com work, but it refuses to recognize the OS.

And that is how I have jailbroken iOS 5 Untethered.

Screw the trolls.

If you want to keep updated on this jailbreak please feel feel to follow this site or follow the developer on twitter @reagentx.

http://rxtech.tk

This will be the official blog with updates on this jailbreak. If you don’t hear it here, his blog, or either of our twitter accounts, it’s not an official update.

We really don’t care if you believe us or not, this exploit is quite possible. Ask any member of either Dev team. The part that some of you may not believe is whether we have it working or not, we do.

4 thoughts on “Exclusive: iOS 5+ Untethered Jailbreak

  1. Why this can’t be done? Easy, first of all, for editing an IPSW and loading it into a device you need a bootrom exploit (in this case limera1n). Then you edit the IPSW, edit the kernelcache, iBoot, WTF, iBEC, iBSS and LLB so they accept the custom root partition. Then you restore, and you’ll get conflict errors due to the incompatible parts of each firmware or due to SHSH checks. In case you don’t get the errors, and the restore goes “well”, the device still has to boot and not hang on the Apple logo (which is the most probably thing that can happen if you reach here) then you can try to exploit it with the Saffron exploit (if the first check on the webpage allows you), and if you reach to see Cydia on screen (most likely it’ll fail due to the new stashing system not adapted to iOS5). If the install suceeds, reboot, and then you’ll find on a recovery loop, DFU loop, or simply Apple logo forever. That’s all.

Leave a comment