New iOS 27 Jailbreak Boots Custom Firmware and Root SSH on iPhone 11 Pro

A new jailbreak targeting iOS 27.0 beta 2 has surfaced, leveraging the usbliter8 exploit chain to achieve PWN DFU mode, boot custom firmware, and enable root SSH access on the iPhone 11 Pro (iPhone12,3).

The release builds on a SecureROM vulnerability disclosed by Paradigm Shift and integrates a hardware-based exploitation rig using an RP2350 microcontroller.

The jailbreak exploits a SecureROM flaw affecting A12 and A13 chips (and S4/S5 on Apple Watch), allowing an external device to force the target into PWN DFU mode.

New iOS 27 Jailbreak Boots Custom Firmware

Researchers use a Raspberry Pi Pico 2 wired to a modified Lightning cable, with VBUS, GND, and data lines D+ and D mapped to specific GPIO pins, to trigger the exploit over USB.

Unlike userland or kernel-only jailbreaks, this method requires physical hardware and currently only supports one device model, as offsets for the userland patches are hardcoded to build 24A5370h.

The chain patches multiple system components to bypass Apple’s security stack. Kernel patches disable restore-mode checks and sandbox file-mapping restrictions, enabling execution from /var/jb.

The AMFIIsCDHashInTrustCache function is neutralized, effectively trusting all code signatures.

Both coreauthd and ctkd are patched to prevent Secure Enclave Processor (SEP) crashes, while mobileactivationd is modified to force a “hacktivated” state that bypasses Apple’s activation servers.

A launchd disabled-services override also stops ScreenTimeAgent from deadlocking Setup Assistant during first boot. This is not a conventional jailbreak but closer to a development-only firmware bypass.

Running the restore process permanently breaks Secure Enclave Processor (SEP) functionality, passcode and biometric security, Wi-Fi and baseband connectivity, and most standard Apple services such as iMessage, iCloud, and Activation.

Bluetooth continues to work only partially. Researchers explicitly warn that this should only be attempted on a dedicated spare device, never a primary iPhone.

According to usbliter8 Advisory, it begins with triggering PWN DFU mode via the Pico 2 rig, followed by flashing custom firmware using make_cfw.py and restore_cfw.sh.

Next, an SSH ramdisk (SSHRD) boot is used to extract the SEP ticket, after which a full custom boot is performed. Finally, post-boot patching bypasses Setup Assistant’s activation and ScreenTime checks.

Once booted, users gain root access via dropbear SSH, using the default password alpine, and can sideload Sileo as a package manager through a Cydia-style bootstrap.

While framed as a developer research tool, the exploit chain demonstrates that SecureROM-level vulnerabilities remain exploitable on A12 and A13 silicon, even on newer iOS releases like 27.0 beta 2.

The reliance on physical PWN DFU access limits real-world attack surface, but it underscores ongoing weaknesses in Apple’s boot-chain trust model that security researchers continue to probe ahead of full firmware hardening in later iOS builds.

Cut SOC investigation blind spots and contain threats earlier to reduce response costs and business disruption with ANY.RUN. 

Tamilselvan
Tamilselvanhttps://cyberpress.org/
Tamilselvan is an Investigative cybersecurity journalist dedicated to breaking stories on ransomware cartels, data breaches, and state-sponsored espionage.

Trending News

Related Stories