Workflow: Jailbreak Detection Bypass
Use when an app exits, shows a warning, or disables features on jailbroken devices.
Detection Vectors to Defeat
- File existence:
/Applications/Cydia.app,/bin/bash,/usr/sbin/sshd,/etc/apt,/private/var/lib/apt. - URL scheme probe:
cydia://,sileo://,zbra://. - Writable path checks:
/private/jailbreak.txt. - Dynamic library enumeration:
_dyld_image_count,_dyld_get_image_namehunting forMobileSubstrate,frida,cynject. fork()/ptracereturning unexpectedly.- Sandbox escape via
staton/private,/.
Bypass Options (try in order)
- Objection:
> ios jailbreak disable - Frida:
frida -U -f <bundle_id> -l scripts/jailbreak_bypass.js --no-pause - Cydia tweaks: Liberty Lite, Shadow, A-Bypass (install + add app to hide list).
- Custom hook of the specific detection method discovered via
class-dump.
Identifying Custom Detection
class-dump -H App.app/App -o headers/
grep -RIn -iE 'jailbreak|cydia|isJailbroken|checkRoot' headers/Then in Frida, intercept the found selector:
var cls = ObjC.classes.SecurityChecker;
Interceptor.attach(cls['- isJailbroken'].implementation, {
onLeave: function (retval) { retval.replace(0); }
});Screen-based Prompt Confirmation
Apps sometimes show a "Jailbreak detected" modal. Capture it with Mobile MCP to prove trigger, then re-run with bypass to confirm absence.
Anti-Anti-Debug
If ptrace(PT_DENY_ATTACH) trips on spawn, hook ptrace to return 0 and sysctl to scrub P_TRACED from the kinfo_proc flags (snippet in references/frida_ios_snippets.md); spawn with --no-pause.