On August 7, 2026, iOS 26 got its first public jailbreak, 326 days after Apple released it, and only for iPhones and iPads with A12 or A13 chips still running iOS 26.0 or 26.0.1. Dopamine 3.0 is a good measure of how far jailbreaking has shifted. In 2010 you could jailbreak a new iPhone 4 by tapping a button on a web page. In 2026 the newest public tools reach a shrinking set of older devices on outdated builds, and the bugs behind them increasingly surface first in exploit chains built for mercenary spyware.
Jailbreaking means using security flaws in iOS to gain root-level control and switch off Apple’s code-signing checks, so the device runs software Apple has not approved: system tweaks, themes, command-line tools and apps from outside the App Store. It is the iPhone counterpart to rooting an Android phone, and it is separate from removing a carrier SIM lock, although the two grew up together on the original iPhone.
Updated, September 14, 2026: Extended from 2019 to the present with checkm8, unc0ver, Fugu15, Dopamine, palera1n and TrollStore, plus the current status for iOS 17, 18, 26 and the iOS 27 release. Early dates were corrected (JailbreakMe 2.0 was patched in iOS 4.0.2, not 4.3.4), two unrelated images were removed, and new sections cover legality, risks and who should not jailbreak.
iOS jailbreak timeline at a glance (2007 to 2026)
Each row lists the tool that defined that year and the versions it covered at release. Later updates to several tools stretched their support further, as the sections below explain.
| Year | Tool | iOS versions and devices |
|---|---|---|
| 2007 | JailbreakMe (original) | iPhone OS 1.0.2 and 1.1.1 |
| 2008 | PwnageTool 2.0 | iPhone OS 2.0, including iPhone 3G |
| 2009 | redsn0w | iPhone OS 3.0 on the original iPhone, iPhone 3G and early iPod touch |
| 2010 | JailbreakMe 2.0 (Star), limera1n | iOS 4 up to 4.0.1; A4 devices through a bootrom flaw |
| 2011 | JailbreakMe 3.0 (Saffron) | iOS 4.3.3, including iPad 2 |
| 2012 | Absinthe | iOS 5.0.x on iPhone 4S and iPad 2 |
| 2013 | evasi0n, evasi0n7 | iOS 6.0 to 6.1.2; iOS 7 |
| 2014 | Pangu, TaiG | iOS 7.1 to 7.1.1; iOS 8.0 to 8.1.1 |
| 2017 | yalu102 | iOS 10.0 to 10.2 |
| 2018 | Electra | iOS 11.0 to 11.1.2 |
| 2019 | checkm8, checkra1n | A5 to A11 bootrom; iOS 12 and later on iPhone 5s to iPhone X |
| 2020 | unc0ver 5.0, Odyssey | iOS 11.0 to 13.5; iOS 13.0 to 13.7 |
| 2021 | Taurine | iOS 14.0 to 14.8.1 |
| 2022 | Fugu15, TrollStore | iOS 15.0 to 15.4.1 on A12 and later; TrollStore from iOS 14 |
| 2023 | Dopamine, palera1n, TrollStore 2 | iOS 15.0 to 15.4.1; iOS 15 and later on A8 to A11; TrollStore up to iOS 17.0 |
| 2024 | Dopamine 2.0 | Adds iOS 15.5 to 16.5.1 on A12 and later |
| 2026 | Dopamine 3.0 | Up to 17.3.1 on A12 and later; 18.7.1 on A8 to A13; 26.0 to 26.0.1 on A12 and A13 |
What an iOS jailbreak actually changes
iOS normally runs only code signed by Apple or by a registered developer, keeps each app inside a sandbox and boots from a verified, read-only system. A jailbreak chains exploits to get around those rules, usually a kernel bug plus bypasses for newer hardware protections, then installs a package manager so users can add software.
Jailbreaks are described by what happens after a restart, and that detail decides how practical a tool is day to day:
- Untethered: the jailbreak survives a reboot on its own. JailbreakMe and evasi0n worked this way.
- Tethered: the phone needs a computer to boot into a jailbroken state every time.
- Semi-tethered: the phone restarts into normal iOS, and you reconnect it to a computer to turn the jailbreak back on. checkra1n and palera1n use this model.
- Semi-untethered: after a reboot you rerun an app on the device itself. Dopamine works this way.
- Rootful or rootless: older jailbreaks wrote to the system partition. Rootless jailbreaks keep their files in a separate location and leave the system volume untouched, which makes them easier to remove.
2007: the first iPhone, the carrier lock and the first jailbreak
Apple put the original iPhone on sale in the US on June 29, 2007, tied to AT&T. The phone had no App Store, and Apple’s grip on both software and carrier made it an instant target. For how the hardware itself developed from there, see this history of every iPhone generation since 2007.
The first famous hack was about the carrier. In August 2007 New Jersey teenager George Hotz (geohot) freed his iPhone from AT&T with a hardware modification, then traded that phone to CertiCell founder Terry Daidone for a Nissan 350Z and three 8GB iPhones.

Software methods followed within weeks. iPhoneSIMfree sold a paid tool, and hackers who studied it learned the iPhone’s baseband could be reflashed in software. In September 2007 the iPhone Dev Team released iUnlock, which Engadget described as the first free and open SIM tool of its kind, and easier point-and-tap apps such as anySIM followed.

Apple answered in late September. It warned that carrier-hacking programs caused irreparable damage to iPhone software, that a future update would likely leave modified phones permanently inoperable, and that owners had voided their warranty. iPhone 1.1.1 arrived days later, and owners of modified phones reported lockouts and anxious waits for workarounds.
Steve Jobs had framed the fight days before at Apple’s London store, calling it a cat-and-mouse game and conceding, “I’m not sure if we are the cat or the mouse.”
The jailbreak most owners could actually run came next. JailbreakMe, by developers cmw and dre, jailbroke iPhone OS 1.0.2 and 1.1.1 straight from a web page in Safari, with no computer involved. That model, open a site and tap a button, returned twice more before Apple closed the door on it.
2008 to 2011: Cydia, redsn0w and one-tap JailbreakMe
Jay Freeman, known as saurik, gave the scene its storefront. He built Cydia on Debian’s APT packaging system after deciding the earlier Installer.app handled software dependencies badly, and a developer’s request for a graphical front end turned that work into Cydia. For years, installing Cydia was what most people meant by jailbreaking.

July 2008 changed the argument. Apple opened the App Store, which logged 10 million downloads in its first three days from more than 800 native apps. The same month the iPhone Dev Team shipped PwnageTool 2.0, which jailbroke the new iPhone 3G but could not free it from its carrier. Jailbreaking was no longer the only way to get third-party apps, so it became about what Apple would not allow.
On June 20, 2009, the Dev Team released redsn0w for iPhone OS 3.0 on Mac and Windows, covering the original iPhone, iPhone 3G and early iPod touch models. A year later, on July 26, 2010, the Library of Congress added a DMCA exemption for jailbreaking phones, the legal milestone covered in more detail below.
In early August 2010 the hacker comex relaunched JailbreakMe with Star, a browser jailbreak that worked on the brand-new iPhone 4 by abusing the way iOS rendered PDF files. Apple shut it down with iOS 4.0.2 on August 11, 2010, an update devoted to fixing that PDF flaw. A flaw a hobbyist could trigger from a web page was just as available to criminals, so the fix could not wait.

Hardware bugs mattered too. On October 8, 2010, geohot released limera1n, built on a bootrom exploit for A4 devices such as the iPhone 4 and original iPad. The Chronic Dev Team shelved its own bootrom exploit, SHAtter, rather than give Apple two different exploits to block.
Comex struck again in July 2011 with JailbreakMe 3.0, known as Saffron, which jailbroke the iPad 2 from Safari. Apple patched the underlying PDF bug in iOS 4.3.4 on July 15, 2011.
2012 to 2013: Absinthe, evasi0n and the peak of jailbreaking
The A5 chip in the iPhone 4S and iPad 2 was harder to crack. On January 20, 2012, pod2g, the Chronic Dev Team and the iPhone Dev Team released Absinthe, the first untethered jailbreak for the iPhone 4S and iPad 2.

evasi0n was the high point. Released on February 4, 2013 by the evad3rs team for iOS 6, including the iPhone 5, it was used on nearly seven million devices in its first four days, according to counts from Cydia. Apple’s iOS 6.1.3 update on March 19, 2013 closed several of the flaws it used, and Apple credited the evad3rs for four of them.

The iOS 7 follow-up, evasi0n7, arrived in December 2013 and quickly turned into a scandal. Users in China found it installing TaiG, a Chinese app store that carried hundreds of pirated apps. The evad3rs dropped TaiG and ended the partnership within days, but the episode foreshadowed the commercial turn of the next few years.
2014 to 2018: Pangu, TaiG, Yalu and Electra
From 2014, Chinese teams released many of the major public jailbreaks. Pangu’s first tool, for iOS 7.1.1, launched as a Windows-only download that installed a Chinese app store with pirated apps alongside Cydia. TaiG followed on November 28, 2014 with a jailbreak for iOS 8.0 to 8.1.1, roughly two weeks after Apple closed Pangu’s iOS 8 exploit.
The risks stopped being theoretical in 2015. Palo Alto Networks’ Unit 42 found KeyRaider malware spreading through third-party Cydia repositories in China, and it had stolen more than 225,000 Apple account credentials from jailbroken devices. The malware worked only because those phones had their security layers removed.
Researcher Luca Todesco carried iOS 10. His yalu102 tool, released in January 2017, supported iOS 10.0 through 10.2 on many 64-bit devices, though not the iPhone 7 at first. Forensics firms used it too, since a jailbroken phone allows a deeper data extraction, a reminder that jailbreak exploits cut both ways.
For iOS 11, CoolStar’s open-source Electra used an exploit published by security researcher Ian Beer to jailbreak iOS 11.0 to 11.1.2. Public exploit write-ups, rather than private teams sitting on bugs, increasingly became the raw material for community tools. In December 2018 saurik also shut down purchases in the Cydia Store, a sign of how much smaller the paying audience had become.
2019: checkm8 and checkra1n, the bootrom exploit Apple cannot patch
On September 27, 2019, researcher axi0mX published checkm8, an exploit for a flaw in Apple’s bootrom rather than in iOS itself. According to the CERT/CC vulnerability note, it affects Apple A5 through A11 chips, from the iPhone 4S to the iPhone X, and because it lives in read-only Boot ROM code no software update can fix it on those devices.
The same note sets clear limits. An attacker needs physical access and a USB connection with the device in DFU mode, the exploit does not persist after a restart, and it cannot reach data protected by the Secure Enclave or Touch ID without the passcode. For owners, that means checkm8 is a jailbreak foundation, not a remote hacking tool.
The checkra1n team turned it into a usable semi-tethered jailbreak for iPhone 5s through iPhone X on iOS 12.0 and later, with a catch on A11 devices running iOS 14, which have to remove their passcode. Because Apple cannot patch the bootrom, every iOS release those phones can install stays jailbreakable in principle. The limit is the device, not the software.
2020 to 2021: unc0ver, Odyssey and Taurine
In May 2020, Pwn20wnd’s unc0ver 5.0 used an unpatched kernel bug to jailbreak every device on iOS 11 through the then-current iOS 13.5. Apple fixed it in iOS 13.5.1 on June 1, 2020, and its security note for that update credits the flaw, CVE-2020-9859, to the unc0ver team. The unc0ver project page still lists support from iOS 11.0 to 14.3.
CoolStar’s team built the other main line. Odyssey supported iOS 13.0 to 13.7, including A12 and A13 devices, and paired the open Procursus bootstrap with the Sileo package manager instead of Cydia. Taurine took the same approach for iOS 14 and now lists support from 14.0 to 14.8.1. On CoolStar’s jailbreaks, Sileo had replaced Cydia.
2022 to 2024: Fugu15, Dopamine, palera1n and TrollStore
Jailbreaks for Apple’s A12 and later chips need more than a kernel bug. In October 2022 Linus Henze open-sourced Fugu15, a developer-focused jailbreak for iOS 15.0 to 15.4.1 on those arm64e devices that bundled a kernel exploit with bypasses for pointer authentication (PAC) and the page protection layer (PPL).
Developer opa334 (Lars Fröder) turned that research into Dopamine, a rootless, semi-untethered jailbreak. Version 1.0 arrived on May 3, 2023 for iOS 15.0 to 15.4.1 on arm64e devices, and Dopamine 2.0 on February 16, 2024 added iOS 15.5 to 16.5.1 on arm64e plus iOS 15.0 to 16.6.1 on older arm64 devices.
checkm8 devices got a successor to checkra1n in palera1n, which supports A8 to A11 and Apple T2 devices on iOS and iPadOS 15.0 and later, with rootless and rootful modes. Its documentation says A11 phones (iPhone 8, 8 Plus and X) must run without a passcode while jailbroken, and on iOS 16 need a full reset before you start.
TrollStore is not a jailbreak, though it came from the same community. Released by opa334 on September 2, 2022, TrollStore is a permanently signed app that installs any IPA file by abusing a CoreTrust bug in how iOS checks code signatures with multiple signers. TrollStore 2.0, released on November 27, 2023, used a second CoreTrust flaw, CVE-2023-41991, to cover iOS 14.0 beta 2 through 16.6.1, the 16.7 release candidate and iOS 17.0. The README says 17.0.1 and later will never be supported unless a third CoreTrust bug turns up.
The patch shows how jailbreak bugs and spyware overlap. Apple fixed CVE-2023-41991 in iOS 17.0.1 and 16.7 on September 21, 2023, and its security note says the issue may have been actively exploited. The Citizen Lab and Google’s Threat Analysis Group had traced that exploit chain to Predator spyware aimed at Egyptian politician Ahmed Eltantawy, the same class of commercial surveillance tool that made NSO Group’s Pegasus infamous.
Can you jailbreak iOS 17, iOS 18, iOS 26 or iOS 27 in 2026?
The honest answer depends on your chip and exact build, not the headline iOS number. Dopamine 3.0 on August 7, 2026 was a major release: it added a PPL and SPTM bypass called Titan and a second bypass called momentarius, and it now describes itself as a jailbreak for iOS 15 through 26.0.1. MacRumors reported it as the first jailbreak of any kind for iOS 26. Here is where things stand as of September 14, 2026:
- iOS 17: Dopamine supports iOS 17.0 to 17.3.1 on all its arm64e devices (A12 and later, plus M1 and M2 iPads), and A12 and A13 devices on every iOS 17 release. Other arm64e support stops at 17.3.1, and the 3.0 notes cite the lack of a bypass for Apple’s SPTM protection on 17.4 and later, so A14 to A17 devices on iOS 17.4 or newer have no Dopamine option.
- iOS 18: Dopamine reaches iOS 18.7.1 on A8 to A13 devices, which includes the iPhone XS, XR, iPhone 11 series and older iPads. palera1n also covers checkm8 iPads that got iPadOS 18, such as the seventh-generation iPad. Dopamine has no iOS 18 support for A14 and newer devices, and iClarified’s compatibility guide likewise lists A14 to A17 support only through iOS 17.3.1.
- iOS 26: only 26.0 and 26.0.1 on A12 and A13 devices, which in iPhone terms means the iPhone 11 series and the second-generation iPhone SE. No checkm8 device can run iOS 26, and there is no public jailbreak for iOS 26.1 or later.
- iOS 27: Apple released iOS 27 on September 14, 2026 for iPhone 11 and later. No public jailbreak supports it, and Dopamine’s 3.0 notes say its iOS 27 beta support for newer chips runs only on Corellium virtual devices.
Much of Dopamine’s newer iOS 16 to 18 support runs through a kernel exploit option called DarkSword, which first appeared in its betas on March 26, 2026. That shares its name with a full iOS exploit chain that Google Threat Intelligence Group documented on March 19, 2026. Google says commercial surveillance vendors and a suspected Russian espionage group used DarkSword against iOS 18.4 to 18.7 since at least November 2025, that its kernel-level bugs were fixed in iOS 18.7.2 and 26.1, and that all six flaws were patched by iOS 26.3. Those patch points line up with where public jailbreak support stops.
Apple’s security release list shows how far older hardware now reaches. The iPhone 8 and X still get iOS 16.7 security updates and the iPhone 6s and 7 get iOS 15.8 updates, but neither can move to a newer major version, while iOS 18.7.10 (August 17, 2026) went to the iPhone XS, XR and seventh-generation iPad. Current iPhone 11 and later models were on iOS 26.6.2, released September 8, 2026, before iOS 27 arrived.
Two more facts shape the outlook. The iPhone 17 lineup and iPhone Air introduced Memory Integrity Enforcement, an always-on memory-safety system for the kernel and more than 70 userland processes on A19 chips, aimed at the memory-corruption bugs that mercenary spyware chains, and most jailbreaks, depend on. And Apple’s secure software update process personalizes each install and lets Apple stop signing older versions, so a supported range only helps if your device is already on it. A phone that has updated past 26.0.1 generally cannot go back.
Treat any website or app that promises a jailbreak for iOS 26.1 or later, or for iOS 27, as a scam. The tools covered here are published on their developers’ GitHub or project pages, so be wary of any site that claims to jailbreak from a web page or asks you to install a configuration profile.
Why fewer people jailbreak an iPhone in 2026
Many reasons to jailbreak in 2010 have faded. Apple has built in many kinds of customization that once needed tweaks (this guide to built-in iOS features covers several), and policy changes removed other motives. Apple began allowing retro game emulators in the App Store worldwide in April 2024, and users in the European Union, Japan and Brazil can now install apps through alternative app distribution outside the App Store. Developers have more official channels as well, from TestFlight to unlisted App Store apps.
What remains is a smaller audience: security researchers, tweak developers, people who want deep system control on a spare device, and owners of older phones Apple no longer updates. For them, the ecosystem is healthier than the headlines suggest. For everyone else, the trade-offs below usually outweigh the gains.
Is jailbreaking legal? US law and Apple’s terms
In the United States, jailbreaking your own phone is lawful under a Section 1201 exemption to the DMCA, first granted in 2010 and renewed in each three-year review since. The current final rule from the Librarian of Congress, effective October 28, 2024, renews the jailbreaking exemptions for smartphones and other portable all-purpose computing devices, smart TVs, voice assistant devices and routers for three more years, and no one filed opposition to renewal.
The exemption protects noninfringing uses, such as making lawfully obtained apps work on your device or removing software you do not want. It does not make pirated apps legal. Laws differ outside the US, so check local rules before relying on the American exemption.
Legal is not the same as supported. Apple’s own iPhone User Guide says unauthorized modification of iOS violates the iOS and iPadOS Software License Agreement and that Apple may deny service for an iPhone with unauthorized software installed. Apple’s one-year limited warranty also excludes any Apple product modified to alter its functionality or capability without Apple’s written permission.
Jailbreak risks: security, warranty, banking apps and updates
Apple’s user guide lists the problems it attributes to jailbreaking, and real incidents back several of them up. The main costs:
- Security: a jailbreak removes the layers that keep apps apart and block unsigned code, which is exactly what KeyRaider exploited. Apple warns that attackers could then steal personal data, attack your network or install malware and spyware.
- Stability and battery: Apple cites crashes and freezes, data loss, faster battery drain, dropped calls and unreliable data. Tweaks written for one iOS build can break another. Phone security apps cannot restore protections the jailbreak itself switched off.
- Apple services: Apple says iCloud, iMessage, FaceTime, Apple Pay and Visual Voicemail may be disrupted, and push notifications can fail.
- Warranty and repairs: Apple may refuse service, and the warranty excludes modified devices, as covered above.
- Banking, work and game apps: many apps check for jailbreaks. NatWest, for example, says Touch ID login is unavailable on a jailbroken iPhone. Niantic lists jailbroken devices as unsupported for Pokémon GO, and employers using Microsoft Intune can mark jailbroken devices as noncompliant, which can cut off work email and apps.
- Updates: installing an iOS update typically removes the jailbreak, Apple warns some modifications can leave a phone inoperable after a future update, and you usually cannot downgrade. Many jailbreak users skip updates to keep their setup, which leaves them exposed to flaws that spyware such as DarkSword already used.
Who should not jailbreak
- Anyone whose only phone handles banking, Apple Pay, two-factor codes or work accounts
- People who do not keep current backups or cannot afford a full restore and data loss
- Anyone on iOS 26.1 or later, or iOS 27, where the only jailbreak offers are scams
- Journalists, activists and others who may be targeted by spyware, who are better served by keeping iOS updated and turning on Lockdown Mode
- Anyone planning to sell or trade in the phone soon
Jailbreaking still makes sense for a spare device that holds nothing important, such as an iPhone 8 or X on palera1n or an iPhone 11 that never left iOS 26.0.1, used by someone who wants to learn how iOS works or build tweaks. Keep it off your main Apple Account if you can, and install packages only from repositories you trust.
iOS jailbreaking FAQs
Can you jailbreak iOS 26?
Only in a narrow case. Dopamine 3.0, released on August 7, 2026, supports iOS 26.0 and 26.0.1 on devices with A12 or A13 chips, which covers the iPhone 11 series and the second-generation iPhone SE. There is no public jailbreak for iOS 26.1 or later, or for iPhone 12 and newer models on any iOS 26 build, and Apple’s signing system generally stops you from downgrading.
Is there a jailbreak for iOS 27?
No. Apple released iOS 27 on September 14, 2026 for iPhone 11 and later, and no public jailbreak supports it. Dopamine 3.0’s release notes say its iOS 27 beta support for newer chips works only on Corellium virtual devices, not real iPhones. Treat any site offering an iOS 27 jailbreak as a scam.
Is jailbreaking an iPhone legal in the US?
Yes, for your own device. The Librarian of Congress first exempted phone jailbreaking from the DMCA anti-circumvention rule in July 2010, and the current rule, effective October 28, 2024, renews the exemption for smartphones and other portable all-purpose computing devices for three years. It covers noninfringing uses such as running lawfully obtained apps, not piracy, and Apple still treats jailbreaking as a breach of its software license.
Does jailbreaking void your iPhone warranty?
It can. Apple’s one-year limited warranty excludes Apple products modified to alter their functionality or capability without Apple’s written permission, and Apple’s iPhone User Guide says Apple may deny service for an iPhone with unauthorized software installed.
What is checkm8 and can Apple patch it?
checkm8 is a bootrom exploit published on September 27, 2019 that affects Apple A5 through A11 chips, from the iPhone 4S to the iPhone X. It sits in read-only Boot ROM code, so no software update can fix it on those devices, but it needs physical access and a USB connection, does not survive a reboot and cannot reach Secure Enclave data without the passcode. It is the basis of checkra1n and palera1n.
Is TrollStore a jailbreak?
No. TrollStore is a permanently signed app that installs IPA files by abusing a CoreTrust code-signing bug, while the device stays jailed. Its README lists support for iOS 14.0 beta 2 through 16.6.1, the 16.7 release candidate and iOS 17.0, and says 17.0.1 and later will never be supported unless a third CoreTrust bug appears. Apple fixed the second bug in iOS 17.0.1 and 16.7 on September 21, 2023.
What was the first iPhone jailbreak most people could use?
JailbreakMe. In 2007 it jailbroke iPhone OS 1.0.2 and 1.1.1 from a web page in Safari with no computer needed. The idea returned with comex’s JailbreakMe 2.0 in August 2010 and JailbreakMe 3.0 in July 2011, which Apple shut down with iOS 4.0.2 and iOS 4.3.4.





Share Your Thoughts