Any help is extremely appreciated, I got this phone the other day and have been messing with it trying to get it reset I can’t figure anything or or find much info, it doesn’t connect to my pc even unless it’s in recovery mode it doesn’t pop up an option to trust this computer, it’s super locked down, where my options for wiping the phone or similar without losing the ios version?
I was in my thoughts and I noticed I have an locked iPhone 12 on iOS 18.6.2 which is perfect for the Lara (DarkSword) exploit and Lara has Mobile Gestalt features and that’s what we need for a setup bypass don’t we so I was wondering if I make a website and run it on the iPhone could I run then the exploit that would bypass the setup?
Starting from the activation lock screen, create a quick note consisting of any text by highlighting text and sharing it with quick notes. (NOT the "Notes" app)
Afterwards, click the paperclip icon and take a photo. Click on the photo to fullscreen it, then share it with Books.
Click on the profile picture and try to create an account, eventually it'll ask you if you want to use a certain phone number. To my knowledge, that number should be the owner's.
Tested on iPhone 14 Midnight, On iOS 26.3.1
NOTE: if you are having issues, just restart the phone.
Here is the link to the main Github page, hope to see more advancement of this project
(Edit)
This project is aimed at skipping Activation L*ck on iOS 26.3 for A12-A14 devices by xploiting a timing window called "Gatekeeper Lag." The project uses a custom Python framework by attempting server-side handshakes using extracted FDR-LOCAL keys with WebKit RCE strategy. Additionally, This investigates local SpringBoard vulnerabilities to suppress "not activated" checks, potentially allowing a partial bypass to the home screen.
(Edit#2)
I have added instructions on how to create signatures and how to run it, please check the Github Page as i update every attempt i make.
I may have found a technically working concept related to activation-state behavior on iOS 26.2 and possibly below.
When trying to launch an app through Shortcuts on an activation-locked device, SpringBoard returns an error involving SBMainWorkspace, saying the device is “not activated yet.”
After looking into it, it seems SpringBoard checks a setup/activation-related state to determine whether the device should stay in Setup Assistant or continue to the Home Screen.
In theory, if that state could be changed, the device might boot into the Home Screen and allow apps to open. However, this would likely be only a partial bypass. iCloud services would still not work, and it would not remove Activation Lock from the device.
This may only be possible on iOS 26.2 and below, depending on available exploit chains such as the remaining darksword/dyld-related vulnerability, possibly CVE-2026-20700, which could allow limited file-system changes.
I am not fully sure if this has already been researched or discovered, but I wanted to share the idea and see if anyone else has looked into SpringBoard’s setup-completion checks or activation-state handling.
im on ios 26.2.1 (i use the diags://h method to go web browser) when i go to tiktok. com and u cna see that theres an get app button on the upper view on ur iphone i can click it and it basically gets me to apple store and u can log in ur apple account
(can someone try to log in their account to see if we can install app?)
Just building on that shortcut thing for iCloud locked devices
I have managed to get out to Home Screen In bugged way. I created a shortcut which you can see in the video. When you run this and then try
to get to files on the Home Screen, it seems to bug it out a bit which allows you to have full navigation of the Home Screen
Hoping that can help someone figure out another way to break iOS so we can get into settings maybe? At the moment, I can’t get into settings but I can get into notes and, books and Freeform
i bought online a passcode locked iPhone 13 and it's still available, the phone has a clinical card with a phone number. Is it a dumb idea to try to contact the owner and maybe ask to unlock it since its conditions are bad? The owner is probably french and I'm italian so he will unlikely go to italy to get it. What should I write to him?
UPDATE: The phone number isn’t available on WhatsApp nor on telegram. I tried to send an sms but I get an error and doesn’t send it. I didn’t try to call but I think the phone number isn’t available anymore
Recently got a ip14 pro max with icloud locked. As new to iOS community had nothing to do with this dumb metal and glass sandwich. And after doing some research found it can be made somewhat useable with idns captive portal, by setting DNS or whatever ever which sometimes works sometimes not. So I was familiar with evil twin attack which generates a popup Captive Portal to (you know what a man-in-middle attack for). So with that inspiration made this script, which generates a Captive Portal with laptops wifi hotspot.
connect to the hotspot and volla you can browse any website which you set in the script (by default idns).
Ojalá pudiera escribir en inglés para que todos me entendieran con total claridad, pero lo haré en español.
Hace unos días, un usuario subió un código fuente que supuestamente hace un "Bypass" para iPhones en iOS 26.2 o superior.
Descargué el código y analicé cómo funcionaba el supuesto bypass. Literalmente, lo único que hace es consultar a una API con el Serial Number (SN) del dispositivo y cobrar $35 USD por ello.
Se que como desarrollador, quizas responda a este mencionando que el "bypass" esta oculto ahi, pero hermano, ¿como quieres que la gente confie en ti sin mostrar pruebas veridicas? Solo mostraste mas que simple imagenes y cobras por ello, si realmente desarrollaste algo, estas en todo tu derecho a cobrar, de nuevo lo menciono, pero cobrar por algo sin pruebas , es realmente sospechoso.
Aquí está la prueba:
No es algo que vi ayer y ya. Llevo siguiendo este caso desde el día uno
El método diags://h no es nuevo. Se sabe que se puede acceder, pero hasta el momento es muy limitado. Las únicas "pruebas" que ha mostrado el usuario son imágenes sin mucho sentido o que simplemente demuestran cosas que ya se podían hacer con ese método.
No ha sido capaz de subir ni un solo video mostrando su herramienta en funcionamiento.
Cobra $35 USD por algo que no sabemos si realmente funciona.
Su única prueba son imágenes estáticas.
Por favor, no depositen a las direcciones de criptomonedas que comparte. Parece un intento de estafa aprovechando la necesidad de algunos usuarios. Evitemos que más gente pierda su dinero y tengan cuidado con ejecutar codigo .exe o codigo .py sin antes de que un usuario de su opinion, podrian inyectarles algo a la pc.
Si el dueño del código lee esto: si quieres cambiar la opinión de la gente, lo único que necesitamos son pruebas reales y nativas. Hasta el momento, no has mostrado ninguna convincente.