NEWS

Zimperium zLabs Team To Release iOS 11.2.2 Vulnerabilities, Potentially Leading To Jailbreak

01/30/2018

8260

It is said that Russ Cox would release iOS 11.2.2 jailbreak, but he has clarified that he doesn’t plan to release a jailbreak, he plans to release the exploit. He has also added that it may not be useful for “breaking into Apple devices”. So looks like it may not help in jailbreaking iOS 11.2.2 or lower. Now, Rani Idan, who is a member of Zimperium zLabs Team, has announced that his team will be releasing multiple vulnerabilities found in Apple’s “bluetoothd” daemon affecting iOS 11.2.2 and below firmwares.


The announcements comes in the form of a post on the official Zimperium blog where the said vulnerabilities are detailed.


Since these vulnerabilities have been patched by Apple in last week’s iOS 11.2.5 release, and have been acknowledged by the company in the iOS 11.2.5 final release notes with due credits given to Rani Idan of Zimperium zLabs Team for the discovery, they will now be made public for research and other purposes.


"The first vulnerability is memory corruption in bluetoothd and the other is execution of arbitrary code on different crucial daemons. The first vulnerability (CVE-2018-4095) is full relative (ASLR bypass) control on the stack in CoreBluetooth that leads to memory corruption over bluetoothd."


"The second major vulnerability (CVE-2018-4087) leads to execution of arbitrary code on different crucial daemons in iOS by hijacking the session between each daemon and bluetoothd. Some of the impacted daemons are: SpringBoard, mDNSResponder, aggregated, wifid, Preferences, CommCenter, iaptransportd, findmydeviced, routined, UserEventAgent, carkitd, mediaserverd, bluetoothd, coreduetd and so on."


What this could all mean is that just like how we saw with Google’s Project Zero member Ian Beer’s iOS 11.0-11.1.2 exploit turned into a jailbreak for public, we could also see a similar thing happened for devices running iOS 11.2-11.2.2. Now of course this would need work before it could be turned into a workable jailbreak solution, but given how the community is active these days with jailbreak tools for iOS 11.1.2 arriving left and right, it wouldn’t surprise me one bit if we saw a similar thing happened for iOS 11.2.2 and below once the aforementioned vulnerabilities are made public.


Zimperium zLabs Team To Release iOS 11.2.2 Vulnerabilities, Potentially Leading To Jailbreak


Since iOS 11.2.2 is still being signed, my advise would be to downgrade to it while you can from iOS 11.2.5 for a potential future jailbreak. Always better to be safe then sorry, especially for those who missed the boat on iOS 11.1.2 jailbreak.


It is said that Russ Cox would release iOS 11.2.2 jailbreak, but he has clarified that he doesn’t plan to release a jailbreak, he plans to release the exploit. He has also added that it may not be useful for “breaking into Apple devices”. So looks like it may not help in jailbreaking iOS 11.2.2 or lower.


Source: Zimperium Blog

Windows
Mac OS
iOS
Linux
3uTools
Win 64-bit For this device
V9.0 2025-11-11
Download
Win 32-bit For this device
V9.0 2025-11-11
Download
3uTools V3.18
2025-09-18
Please use the 3uTools PC client to install the iOS client:
1、 Install either the Windows or Mac version of 3uTools on your computer
2、 Open the PC client and connect your device to the computer via USB cable
3、 After the connection is successful, wait for the computer to automatically install the mobile app for the device, or locate “Install Mobile App” on the computer and manually click to install.
3uTools
deb file
v3.01 2025-11-20
Download
rpm file
v3.01 2025-11-20
Download
Windows
iOS
Android
3uAirPlayer
Win 64-bit For this device
V6.0.2 2025-11-19
Download
Win 32-bit For this device
V6.0.2 2025-11-19
Download
iOS Device Mirroring (No App Required)
1、 Install 3uAirplayer on the Windows PC
2、 Open Control Center and select Screen Mirroring
3、 From the list, choose your PC to start mirroring
4、 Or connect your iOS device to the PC via USB to begin mirroring
Scan to get "3uAirPlayer" App