The jailbreak is near ready for prime time (excluding 4S and iPad 2).
For now the jailbreak is tested on all devices, including iPhone 4, iPhone 3GS, iPad 1, iPod Touch 3G and iPod Touch 4G. iPad 2 and iPhone 4S status is “work in progress”.
pod2g has also published a new video demo of iOS 5.0.1 untethered jailbreak for iPhone 4:
Pod2g has recently announced that he has successfully performed an untethered jailbreak on an iPhone 4 running iOS 5.0.1.
Got an untethered iPhone 4 running iOS 5.0.1. Feel free to update.
Of course, if you want to SIM unlock, don’t update using Apple’s original FW nor update OTA.
This means jailbreakers can update to iOS 5.0.1. Previously it was recommended to stay on iOS 5. Unlockers as usual should stay away from Apple’s firmwares and from iOS 5.0.1.
We strongly recommend that everyone use TinyUmbrella to save their iOS 5.0.1 SHSH Blobs.
Pod2g writes in his blog, that next devices he will try to untehter jailbreak are iPod 3G, iPod 4G and iPad 1.
Chronic Dev Team is almost done with a much anticipated untethered jailbreak for iOS 5 and iOS 5.0.1. Team member and French hacker pod2g just released a video showing off the jailbreak. It looks to be near-complete and functioning properly. Take a look:
pod2g even created a blog, where he plans to post the most recent news about his progress:
Today I succeed in jailbreaking my iPod 3G. The exploit is user-land, rely on a user ROP payload and a kernel write anywhere exploit.
I can’t give much details right now, but here are the next steps :
- upgrade the iPod 3G to iOS 5.0.1
- do the same on iPhone 4 / iOS 5.0.1
- then iPad 1 & iPod 4G
At every step, the exploit code needs certainly to be reworked, but I really don’t know right now. Next, I’ll return to the research for iPad 2 and iPhone 4S. I don’t know if I gonna release first for other devices or not. I’ve to think about it. Feel free to give your opinion.
Semi-tethered jailbreak is already available for some devices for both iOS 5 and iOS 5.0.1. But we all want untethered jailbreak and we want jailbreak for iPad 2 and iPhone 4S. So why not help hackers to find new exploits and vulnerabilities?
The Chronic Dev-Team has a released a tool to collect crash reports from iOS devices in order to find vulnerabilities that could lead to an untethered jailbreak.
The idea is very simple. When your iPhone, iPad or iPod Touch crashes it sends data to Apple (you can turn it this off though). Apple uses these reports to update iOS in the future. By the way, it also uses them to fix exploits found by jailbreakers. P0sixninja says that Apple closed several exploits they have found in IOS 5 beta before the final version of the software was released.
In order to find more vulnerabilities as fast as possible, the team has developed a tool which will copy the crash reports from your device and analyze them to locate potential exploits. The tool will also remove the crash reports from your device and modify your iTunes installation to prevent uploading of that diagnostic information to Apple.
iH8Sn0w has released Sn0wBreeze 2.8b11 with support of recently released iOS 5.0.1 firmware.
As usual the jailbreak is semi-tethered for iPhone 4, iPad, iPhone 3GS with new bootrom, iPad Touch 3G, iPod Touch 4G and untethered for iPhone 3GS with old bootrom.
Sn0wBreeze 2.8b11 will create a custom firmware with jailbreak and preserve modem version for unlock. Unlockers will also be able to flash 06.15 iPad modem for unlock.
Earlier this week pod2g reported that a code signing bug found in iOS 5.0 will make it easier for hackers to develop a full jailbreak for iOS 5 firmware version. That bug might have been closed in iOS 5.0.1. UPDATE: According to pod2g the bug is still present, but harder to exploit because another exploit found by Charlie Miller is fixed in iOS 5.0.1.
Also, MuscleNerd via twitter has warned iOS users that there is no downgrade from iOS 5.0.1 to iOS 5.0 yet and he recommends to wait until downgrade mechanism is available.
Jailbreakers and unlockers should avoid today’s 5.0.1 until a flow for downgrading to 5.0 is developed.
Downgrade flow needs to be modified for AP “nonce” http://is.gd/b3G0io … saved SHSH blobs are not enough to downgrade to 5.0
iPhone 3GSjailbreak can be either tethered or untethered. Tethered jailbreak means that each time you restart your device you will need to connect it to a computer and run redsn0w. If you have iPhone 3GS with an old bootrom version 359.3, the jailbreak is untethered. If your device has bootrom version 359.3.2 and higher, iOS 5/4.3.5 jailbreak will be tethered.
You can read tutorial to detect if your iPhone 3GS has new or old bootrom version here.
iH8Sn0w has released Sn0wBreeze 2.8b10. Here is a changelog:
Supports iOS 5.0 (9A334)/5.0.1-b2 (9A404)
Fixed iBooks sandbox crashing issues.
Fixed location services issues with iPhone 3GS users running the iPad baseband (06.15).
Re-added iPad baseband (06.15) install option to iPhone 3GS.
Removes UDID requirement/Beta timer in 5.0.1.
Tethered devices are booted via iBooty which is extracted to the Desktop after running sn0wbreeze.
As usual the jailbreak is semi-tethered for iPhone 4, iPad, iPhone 3GS with new bootrom, iPad Touch 3G, iPod Touch 4G and untethered for iPhone 3GS with old bootrom.