matteyeux Profile Banner
matteyeux Profile
matteyeux

@matteyeux

10,018
Followers
218
Following
3,233
Media
28,421
Statuses

0x1fc080000
Joined April 2011
Don't wanna be here? Send us removal request.
@matteyeux
matteyeux
5 years
Here is an iPhone 7 booting Android !
190
2K
6K
@matteyeux
matteyeux
5 months
Looks like someone dropped a Linux kernel 0day
Tweet media one
41
534
3K
@matteyeux
matteyeux
1 year
I still find this funny that Apple keeps adding this stop sign on some rkos fw even on the Vision Pro one
Tweet media one
8
98
1K
@matteyeux
matteyeux
6 years
@nixcraft Reminds me this comic from @CommitStrip
7
236
700
@matteyeux
matteyeux
4 years
Patched version of checkra1n + working KPF on iPhone 7/14.0 (no sep stuff)
Tweet media one
56
92
648
@matteyeux
matteyeux
3 years
Pangu Team showed iOS 15 beta 4 jailbreak on iPhone 11 Pro at MOSEC
41
54
458
@matteyeux
matteyeux
4 years
Attack Secure Boot of SEP
Tweet media one
4
120
385
@matteyeux
matteyeux
8 months
Seems like someone pushed a bunch of iBoot symbols to Hexrays's Lumina server
Tweet media one
9
57
394
@matteyeux
matteyeux
4 years
Nice, this 14.3 exploit works on A13 without any changes
Tweet media one
17
37
349
@matteyeux
matteyeux
5 years
iPhone 11(Pro) SecureROM
Tweet media one
13
40
325
@matteyeux
matteyeux
3 years
A15 SecureROM exploit
Tweet media one
16
56
314
@matteyeux
matteyeux
4 years
Jailbreaks Never Die: Exploiting iOS 13.7 (slides)
8
71
299
@matteyeux
matteyeux
3 months
Well, a decryption tool is now available
@matteyeux
matteyeux
3 months
It looks like iOS 18 OTA firmware images are now encrypted
Tweet media one
7
12
196
0
63
301
@matteyeux
matteyeux
4 years
How to decompress iOS 14.3 sep-firmware for A10 : 1. decrypt file 2. extract compressed part : dd if=sep-firmware.d10.RELEASE.im4p.dec of=sep.compressed skip=65536 bs=1 3. decompress with lzvn : ./lzvn -d sep.compressed sep.bin
Tweet media one
5
81
279
@matteyeux
matteyeux
5 years
SSD Advisory – iOS Jailbreak via Sandbox Escape and Kernel R/W leading to RCE
6
94
260
@matteyeux
matteyeux
5 years
Fugu
Tweet media one
17
24
226
@matteyeux
matteyeux
2 years
[Slides] The hitchhacker’s guide to iPhone Lightning & JTAG hacking
9
81
247
@matteyeux
matteyeux
4 years
also A11 on 14.2b2
Tweet media one
19
39
218
@matteyeux
matteyeux
3 years
Reverse Engineering the M1
7
70
231
@matteyeux
matteyeux
5 years
Recreating an iOS 0-day jailbreak out of Apple’s security patches
2
55
215
@matteyeux
matteyeux
3 years
iOS 15 (19A5261w) iBoot : iBoot-7429.0.72.112.2 Kernel : Darwin Kernel Version 21.0.0: Sat May 22 02:37:35 PDT 2021; root:xnu-7938.0.0.112.1~5/RELEASE_ARM64_T8030
8
20
209
@matteyeux
matteyeux
4 years
Spotted that iPhone prototype ? :P
Tweet media one
14
32
205
@matteyeux
matteyeux
5 years
Wen ETA Redsn0w for iPhone X
9
19
193
@matteyeux
matteyeux
5 years
Here is checkra1n web interface
Tweet media one
9
27
194
@matteyeux
matteyeux
3 years
Exploiting checkm8 with unknown SecureROM for the T2 chip
4
68
206
@matteyeux
matteyeux
6 years
The making of an iOS 11 jailbreak - Kiddie to kernel hacker in 14 sleepless nights
1
92
205
@matteyeux
matteyeux
2 months
Unstripped SPTM found in the wild👀
Tweet media one
12
27
207
@matteyeux
matteyeux
3 years
iOS 15.0 RC (19A344) iBoot d53g f616222bda5f10aadc5dd206c4cfb9dd9f287480e05bb40a61f6b6220412e7b01a7358245838fe2ce2dcce179341bbe3
Tweet media one
1
29
200
@matteyeux
matteyeux
5 years
I don't even know how to use an Android phone
8
6
202
@matteyeux
matteyeux
5 years
Checkra1n command line version
Tweet media one
4
31
192
@matteyeux
matteyeux
2 years
wInd3x, the iPod Bootrom exploit 10 years too late
6
62
200
@matteyeux
matteyeux
4 years
@RazMashat From mosec account on Weibo
Tweet media one
5
52
195
@matteyeux
matteyeux
5 years
iOS 13.3.1. (17D6050) Homepod iBoot bae48ea04ae32b1cb8c17c9b4120ef332b7aa58fae9a0f4393f3698799b02a4de497b0ca369b450c2ab27e7fa2d1701c
Tweet media one
7
28
197
@matteyeux
matteyeux
3 months
It looks like iOS 18 OTA firmware images are now encrypted
Tweet media one
7
12
196
@matteyeux
matteyeux
4 years
Accelerating iOS on QEMU with hardware virtualization (KVM)
2
65
186
@matteyeux
matteyeux
5 years
Since checkra1n 0.9.8.1 you can access AES engine from userland to decrypt kbags. I updated autodecrypt to grab keys from a device
Tweet media one
7
28
181
@matteyeux
matteyeux
4 years
Here is a script to split 64 bits Mach-O files from a decrypted sep-firmware (A11+)
Tweet media one
5
40
182
@matteyeux
matteyeux
4 years
So the vulnerability announced at #MOSEC2020 is in SEPROM. It can't be patched.
5
34
176
@matteyeux
matteyeux
3 years
Apple added firebloom 🔥🌸 in A12 (except TV) and A12X iBoot in iOS 14.5
Tweet media one
5
29
172
@matteyeux
matteyeux
2 years
Mandatory step: open twitter[.]com and brag about Linux on Apple, because internet
Tweet media one
3
9
179
@matteyeux
matteyeux
5 months
Apple Security Research Device Picture Gallery
Tweet media one
4
19
175
@matteyeux
matteyeux
4 years
To decrypt sep kbag with checkra1n 0.12.0 : - sep auto - sep decrypt <kbag>
Tweet media one
6
28
168
@matteyeux
matteyeux
3 years
Nice to see that A14 SecureROM and SEPROM available on !
Tweet media one
4
32
173
@matteyeux
matteyeux
3 years
checkra1n does not work on iOS 15.0/iPhone 7
Tweet media one
7
20
164
@matteyeux
matteyeux
4 years
@blue_kanikama @jon_prosser iPhone SDKs have always been named iPhoneOS
Tweet media one
2
19
169
@matteyeux
matteyeux
6 years
6
21
164
@matteyeux
matteyeux
7 years
Here we are, thanks @tihmstar my iPhone 5C is now jailbroken for life
Tweet media one
Tweet media two
9
10
155
@matteyeux
matteyeux
2 years
I finally have a working setup with the Raspberry Pico and the tamarin fw
Tweet media one
11
16
165
@matteyeux
matteyeux
3 years
Security Research Device Cohort
Tweet media one
4
25
163
@matteyeux
matteyeux
4 years
MagicCFG working without DCSD ✅
Tweet media one
27
33
141
@matteyeux
matteyeux
5 years
9
5
151
@matteyeux
matteyeux
7 years
Is jailbreak still dying ? This month we got : - Houdini - v0rtex - Ian Beer's tfp0 + kdbg - JailbreakMe for 32bits devices
7
40
145
@matteyeux
matteyeux
6 years
No, you can't get tfp0 with the FaceTime bug
7
16
143
@matteyeux
matteyeux
3 years
Replay of the iPhone 13 remote jailbreak demo by Pangu
Tweet media one
1
33
147
@matteyeux
matteyeux
3 years
The qemu fork by @ntrung03 is pretty cool ! It's also possible to debug the A9 SecureROM in IDA 😁
Tweet media one
1
32
150
@matteyeux
matteyeux
4 years
New blog post by Pangu Team
5
40
148
@matteyeux
matteyeux
2 years
So it's possible to boot Ubuntu initrd on iPhone 7
Tweet media one
7
7
148
@matteyeux
matteyeux
2 years
iOS 16.0 - 20A5283p iBoot-8419.0.42.112.1 Darwin Kernel Version 22.0.0: Thu May 26 20:49:02 PDT 2022; root:xnu-8792.0.50.112.3~4/RELEASE_ARM64_T8020
5
17
138
@matteyeux
matteyeux
2 years
My iPhone 14 Pro in DFU is detected as "Debug USB" 🤨
Tweet media one
9
9
139
@matteyeux
matteyeux
7 years
CVE-2017-13868: A fun XNU infoleak
3
71
139
@matteyeux
matteyeux
5 years
DEV iBoot + Diags with menu on iPhone 8
Tweet media one
Tweet media two
Tweet media three
8
16
132
@matteyeux
matteyeux
4 years
FYI : checkra1n does not support yet iOS 14 :P
Tweet media one
Tweet media two
8
19
132
@matteyeux
matteyeux
4 years
Based on @haiyuidesu 's sephelper I made a SEPROM loader for Binary Ninja
Tweet media one
10
29
130
@matteyeux
matteyeux
5 years
KTRR bypass analysis (in French) 😁
Tweet media one
7
12
129
@matteyeux
matteyeux
6 years
Was able to build multi_path last night (without dev cert)
Tweet media one
6
29
123
@matteyeux
matteyeux
6 years
iOS 11.4.1 unstripped kernels
4
39
116
@matteyeux
matteyeux
6 years
A tool for analyzing and find vulnerabilities in macOS and iOS kernel drivers.
1
41
122
@matteyeux
matteyeux
1 year
iBoot* for n301 (Apple Vision Pro) 1.0 - 21N5165g e93c560966ad2d584c5fb86f7c32ab2e003739b11d51fdddc3a76eed70ae05422419d89983a4b796d3b68f9ec82c0370 *iBEC.n301.RELEASE.im4p
Tweet media one
0
18
125
@matteyeux
matteyeux
5 years
Real question is : can we use checkra1n for Linux on an iPhone running Linux
Linux on T8010 via PongoOS :) /cc @CorelliumHQ @never_released
Tweet media one
Tweet media two
35
165
817
4
4
116
@matteyeux
matteyeux
4 years
checkm8 port for S5L8940X/S5L8942X/S5L8945X
6
29
114
@matteyeux
matteyeux
7 years
An iOS kernel exploit designated to work on all iOS devices <= 10.3.1
4
74
121
@matteyeux
matteyeux
5 years
Technical analysis of the checkm8 exploit
1
34
115
@matteyeux
matteyeux
4 years
Twitter does not allow anymore to tweet hashes. So it's not possible to publish iOS bootloader keys here ¯\_(ツ)_/¯
Tweet media one
5
4
116
@matteyeux
matteyeux
1 year
CVE-2023-4863: Heap buffer overflow in WebP. Reported by Apple SEAR and CitizenLab Seems to be one of the bugs in ImageIO exploited in the latest iMessage exploit chain (BLASTPASS)
2
31
121
@matteyeux
matteyeux
4 years
Here is a tip to use diags without a DCSD lightning cable. In iBoot set a new boot-arg : setenv boot-args usbserial=enabled. Then run saveenv and boot diags.
6
34
107
@matteyeux
matteyeux
4 years
iOS 14 : Darwin Kernel Version 20.0.0: Thu Jun 11 21:45:17 PDT 2020; root:xnu-7090.0.0.112.4~2/RELEASE_ARM64_T8020 iBoot : iBoot-6603.0.0.110.6
4
14
117
@matteyeux
matteyeux
5 years
iBoot for Watch3,2 17S5433b (6.1.1) 013633486acc2e0de16988ce696f3bde856367b89cf1299165e5f2450c1df84154ece77250f8a990d6003b0c975cbe6b #checkm8
7
16
111