Skip to content
This repository was archived by the owner on Aug 27, 2026. It is now read-only.
This repository was archived by the owner on Aug 27, 2026. It is now read-only.

Remotecall problem #71

Description

@tureefy

What happened?

All tweaks that rely on RemoteCall cannot function properly.

Device: iPad Pro (11-inch) (4th Generation)

The error log is shown below:
KRW No cached state — running fresh exploit chain.

  • Running on non-A18/M4 device
    KRW Racing TCP socket zone allocator...
  • readFd: 15
  • writeFd: 16
    i process marker guest='Cyanide' host='Cyanide' kernel='Cyanide'
    i process_marker[0]=Cyanide
    i totalSearchMappingPagesNum: 0x10000
    i searchMappingSize: 0x8000000
    i totalSearchMappingSize: 0x40000000
    i searchMappingNum: 0x8
  • physicalMappingAddress: 0x115dbc000
  • pcObject: 82435
  • pcAddress: 0x3c439c000
    i socketPortsCount: 22528
    i startPcbId: 90116
    i endPcbId: 135170
    i looking in search mapping: 0
  • matched PCB via process marker: Cyanide
  • pcbStartOffset: 0
  • targetInpGencnt: 0x1c5a2
  • inpListNextPointer: 0xfffffe1315f40400
  • icmp6Filter: 0xfffffe16156b5840
    KRW restore snapshot saved controlFilter=0xfffffe16156b5840 rwFilter=0xfffffe16156b5860
  • Corrupting icmp6filter pointer...
  • target corrupted: 0xfffffe1315f40548
  • Found control_socket at idx: 13007
  • pe_v1: post-acquire cleanup complete
  • highestSuccessIdx: 500
  • successReadCount: 680
    OK Kernel memory r/w acquired.
  • controlSocketPcb: 0xfffffe1315f40000
  • pcbinfo_pointer: 0xfffffe004c137bd0
  • ipi_zone: 0xfffffe004902a9e0
  • zv_name: 0xfffffe00484b213a
  • searching for kernel Mach-O header from 0xfffffe00484b0000...
  • candidate Mach-O at 0xfffffe004844c000: filetype=2 cpuinfo=0x2c0000002 iter=25
  • candidate Mach-O at 0xfffffe0048444000: filetype=12 cpuinfo=0xc00000002 iter=27
  • found MH_FILESET header at 0xfffffe0048444000
  • kernel_base: 0xfffffe0048444000
  • kernel_slide: 0xfffffe1041440000
    OK Kernel mapped at 0xfffffe0048444000 (slide +0xfffffe1041440000).
    early_kread64(0xfffffe0048444000) -> 0x100000cfeedfacf
    win??
    PERSIST Anchoring KRW fileports in launchd for recovery...
    RemoteCall Found launchd in kernel (pid=1) — preparing EXC_GUARD thread hijack.
    [init_remote_call:1134] failed to resolve dummy thread kobject mach=0x1400b addr=0
    PERSIST init_remote_call(launchd) failed
  • kexploit_opa334: KRW persistence transfer failed
    WARN Couldn't park state — next run will re-exploit.
    RemoteCall Found SpringBoard in kernel (pid=33) — preparing EXC_GUARD thread hijack.
    [init_remote_call:1134] failed to resolve dummy thread kobject mach=0x11af17 addr=0
    GRAVITY SpringBoard not reachable.
    WARN Gravity Lite explosion found no active state.

Device

IPad Pro (11inch)(4Generation)

iOS version

18.1

Anything else?

No response

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workingstatus:investigatingEnough information exists to investigate

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions