ESC
其他 2 分钟阅读

Boot a Virtual iPhone via Apple's Virtualization.framework

Boot a Virtual iPhone via Apple's Virtualization.framework

来源:Hacker News

Five patch variants with increasing security bypass — pass one to --variant:

See research/0_binary_patch_comparison.md for the per-component breakdown.

  • SSH (jailbreak): ssh -p 22222 mobile@ (password alpine)
  • SSH (regular/dev): ssh -p 22222 root@
  • VNC: vnc://:5901

Locations

Everything vphone-cli creates lives under ~/.vphone/ — kept outside the repo and the .app so the signed bundle stays portable. Redirect the whole tree with $VPHONE_ROOT:

Precedence: the per-item overrides ($VPHONE_LIBRARY_ROOT, $VPHONE_VENV_DIR) win over $VPHONE_ROOT, which wins over the ~/.vphone default. The ipsws/, tools/, and debs/ caches always sit directly under whichever root is active.

Option A — fully disable SIP, then disable AMFI via boot-arg (most permissive).

In Recovery (long-press power → Terminal):

csrutil disable csrutil allow-research-guests enable

Then reboot into macOS and set the AMFI boot-arg (needs SIP fully off to take effect):

sudo nvram boot-args=“amfi_get_out_of_my_way=1 -v” # reboot after

Option B — keep SIP on (debug-only relaxed), then allowlist the binary with amfidont (leaves AMFI enabled system-wide).

csrutil enable –without debug csrutil allow-research-guests enable

Then reboot into macOS and:

vphone-amfidont # .build/vphone-cli.app/Contents/Resources/vphone-amfidont for local builds

Tested Environments

Host iPhone CloudOS

Mac16,11 27.0b2 17,3_18.6.2_22G100 26.1-23B85

Mac16,8 26.5.1 17,3_26.0_23A341 26.1-23B85

Mac16,8 26.5.1 17,3_26.0.1_23A355 26.1-23B85

Mac16,12 26.3 17,3_26.1_23B85 26.1-23B85

Mac16,12 26.3 17,3_26.3_23D127 26.1-23B85

Mac16,12 26.3 17,3_26.3_23D127 26.3-23D128

Mac16,12 26.3 17,3_26.3.1_23D8133 26.3-23D128

Mac16,11 26.2 17,3_26.4_23E246 26.4-23E5207q

Mac16,11 26.2 17,3_26.5_23F77 26.4-23E5207q

Mac16,11 27.0b2 17,3_26.5.2_23F84 26.4-23E5207q

Mac16,6 26.4.1 17,3_26.6_23G71 26.4-23E5207q

Mac16,11 27.0b2 17,3_26.6.1_23G83 26.4-23E5207q

Mac16,11 27.0b2 17,3_27.0_24A5380h 26.4-23E5207q

Mac16,6 26.4.1 17,3_27.0_24A5390f 26.4-23E5207q

Mac16,6 26.6.1 17,3_27.0_24A5408d 26.4-23E5207q

Mac16,11 27.0b2 17,3_27.0_24A5418b 26.4-23E5207q

Mac16,11 27.0b2 17,3_27.0_24A5424a 26.4-23E5207q

FAQ

zsh: killed ./vphone-cli — AMFI/debug restrictions aren’t bypassed; see Prerequisites (amfi_get_out_of_my_way=1 or amfidont).

Virtualization is not available on this hardware — your Mac is itself a VM; PV=3 guest boot can’t nest. Use a non-nested macOS 15+ host.

Stuck on “Press home to continue” — connect via VNC and right-click (two-finger click) to simulate the home button.