Palera1n Jailbreak for iOS 15 – iOS 16
Palera1n is the first public iOS 15 – iOS 16 semi-tethered checkm8 “jailbreak”. This is an early release, and using it on your main iPhone is not recommended. As for now, Palera1n Jailbreak offers the tweak injection feature, installing Substitute on iOS.
What is Palera1n?
Palera1n Jailbreak is a script for macOS and Linux, allowing you to execute iOS 15.0 – iOS 16 checkm8 exploit on compatible iDevices. It boots the device with AMFI patches and requires you to install Pogo by Amy through the TrollStore app to access the Sileo package manager.
It is brought to you by Nebula, the developer behind the appreciated IPA Permasigner terminal app, the first open-source solution to install IPA files without revokes on iOS 14.0 up to iOS 14.8.1, and iOS 15.0 up to iOS 15.4.1 using the CoreTrust bypass discovered by Linus Henze.
Palera1n Jailbreak is a work in progress, and the installation process isn't as user-friendly as other jailbreaks. To install the semi-tethered iOS 15 jailbreak, it's required to make some preparation first and use a computer. Using this tool is recommended only for advanced users!
Palera1n should work for most devices supported by checkra1n, but it's unstable and can get you into some kind of issues on the way. Use it at your own risk and when necessary run futurerestore --exit-recovery, or use irecovery to exit recovery mode.
checkm8 exploit developed by axi0mX is the main engine behind checkra1n jailbreak. The exciting part about this permanent unpatchable bootrom exploit is potentially ensured lifetime jailbreak ability for A5-A11 devices. It means every future iOS release should be vulnerable.
Palera1n Jailbreak executes all necessary scripts to jailbreak, and the Pogo app is used to install Procursus Bootstrap and Sileo. The package manager allows you to manage repositories, view packages, and install “jailbreak” apps on iOS 15.0 up to iOS 15.7.1, and iOS 16.
Sileo is a modern APT Package Manager for iOS 12 and up with a focus on speed and usability. It was designed to provide a real Cydia alternative for jailbroken devices. Sileo officially supports all jailbreaks and can share its sources with Cydia if you're on unc0ver or checkra1n.
It was developed in Swift a modern programming language created by Apple to deliver lightning-fast iOS apps. Therefore, Sileo Package Manager works fast on all jailbroken devices.
Amy, the developer behind Pogo, is working on implementing a tweak injection method for Palera1n jailbreak. At present, you can install Cydia tweaks on jailbroken iOS 15 and iOS 16, but not all will work. Instead, you can install apps like Filza, OpenSSH, AppStore++, NewTerm 2, etc.
Pogo is packed with a CoolStar's Sileo 2.4, but Amy is pushing through a private repo also beta releases. The build of Sileo bundled in this is considered beta. If you want more regular updates, add the https://beta.anamy.gay repo to access the latest releases of Sileo APT.
Note: Palera1n Jailbreak for iOS 15 is recommended for advanced users. If you looking forward to Cydia tweaks thoes are supported now on iOS 15.0 up to iOS 15.7.1.
Palera1n Jailbreak was released as an open-source project under GPL-3.0 license through GitHub Repository. The latest Palera1n release works also on iOS 15.5 up to iOS 15.7 (and also iOS 16). The Pogo app can be used with patched AMFI as long as it’s installed with a ramdisk.
Since version 1.2, the devs added semi-tethered support with tweaks to Palera1n. The jailbreak creates a fake rootfs partition that could be modified, then copies the file system over. Only downside is that it can use 5-10 extra GB of your storage. This will not work on 16 GB devices.
Palera1n for iOS 15.0 up to iOS 15.7.1 with tweaks support
Recently, @mineekdev started working on a new branch of Palera1n jailbreak, with the main focus on adding support for tweaks. This version boots the device with AMFI patches. On the first run, it'll boot a ramdisk which dumps your onboard blob, and installs Sileo and Substitute.
Substitute is a tweak injection system that runs on already jailbroken devices. Basically, it is used to run tweaks. Substitute 2.3.1 is using a newly designed tweak injection system that allows loading a big number of tweaks for ultimate customization with minimal overhead on iOS 15.
On top of that, Palera1n with support for tweaks is works on all releases between iOS 15.0 up to iOS 15.7.1. Tethered jailbreak is able to temporarily jailbreak the device during a single boot. To start the device with a patched kernel, it must be “re-jailbroken” with a PC. This also means that you will need a PC every time to boot your iPhone or iPad.
Palera1n for iOS 16.0 up to iOS 16.2
Palera1n for iOS 16 with tweak support was officially released soon. Of course, this version works only with checkm8 compatible iPhones and iPads mentioned below. What's more, there will be created a graphic interface (GUI) to make the jailbreak process more user-friendly.
In the new release of Palera1n iOS 16 jailbreak for A11 devices, the Pogo app will be replaced with a new Palera1n loader app. From now on, this tool will be used to prepare the Bootstrap, and install Sileo in uicache, the default manager for tweaks. iOS 16.0 – iOS 16.2 is supported.
On top of that the loader for Palera1n for iOS 16, also offers tools to fix some common issues such as refreshing icon cache, remounting rootfs and preboot as read/write, start daemons, respring SpringBoard, and activate installed tweaks with substitute-launcher.
Note: Palera1n for iOS 16 was released in the official GitHub in branch. It's still recommended to use it at this stage only for experience users. A9 – A10 are not supported because Apple doesn't allow to install iOS 16 on those devices.
At this stage of development, Nebulas custom launchd and script aren’t spawning the loader app yet. If you’re installing with the experimental iOS 16 branch, you can install TrollStore using an SSH Ramdisk, then jailbreak the device and install the loader app with TrollStore.
All A9-A11 systems on a chip (SoC) are supported by jailbreak. Below, you can find the actual list of compatible Palera1n Jailbreak iPhones and iPads. The jailbreak was tested to run and work without issues on iPhone X (GSM), iPhone 8, iPhone 7, and iPhone 6s running iOS 15.
for iOS 15.0 – 15.7.1
- A9 – iPhone 6S, iPhone 6S Plus, iPhone SE, iPad (2017) 5th Generation.
- A9X – iPad Pro (12.9 in.) 1st generation, iPad Pro (9.7 in.).
- A10 – iPhone 7 and iPhone 7 Plus, iPad (2018, 6th generation), iPad (2019, 7th generation) (iOS 14 not supported).
- A10X – iPad Pro 10.5” (2017), iPad Pro 12.9” 2nd Gen (2017).
- A11 – iPhone 8, iPhone 8 Plus, and iPhone X.
for iOS 16.0 – 16.4
- A11 – iPhone 8, iPhone 8 Plus, and iPhone X.
How to jailbreak iOS
To jailbreak iOS 15 or iOS 16 using Palera1n first check if your device is on the supported list. Remember to disable the passcode on A10/A11 devices before proceeding with the jailbreak.
- Install libimobiledevice on your Linux or Mac through brew. This library is required to connect your iPhone through USB to the computer.
brew install libimobiledevice
or on Linux distribution:
sudo apt install libimobiledevice-utils libusbmuxd-tools
- Clone the Palera1n repo from GitHub. It is used to exploit iOS firmware and boot the device with AMFI patches. Next CD into this repository. Palera1n checkm8 jailbreak with installed Sileo and Substitute (tweaks support) on iOS 15.0 – 15.7.1, and iOS 16 – 16.2. This is a work in progress and iPhones: X, 8+, 8, 7+, 7, 6s+, 6s, SE; iPods: Touch 7; iPads: 5, 6, 7, and the Air 2 are supported.
git clone --recursive https://github.com/palera1n/palera1n && cd palera1n
- Run the Palera1n script to jailbreak your iOS 15 / iOS 16 device with tweaks support.
./palera1n.sh --tweaks <your iOS version here>
or enable semi-tethered jailbreak with tweak support (it will use 5-10 extra GB of your storage).
./palera1n.sh --tweaks --semi-tethered <your iOS version here>
- Palera1n will replace the Tips app with Pogo IPA (can be also installed via TrollStore).
- Open the modified Tips app and tap on install.
- Access Sileo from your Home Screen.
Note: To install Pogo app make sure your device is in normal mode. You'll have to uicache in the Pogo app every time you will reboot your iPhone.
If you want to start from DFU mode add the argument after the script file to execute.
./palera1n.sh --dfu <your iOS version here>
Palera1n Jailbreak offers access to verity of options and subcommands while jailbreaking iOS 15 or iOS 16. Below you can find the list of all available features with proper description.
Options: --help Print this help --tweaks Enable tweaks --semi-tethered When used with --tweaks, make the jailbreak semi-tethered instead of tethered --dfuhelper A helper to help get A11 devices into DFU mode from recovery mode --skip-fakefs Don't create the fakefs even if --semi-tethered is specified --no-baseband Indicate that the device does not have a baseband --restorerootfs Remove the jailbreak (Actually more than restore rootfs) --debug Debug the script --serial Enable serial output on the device (only needed for testing with a serial cable) Subcommands: dfuhelper An alias for --dfuhelper clean Deletes the created boot files
Palera1n Jailbreak for iOS 15 – iOS 16 is still a work in progress, and you can get into some issues while jailbreaking. Here are some discovered solutions for various situations.
- “sudo usbmuxd -p -f” should fix most USB issues on Linux and install usbmuxd.
- If your device is stuck in recovery, please run futurerestore --exit-recovery, or use irecovery -n.
- The Palera1n black screen after verbose issue can be fixed by using an onboard blob. You can dump one using SSHRD Script.
- If Pogo didn't install to Tips for some reason, you can install the Pogo IPA using TrollStore.
- Make AFC2 work, use “ldid -s /usr/bin/killdaemon && killdaemon”. Ensure you have procursus' ldid and AFC2 installed first.
- Add iOS 16.4 support.
- Various fixes.
- Increasing stability.
- ibot.patched fix.
- Use payload on the X.
- Other random changes and fixes.
- Does not mount user data partition for iPhone X compatibility.
- Deploys files to the rootfs (fakefs if required).
- Fix deviceid finding.
- Use apticket.der because dumping rdisk seems to freeze.
- Add /.installed_palera1n with info.
- uicache loader app on boot (no more Tips app hijacking).
- Fix rootless.
- Webkit fix on iOS 16.
- Switch to local boot.
- Fix home button on iPhone 7(+) and 8(+).
- Increase stability.
- Supports iOS 15 – iOS 16.2 on all checkm8 devices.
- Fully fix deep sleep bug.
- Supports for iOS 15 – iOS 15.7.1 on all checkm8 devices.
- Increase stability.
- Fix TrollStore, camera, and screen recording.
- Numerous fixes.
- Let Pogo install tweak support.
- Support iPad beta URLs.
- Make sure auto-boot is always set to false (unless restoring rootfs).
- Wait for sshd to start before running postboot.
- Fix Tips check error.
- Fix --restorerootfs.
- Check if Tips is installed.
- Only prompt for disclaimer once.
- Check for DFU.