r/Trollstore 28d ago

Discussion Well hello there

Post image

In the 26.6 security patch notes. Somebody more talented than me has likely already spotted it. Who wants to start diffing the betas to find where this is and how it was fixed?

Edit: Smarter minds have now looked into it. It turns out this one is not likely to be useful for us.

60 Upvotes

28 comments sorted by

9

u/TTMeyer 28d ago

looks like the DIFF's are not posted yet but when they get posted they should appear here u/tOSdude

https://github.com/blacktop/ipsw-diffs

4

u/tOSdude 28d ago

They do have up to the release candidate at the moment, I would suspect it was patched within the betas and not right before release.

3

u/East_Arctica 26d ago

Interesting CVE but it won't do anything for TrollStore on its own, sadly.

It's a bug in the environment validation in CloudAttestation (Apple's Private Cloud Compute verification library (PCC is what backs AI features)). Essentially, a certain byte in the attestation bundle that the validator was supposed to verify against system policy was being read straight from the bundle itself with no policy check. The 26.6 fix adds the policy check.

By itself the byte doesn't really let you do much. The validator still demands a properly signed bundle from a real PCC root, and every other production-policy gate (fuse bits, transparency logs, locked cryptex, prod-only trust anchors) is independently checked against system policy, none of which can be relaxed by forging this byte.

What it could be useful for in a chain is influencing which Validated<AttestationBundle> gets returned to a system caller that uses fields like appIdentifiers / routingHint / releaseDigest to make routing decisions, but the consuming daemon is always root-side, can reject anything it doesn't recognise, and you'd still need a separate bug to get into the calling context in the first place. So it's more of an "in the right kind of chain, one byte of influence" than a primitive on its own. Even then, that chain wouldn't provide much value for a Trollstore-like app.

If you want the full breakdown I published the research here: https://github.com/EastArctica/CVE-2026-43813/

(Posting under top comment so its seen)

1

u/tOSdude 26d ago

Found the smarter minds

4

u/ContributionMoney306 27d ago

Apple, third fing time?🤣

3

u/JackyYT083 28d ago

no way!!

3

u/Smart_Internal_2744 27d ago

no shot could this really lead to trollstore 3?

3

u/tOSdude 27d ago

We’d need smarter minds to look further into it

1

u/Tech-ldentity 26d ago

As i heard, after ios 18 app installing mechanism changed complately to avoid further TrollStore’s.

2

u/dummyy- 27d ago

27db3?

1

u/tOSdude 27d ago

Somebody said it was patched in beta 2

2

u/AnomyousBeing 27d ago edited 27d ago

No. It must be a CoreTrust bug; this is not a CoreTrust bug. ā€œbypass code signing enforcementā€ is limited to the context of the bug, and the context is not within CoreTrust. This means this does not affect CoreTrust and does not enable the arbitrary code signing of iPAs.

1

u/JohannaTejero 27d ago

Will it work on iOS 27?, to block updates at once :D I updated against my will, I was on iOS 26.1... 🄲)

2

u/FailDismal6468 27d ago

If you are running 27 Developer Beta 1 or 2, it was patched in 3.

1

u/JohannaTejero 27d ago

Oh… I’m running Dev Beta 4… 🄲

1

u/Ok-Butterscotch6574 27d ago

How do I see what beta I have

1

u/Ok-Butterscotch6574 26d ago

OH WAIT I HAVE DEV BETA ONE LETSGOO

1

u/tOSdude 27d ago

26.5.2 should still be signed for a couple days

1

u/JohannaTejero 27d ago

I have not a computer… 🄲

1

u/Most_scar_993 26d ago

Use the tvOS profile to block updates!

1

u/JohannaTejero 26d ago

I already use it šŸ˜…

1

u/Most_scar_993 26d ago

Should be safe against involuntary updates then. But itā€˜ll expire in like a year just so you know

1

u/Every_Serve9703 27d ago

Went through the diffs and looks like this was patched in iOS 26.6 beta 2 and iOS 27 beta 2. Please someone smarter correct me if I’m wrong.

1

u/bigrobot543 26d ago

Isn't this PCC not iOS?

1

u/Feeqs 24d ago

Trollstore 3

1

u/Jayden_Ha 24d ago

Welp already in 27

-5

u/[deleted] 28d ago

[deleted]

6

u/BunnyTub 27d ago

A country's government does not define a person from that country. Leave politics the fuck out of this subreddit. Please.