iH8sn0w shows off untethered iOS 8.1.1 jailbreak

Well known iOS hacker iH8sn0w has posted a new video on his YouTube channel of an iPad 3 (J2a model) running an untethered iOS 8.1.1 jailbreak.

Well-known iOS hacker iH8sn0w has posted a new video on his YouTube channel demonstrating an untethered jailbreak running on iOS 8.1.1. The demonstration was performed on an iPad 3 (J2a model), and it is significant because iOS 8.1.1 patched three of the exploits used by the Pangu team, effectively killing the latest public jailbreak. An untethered jailbreak means the device does not need to be connected to a computer every time it is rebooted, a major convenience factor that has been missing since Apple’s update.

Understanding Jailbreaking and the iOS 8.1.1 Update

Jailbreaking is the process of removing software restrictions imposed by Apple on iOS devices, allowing users to gain root access to the operating system and install applications, extensions, and themes that are not available through the official App Store. A tethered jailbreak requires the device to be connected to a computer during boot, while an untethered jailbreak allows the device to boot independently, making it far more user-friendly and desirable for everyday use.

When Apple released iOS 8.1.1 in November 2014, it was primarily a bug fix and performance improvement update, particularly for older devices like the iPad 2 and iPhone 4s. However, it also included security patches that closed the vulnerabilities exploited by the Pangu jailbreak team in their iOS 8.0-8.1 jailbreak. Specifically, Apple patched three of the exploits used by Pangu, which meant that users who updated to iOS 8.1.1 lost their jailbreak and had no immediate way to re-jailbreak.

The Demonstration by iH8sn0w

iH8sn0w, whose real name is not widely publicized, is a respected figure in the jailbreak community, known for developing tools like sn0wbreeze and iFaith. In his video, he shows an iPad 3 model J2a (the Wi-Fi only version) running iOS 8.1.1 with an untethered jailbreak. The video appears to show the device booting normally after a reboot, without any connection to a computer, which is the hallmark of an untethered jailbreak.

The fact that iH8sn0w is demonstrating this on an iPad 3 is notable because the iPad 3 uses the A5X chip, which has been notoriously difficult to jailbreak untethered due to its hardware bootrom. This suggests that the exploit he is using may be powerful enough to work across multiple devices and iOS versions. However, it is important to note that this is a proof-of-concept demonstration, and there is no indication yet whether iH8sn0w plans to release a public jailbreak tool based on this exploit.

An untethered jailbreak for iOS 8.1.1 would be a significant milestone, as it would restore the ability for users to reboot their devices freely without losing their jailbreak, something that has been missing since Apple patched the Pangu exploits.

Implications for the Jailbreak Community

The jailbreak community has been eagerly awaiting news of a new untethered jailbreak since iOS 8.1.1 closed the previous exploits. iH8sn0w’s demonstration has sparked hope, but it also comes with caution. Apple is known for quickly patching security vulnerabilities, and if iH8sn0w releases his exploit publicly, it may only work on iOS 8.1.1 and earlier, leaving users who have already updated to iOS 8.1.2 or later out of luck. Furthermore, the demonstration does not guarantee a public release; many hackers keep their exploits private for research or personal use.

From a technical standpoint, an untethered jailbreak requires a chain of exploits that bypass iOS’s security features, including code signing, sandboxing, and kernel protections. The fact that iH8sn0w has achieved this on iOS 8.1.1 indicates that he has found a way to circumvent these protections, possibly using a combination of new and existing vulnerabilities. However, the details of the exploit are not public, and it may be some time before it is fully understood and potentially incorporated into a user-friendly tool.

Technical Challenges of Untethered Jailbreaks

Untethered jailbreaks are inherently more complex than tethered ones because they require the exploit to persist after every reboot. In a tethered jailbreak, the device must be connected to a computer each time it boots, and the computer injects the jailbreak code. An untethered jailbreak must find a way to automatically re-apply the jailbreak during the boot process without external assistance, which typically involves exploiting a vulnerability in the boot chain or in a system process that runs at startup.

Apple has significantly hardened iOS over the years, making untethered jailbreaks increasingly rare and difficult to develop. Each iOS version closes known vulnerabilities, and hackers must constantly find new ones. The iPad 3’s A5X chip is particularly challenging because it lacks some of the hardware features that newer chips have, but it also has a well-documented bootrom exploit that has been used in previous jailbreaks, such as the limera1n exploit. It is possible that iH8sn0w is leveraging this bootrom vulnerability, which would make his jailbreak applicable to all devices with that bootrom, including the iPhone 4, iPod touch 4th generation, and original iPad mini.

iH8sn0w’s Track Record

iH8sn0w has a long history in the jailbreak scene. He is the developer of sn0wbreeze, a tool that created custom iOS firmware files for jailbreaking, and iFaith, which allowed users to save SHSH blobs and downgrade their devices. He has also contributed to various research and has been a vocal critic of Apple’s security policies. His expertise in bootrom exploits and low-level iOS hacking makes him one of the few people capable of achieving an untethered jailbreak on such a recent iOS version.

Despite his skills, iH8sn0w has sometimes chosen not to release public jailbreak tools, preferring to keep his methods private for research or to avoid legal issues. This means that even though he has demonstrated the jailbreak, it is uncertain whether the average user will ever have access to it. The jailbreak community often relies on teams like Pangu or TaiG to release polished, user-friendly tools, and individual hackers sometimes share their exploits with these teams to be incorporated into a public jailbreak.

What This Means for the Future of Jailbreaking

The demonstration on iOS 8.1.1 is a reminder that the cat-and-mouse game between Apple and jailbreak developers continues. Even as Apple tightens security, determined hackers find ways through. However, the gap between iOS releases and jailbreak availability has been growing, and many users have given up on jailbreaking altogether, preferring the stability and security of stock iOS. The fact that an untethered jailbreak for 8.1.1 is only now being shown, months after the release of iOS 8.1.1, illustrates the increasing difficulty.

For those still interested in jailbreaking, the advice remains to stay on the lowest possible iOS version and save SHSH blobs, as this increases the chances of being able to jailbreak in the future. iH8sn0w’s video may not lead to a public release, but it does prove that untethered jailbreaks are still possible on iOS 8.1.1, and that is enough to keep hope alive for the community.

Conclusion

iH8sn0w’s demonstration of an untethered jailbreak on iOS 8.1.1 is a noteworthy development in the jailbreak world. While it does not guarantee a public tool, it shows that the possibility exists and that skilled hackers are still able to overcome Apple’s security measures. For now, users who updated to iOS 8.1.1 or later will have to wait and see if iH8sn0w or another team releases a jailbreak, but at least there is proof that it can be done.