People are using iPad OS features on their iPhones

https://news.ycombinator.com/rss Hits: 9
Summary

The newly released itunesstored & bookassetd sbx escape exploit allows us to modify the MobileGestalt.Plist file to change values inside of it.This file is very important since it contains all the details about the device. Its type, color, model, capabilities like Dynamic Island, Stage Manager, multitasking, etc. are all present inside that file.Naturally, Apple has encrypted the key-value pairs, but people have managed to figure out most of them over the years.Modification of the MobileGestalt file has allowed many tweaking applications like Nugget, Misaka, and Picasso to exist over the years.Recently, developer Duy Tran posted an intriguing video of their iPhone having iPad features like actual app windows, the iPadOS dock, stage manager, etc. This was done with the new exploit that uses a maliciously crafted downloads.28.sqlitedb database to write to paths normally protected by the Sandbox.Fortunately, MobileGestalt.Plist is one of these paths, and you can actually modify your iPhone to have iPadOS features. Supported iOS versions and devicesThe new itunesstored & bookassetd sandbox escape exploit supports all devices on iOS up to iOS 26.1 and iOS 26.2 Beta 1.This exploit circulated for a while on the internet and was used for iCloud Bypass purposes since it can write to paths and hacktivate.This will very likely be used to update tools like Nugget, Misaka, etc.It鈥檚 quite a powerful exploit. It can write to most paths controlled/owned by the mobile user. It cannot write to paths owned by the root user.Obtaining the MobileGestalt.Plist file from the deviceThere are several ways to go about this. Some Shortcuts allow you to obtain the plist still, tho some of these floating around have been patched.I didn鈥檛 bother. I just made a new Xcode application and read the file at /private/var/containers/Shared/SystemGroup/ systemgroup.com.apple.mobilegestaltcache/Library/Caches/com.apple.MobileGestalt.plistIt鈥檚 as simple as:import SwiftUI import UniformTypeIdentifiers struc...

First seen: 2025-11-17 06:57

Last seen: 2025-11-18 01:48