1. X
  2. Adam Donenfeld
Log inSign up
Adam Donenfeld
1,707 posts
user avatar
Adam Donenfeld
@doadam
iOS security, politics, tech and traveling. Not really on social media anymore.
🇪🇺
Joined January 2011
344
Following
10.8K
Followers
RepliesRepliesMediaMedia

New to X?

Sign up now to get your own personalized timeline!

Create account

By signing up, you agree to the Terms of Service and Privacy Policy, including Cookie Use.

Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
Don't miss what's happening
People on X are the first to know.
Log inSign up
  • user avatar
    Adam Donenfeld
    @doadam
    Aug 24, 2017
    #ETA: NOW blog.zimperium.com/ziva-video-aud…
  • user avatar
    Adam Donenfeld
    @doadam
    Feb 5, 2018
    1/N Apple has finally acknowledged my kernel heap overflow and fixed it on 11.2.5 (CVE-2018-4109). While I didn't write an exploit, it's one of the most hidden vulnerabilities I've ever found, and it took me a couple of days to trigger it once I found it!
  • user avatar
    Adam Donenfeld
    @doadam
    Oct 4, 2017
    iOS 10.3.3 is no longer signed. If you were smart you are on 10.3.1. if you're on 11 good luck waiting till somewhen in 2018.
  • user avatar
    Adam Donenfeld
    @doadam
    May 19, 2017
    Replying to @doadam
    If someone wants to take the hassle of wrapping it into a jailbreak I’d be happy to help. (2/2)
  • user avatar
    Adam Donenfeld
    @doadam
    Aug 24, 2017
    Some people asked about donations, Thanks! but I'm employed. Go donate to your favorite charity organization :)
  • user avatar
    Adam Donenfeld
    @doadam
    May 19, 2017
    I never said anything about jailbreak. I'm releasing an exploit (source code + instructions). (1/2)
  • user avatar
    Adam Donenfeld
    @doadam
    Aug 25, 2017
    Replying to @doadam
    Apple bug submissions are also public now, and like I said in the presentation, some of them might still be working on 10.3.2 🙂
  • user avatar
    Adam Donenfeld
    @doadam
    Feb 16, 2019
    Well, that should help get you started on the latest ones: iCrypto -f iBoot.d11.RELEASE.im4p -k 53c616cddb7c0ca65b216643d2c35f3a0b5223de14e82af376ee440973d1148e0fc4a46595b88292ee0c4adee3587298 -o iBoot.d11.RELEASE.4513.230.10
    user avatar
    matteyeux
    @matteyeux
    Feb 16, 2019
    Replying to @doadam
    Sure ! I can do it if you provide me a bootchain exploit
  • user avatar
    Adam Donenfeld
    @doadam
    Nov 20, 2017
    I'm not sure if a coincidence or not, but on iOS 10.3.1, my sysctl trick to bypass SMAP was "challenged". Apple switched the order of l1dcache and l1icache... so now the whole exploit is a little bit more messed up. Anyway... ZiVA runs on 10.3.1 :)
  • user avatar
    Adam Donenfeld
    @doadam
    Sep 27, 2019
    This would mean a jailbreak from iPhone 4S till iPhone 8/X for every version forever.
    user avatar
    axi0mX
    @axi0mX
    Sep 27, 2019
    EPIC JAILBREAK: Introducing checkm8 (read "checkmate"), a permanent unpatchable bootrom exploit for hundreds of millions of iOS devices. Most generations of iPhones and iPads are vulnerable: from iPhone 4S (A5 chip) to iPhone 8 and iPhone X (A11 chip). github.com/axi0mX/ipwndfu
  • user avatar
    Adam Donenfeld
    @doadam
    Oct 30, 2018
    phrack.org/papers/viewer_… I must say, this is one of the only few times I feel like my work is actually reviewed based on its content and not based on the amount of money the company I represent pay :)
  • user avatar
    Adam Donenfeld
    @doadam
    Nov 22, 2017
    🙄gg
    Image
  • user avatar
    Adam Donenfeld
    @doadam
    Sep 11, 2019
    Would a "new mitigations introduced in iOS 13" presentation be something that people are interested in?
  • user avatar
    Adam Donenfeld
    @doadam
    May 13, 2019
    it's been a while
    Image
Advertisement
Advertisement