Tuesday, April 15, 2025
HomeAppleCheckm8 - Hacker Published "Unpatchable" Jailbreak for Millions of iOS Devices from...

Checkm8 – Hacker Published “Unpatchable” Jailbreak for Millions of iOS Devices from iPhone 4S to iPhone X

Published on

SIEM as a Service

Follow Us on Google News

An iOS security researcher with twitter handle Axi0mX released an Epic Jailbreaking tool dubbed Checkm8, exploit iOS device form iPhone 4S (A5 chip) to iPhone 8 and iPhone X (A11 chip).

The tool is compatible with Mac and Linux and the tool will not work for the virtual machine. Also, the tool can be downgraded to jailbreak iPhone 3GS. To note Checkm8 is only the exploit not the Jailbreak tool with Cydia.

The exploit was published for free, by using the exploit iOS jailbreak community and researchers can develop a complete jailbreak tool.

- Advertisement - Google News

Checkm8 leverages bootrom (called “SecureROM” by Apple), the bootrom in read-only mode, it is the first code executed on iphone while booting, exploits at this level can be fixed only by a hardware revision.

According to the researcher, the “EPIC JAILBREAK” vulnerability is permanent, “unpatchable bootrom exploit for hundreds of millions of iOS devices.”

Features Included with Exploit – Checkm8

  • Jailbreak and downgrade iPhone 3GS (new bootrom) with alloc8 untethered bootrom exploit. 🙂
  • Pwned DFU Mode with steaks4uce exploit for S5L8720 devices.
  • Pwned DFU Mode with limera1n exploit for S5L8920/S5L8922 devices.
  • Pwned DFU Mode with SHAtter exploit for S5L8930 devices.
  • Dump SecureROM on S5L8920/S5L8922/S5L8930 devices.
  • Dump NOR on S5L8920 devices.
  • Flash NOR on S5L8920 devices.
  • Encrypt or decrypt hex data on a connected device in pwned DFU Mode using its GID or UID key.

Axi0mX also published a Jailbreak guide, Others features will be added soon, he said.

“A bootrom exploit for older devices makes iOS better for everyone. Jailbreakers and tweak developers will be able to jailbreak their phones on the latest version, and they will not need to stay on older iOS versions waiting for a jailbreak. They will be safer.”

Axi0mX said this vulnerability cannot be exploited remotely, the attackers need to have physical access to the device.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity and hacking news updates.

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Microsoft Teams File Sharing Unavailable Due to Unexpected Outage

Microsoft Teams users across the globe are experiencing significant disruptions in file-sharing capabilities due...

Cloud Misconfigurations – A Leading Cause of Data Breaches

Cloud computing has transformed the way organizations operate, offering unprecedented scalability, flexibility, and cost...

Security Awareness Metrics That Matter to the CISO

Security awareness has become a critical component of organizational defense strategies, particularly as companies...

New ‘Waiting Thread Hijacking’ Malware Technique Evades Modern Security Measures

Security researchers have unveiled a new malware process injection technique dubbed "Waiting Thread Hijacking"...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Microsoft Teams File Sharing Unavailable Due to Unexpected Outage

Microsoft Teams users across the globe are experiencing significant disruptions in file-sharing capabilities due...

Cloud Misconfigurations – A Leading Cause of Data Breaches

Cloud computing has transformed the way organizations operate, offering unprecedented scalability, flexibility, and cost...

Security Awareness Metrics That Matter to the CISO

Security awareness has become a critical component of organizational defense strategies, particularly as companies...