Fake iOS jailbreak could be putting iPhone users at risk

iPhone X
(Image credit: Future)

A new vulnerability has been discovered which exists across legacy iOS hardware and while some have used it to jailbreak their devices, Cisco Talos recently discovered that cybercriminals have set up a fake website looking to capitalize on users trying to jailbreak their iPhones.

However, instead of actually jailbreaking a user's device, the site just prompts users to download a malicious profile that the attackers then use to conduct click fraud.

Checkm8 is a bootrom vulnerability that impacts all legacy models of the iPhone from the 4S through the X. The campaign discovered by Cisco Talos tries to capitalize off of a project called checkrain which uses the checkm8 vulnerability to modify an iPhone's bootrom and load a jailbroken image onto the device.

The Checkm8 vulnerability can be exploited using an open source tool called “ipwndfu” developed by AxiomX but the attackers being tracked by Cisco Talos run a malicious website called checkrain.com that preys on users searching for the legitimate checkrain project.

Checkrain

The fake checkrain site tries to appear to be legitimate by claiming to work with popular jailbreaking researchers such as “CoolStar” and Google Project Zero's Ian Beer. The page prompts users to download an application to jailbreak their phone but there actually is no application, as the attackers are trying to install a malicious profile onto the end-user device.

When a user first visits the fake website, they are presented with a download button. Cisco Talos noticed several things about the site, including the mention of A13 devices which aren't vulnerable to Checkm8, which indicate that the website is not legitimate.

Additionally, the website says that users can install the checkrain jailbreak without using a PC but in reality, the Checkm8 exploit requires that the iOS device be in DFU mode and is exploitable using an Apple USB cable. Another tip off was the fact that the fake checkrain site uses an SSL certificate from LetsEncrypt while the actual site doesn't even have an SSL certificate.

Once the download button is clicked, an app with a checkrain icon is downloaded an installed onto a user's iPhone. However, while the icon may appear like a regular app, it is actually a bookmark to connect to a URL.

Instead of providing users with an authentic jailbreak, the threat actors behind this campaign are instead using their devices to commit click fraud

As tempting as a jailbroken device may seem, by trying to exploit the Checkm8 vulnerability, you could be opening your device and your data to hackers.

Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Latest in Phone & Communications
GlocalMe KeyTracker
When I tested this global tracker, it trounced the Apple AirTag in so many ways
Privacy Hero II
Privacy Hero II VPN Router
ThinkPhone 25 by Motorola
I reviewed the ThinkPhone 25 by Motorola and while it's not as fast as its predecessor, it's the superior phone in so many ways
FRITZ!Box 7690 WiFi 7 Router
FRITZ!Box 7690 router review
Ulefone Armor Pad 4 Ultra Thermal
Ulefone Armor Pad 4 Ultra Thermal rugged tablet review
Unihertz Tank Pad 8849
Unihertz Tank Pad 8849 rugged tablet review
Latest in News
Zotac Gaming RTX 5090 Graphics Card
Nvidia Blackwell stock woes are compounded by price hikes as more RTX 5090 GPUs soar in pricing, and I’m sick and tired of it all at this point
A collage of Elizabeth Olsen's Scarlet Witch and Tatiana Maslany's She-Hulk
Marvel fans are already tired of Doomsday and Secret Wars cast gossip as two more superheroes get linked with roles in the next two Avengers movies
Four operators survey Verdansk. One holds a sniper rifle, one binoculars, another holds is landing with their parachute, while the last wears a skull mask
New Call of Duty: Warzone trailer shows a beautiful rebuilt Verdansk, but some fans want more: 'it won't be the same unfortunately'
An Apple Music pink/pixellated poster advertising DJ with Apple Music
DJ with Apple Music lands, allowing subscribers to build and mix DJ sets directly from its +100 million-song catalog
The Meta Quest 3 and controllers on their charging station which is itself on a wooden desk next to a lamp
Forget Android XR, I've got my eyes on Vivo's new Meta Quest 3 competitor as it could be the most important VR headset of 2025
Samsung Galaxy S25 from the front
The Now Bar on Samsung One UI 7 is about to get a lot more useful – and could soon match Live Activities on iOS