Five patch variants with increasing security bypass — pass one to --variant:
See research/0_binary_patch_comparison.md for the per-component breakdown.
- SSH (jailbreak): ssh -p 22222 mobile@
(password alpine) - SSH (regular/dev): ssh -p 22222 root@
- VNC: vnc://
:5901
Locations
Everything vphone-cli creates lives under ~/.vphone/ — kept outside the repo and the .app so the signed bundle stays portable. Redirect the whole tree with $VPHONE_ROOT:
Precedence: the per-item overrides ($VPHONE_LIBRARY_ROOT, $VPHONE_VENV_DIR) win over $VPHONE_ROOT, which wins over the ~/.vphone default. The ipsws/, tools/, and debs/ caches always sit directly under whichever root is active.
Option A — fully disable SIP, then disable AMFI via boot-arg (most permissive).
In Recovery (long-press power → Terminal):
csrutil disable csrutil allow-research-guests enable
Then reboot into macOS and set the AMFI boot-arg (needs SIP fully off to take effect):
sudo nvram boot-args=“amfi_get_out_of_my_way=1 -v” # reboot after
Option B — keep SIP on (debug-only relaxed), then allowlist the binary with amfidont (leaves AMFI enabled system-wide).
csrutil enable –without debug csrutil allow-research-guests enable
Then reboot into macOS and:
vphone-amfidont # .build/vphone-cli.app/Contents/Resources/vphone-amfidont for local builds
Tested Environments
Host iPhone CloudOS
Mac16,11 27.0b2
17,3_18.6.2_22G100
26.1-23B85
Mac16,8 26.5.1
17,3_26.0_23A341
26.1-23B85
Mac16,8 26.5.1
17,3_26.0.1_23A355
26.1-23B85
Mac16,12 26.3
17,3_26.1_23B85
26.1-23B85
Mac16,12 26.3
17,3_26.3_23D127
26.1-23B85
Mac16,12 26.3
17,3_26.3_23D127
26.3-23D128
Mac16,12 26.3
17,3_26.3.1_23D8133
26.3-23D128
Mac16,11 26.2
17,3_26.4_23E246
26.4-23E5207q
Mac16,11 26.2
17,3_26.5_23F77
26.4-23E5207q
Mac16,11 27.0b2
17,3_26.5.2_23F84
26.4-23E5207q
Mac16,6 26.4.1
17,3_26.6_23G71
26.4-23E5207q
Mac16,11 27.0b2
17,3_26.6.1_23G83
26.4-23E5207q
Mac16,11 27.0b2
17,3_27.0_24A5380h
26.4-23E5207q
Mac16,6 26.4.1
17,3_27.0_24A5390f
26.4-23E5207q
Mac16,6 26.6.1
17,3_27.0_24A5408d
26.4-23E5207q
Mac16,11 27.0b2
17,3_27.0_24A5418b
26.4-23E5207q
Mac16,11 27.0b2
17,3_27.0_24A5424a
26.4-23E5207q
FAQ
zsh: killed ./vphone-cli — AMFI/debug restrictions aren’t bypassed; see Prerequisites (amfi_get_out_of_my_way=1 or amfidont).
Virtualization is not available on this hardware — your Mac is itself a VM; PV=3 guest boot can’t nest. Use a non-nested macOS 15+ host.
Stuck on “Press home to continue” — connect via VNC and right-click (two-finger click) to simulate the home button.