Skip to content

Releases: pwnapplehat/iPASide

iPASide 1.2.4

Choose a tag to compare

@pwnapplehat pwnapplehat released this 14 Aug 13:18

Pairing matches iLoader: mint the merged file once over USB, place it, then unplug. EscapeOS / StikDebug / SideStore talk to the phone over LocalDevVPN.

pairing --app com.ipaside.escapeos now finds the team-suffixed install.

EscapeOS remains iOS 18 and 26 only. iPASide still sideloads and places pairing files on iLoader's full range (15–26).

Verified: 505 pytest + 778 Flutter (6 skip) = 1,283. Pairing inspect and Place on iPhone 17 (iOS 26.5.1) with EscapeOS installed. Sideload of current EscapeOS 0.1.0 already landed on that phone this session.

The installer is unsigned, so SmartScreen will warn — the SHA-256 is in SHA256SUMS.txt.

iPASide 1.2.3

Choose a tag to compare

@pwnapplehat pwnapplehat released this 14 Aug 12:15

Pairing without iLoader

iPASide now creates Remote Pairing keys over USB on a trusted iPhone. Importing an iLoader file is optional.

Pairing lives in Settings → Pairing file: create / import / export, place into every supported app, or Place into one app (EscapeOS, SideStore, AltStore, LiveContainer, StikDebug). Sideloading EscapeOS still places pairingFile.plist automatically.

Installer

SHA256 of iPASide-Setup-1.2.3-x64.exe:

f815a5fd66a82f5149cb8b10b8bd0cae60989dbfb622c19f0455e792ce7875d4

Verified on iPhone 17 (iOS 26.5.1): create keys, sideload EscapeOS 0.1.1, auto-place pairing file.

iPASide 1.2.2

Choose a tag to compare

@pwnapplehat pwnapplehat released this 14 Aug 11:16

Added

  • Pairing file on Home: import an iLoader (or other) plist, export this PC's
    record as XML, and place it into every supported app on the phone — EscapeOS,
    SideStore, AltStore, LiveContainer, and StikDebug — under the filename each
    app looks for. Sideloading EscapeOS places the file automatically.
  • The card reports USB pairing keys and Remote Pairing keys separately, because
    iOS 26.4+ EscapeOS and StikDebug need the Remote Pairing half that Windows
    Lockdown alone does not write.

Verified

Tested using this exact installer:

  • Silent install reached install verified; bundled engine reported 1.2.2.
  • Installed iPASide.exe (not a debug run) showed Home pairing with USB,
    Remote Pairing, and Imported on an iPhone 17 (iOS 26.5.1).
  • Imported pairing file placed into EscapeOS /Documents/pairingFile.plist
    (9764 bytes). Sideloading EscapeOS also auto-placed pairing.
  • Shutdown left no iPASide or bundled-engine process behind.
  • 499 engine tests and 777 Flutter tests passed.

Windows 10/11 · 64-bit. The installer is not code-signed yet, so
SmartScreen may show “Windows protected your PC.” Choose
More info → Run anyway.

SHA256 6150ab1fe19e7f378816e88433da9cc2e14bc5cb4a47fa3d71bcb6e344685da0

iPASide 1.2.1

Choose a tag to compare

@pwnapplehat pwnapplehat released this 13 Aug 12:18

Fixed

  • Dopamine compatibility now uses the exact device and OS build. Eligible
    A12/A12X/A12Z iPads are supported on iPadOS 26.0–26.0.1, and Dopamine
    3.0.5's 26.1 beta 1–3 support is matched by build number without accepting
    the patched 26.1 final release.
  • Installation rechecks compatibility immediately before downloading and pins
    the resolved device UDID, so direct commands and device swaps cannot bypass
    the compatibility gate.
  • The live catalog now includes missing legacy and current iPhones, iPads and
    iPod touch models with their real firmware ceilings.
  • Portable-engine dependency assembly is isolated from packages installed on
    the build PC.

Verified

Tested using this exact installer and a physical iPhone 8 Plus (A11,
iOS 16.7.15):

  • Transactional upgrade from 1.2.0 and fresh install both reached
    install verified.
  • The shipped engine fetched schema 3, identified build 20H380, and reported
    the device supported.
  • Dopamine 3.0.5 completed download, provision, sign and installation over USB.
  • Cold start reached a window in 476 ms; shutdown exited with code 0 and left
    no app or engine process behind.
  • All engine tests and 764 Flutter tests passed; Flutter analysis reported no
    issues.

Windows 10/11 · 64-bit. The installer is not code-signed yet, so
SmartScreen may show “Windows protected your PC.” Choose
More info → Run anyway.

SHA256 154387be5e4aca8b875e1a79e483fedab25fd5c818751317c6a0b84f3517b0d7

iPASide 1.2.0

Choose a tag to compare

@pwnapplehat pwnapplehat released this 13 Aug 09:41

Added

  • Jailbreak tab. iPASide now checks whether Dopamine supports your connected iPhone — worked out from its chip and iOS version — and installs the latest release in one click. It is an ordinary sideload: iPASide signs and installs Dopamine and refreshes it before its 7-day profile expires, and the exploit only runs on the phone the first time you open Dopamine.
  • Live compatibility list. The supported chips and iOS ranges are fetched at runtime from compat/dopamine.json, so support can widen (a new iOS, a newer device) by editing that one file — no new iPASide build required. If the list can't be fetched, the tab shows a Retry button instead of guessing.

Verified end to end against a physical iPhone 8 Plus (A11, iOS 16.7.15): clean silent install, cold start, exit code 0 with no orphaned engine process, and a full Dopamine install over USB.

Windows 10/11 · 64-bit. The installer is unsigned, so SmartScreen shows "Windows protected your PC" — choose More info → Run anyway.

SHA256 b02ef0f113a937056d004777d02c5b936117d194d03cfdecd93ff7091af38f08

iPASide 1.1.6

Choose a tag to compare

@pwnapplehat pwnapplehat released this 01 Aug 16:07

Fixed

  • Update banner height. One horizontal strip now: status on the left, See Changes / Download|Install / Later on the right — no more stacked title + body + buttons burning vertical space.

Verify

  • Built from a4ab372
  • SHA256: 9d4fe6e567b23e42f3b409bee68e96da7eda8a0de2bd94807bf9eeb343efa63c
  • Upgrade over 1.1.5: install verified, engine 1.1.6

iPASide 1.1.5

Choose a tag to compare

@pwnapplehat pwnapplehat released this 01 Aug 15:57

Highlights

  • Update banner under the title bar: See Changes, Download / Install now, Later — same actions as Settings → Updates.
  • Silent upgrade hand-off: Install launches Setup with /SILENT /NORESTART /CLOSEAPPLICATIONS /RESTARTAPPLICATIONS, closes iPASide so AppMutex releases, and the installer relaunches the new build when done.

Verify

  • Built from f5d3f3c
  • SHA256: 0680327b88fb1d46d0600901de1d087bfe4b739a5202a45e8ccffd9f6cccc5aa
  • Fresh upgrade over 1.1.4: install log new install verified; rollback backup discarded, engine answered 1.1.5
  • Cold start ~417ms, close exit 0, no orphan engine processes
  • Update banner screenshot-verified (See Changes / Download / Later) against a live GitHub release check

Notes

Installer is unsigned (SmartScreen may warn). Full sideload of a large IPA was not re-run in this cut; device USB/Network connectivity was confirmed live during install verification.

iPASide 1.1.4

Choose a tag to compare

@pwnapplehat pwnapplehat released this 01 Aug 14:47

Fixed

Apple ID 2FA on Chinese Windows — code screen, but no code

On 1.1.3, sign-in reached the verification screen but Apple never sent a code (#5). 1.1.3 had fixed the latin-1 crash, but left Windows locale display names like Chinese (Simplified)_China in place because they are ASCII. Apple's trusted-device endpoint returns HTTP 500 for that value (proven live); the same request with zh_CN returns 200. Locales are now mapped to Apple-style tags, and a failed 2FA trigger is reported instead of claiming a code was sent.

Update to 1.1.4 and sign in again.


Verified live against Apple's servers before publishing. Installer is unsigned — SmartScreen will warn; SHA-256 is in SHA256SUMS.txt.

iPASide 1.1.3

Choose a tag to compare

@pwnapplehat pwnapplehat released this 31 Jul 10:22

Fixed

Apple ID sign-in failed on non-English Windows

Signing in died with 'latin-1' codec can't encode characters in position 0-5 after the password check had already succeeded (#3). The trusted-device 2FA step puts anisette fields on the HTTP request; on a Chinese Windows install the timezone display name is 中国标准时间, and HTTP headers must be latin-1. Timezone and locale are now rewritten to ASCII Apple-style values before they leave the engine.

If you hit this on 1.1.2 or earlier, update to 1.1.3 and sign in again — no cache wipe needed.


Verified: reproduced the exact encode error, fixed it, regression-tested, and confirmed in the installed 1.1.3 engine. The installer is unsigned, so SmartScreen will warn — the SHA-256 is in SHA256SUMS.txt.

iPASide 1.1.2

Choose a tag to compare

@pwnapplehat pwnapplehat released this 28 Jul 22:43

Fixed

Signing IPAs larger than about 2 GB

Big apps — a 4 GB game, for instance — failed the moment signing started, with "Unzip failed!". The bundled signer read archives through a 32‑bit file layer on Windows and couldn't reach the index of an IPA over 2 GB. It now uses 64‑bit file access for both reading and repacking. Proven by signing a real 4.19 GB IPA end to end and installing it on a phone. Apps under 2 GB were never affected — which is why most apps signed fine.

Signing in could get stuck on a cryptic archive error

If the one‑time download of Apple's provisioning libraries was blocked (a proxy or error page arriving instead of the file), or a first run was interrupted and left a half‑written cache, every later launch failed with a raw "not a gzip/bzip2/xz/tar file" error — and the only way out was to find and delete a file by hand. iPASide now discards an unusable cache and rebuilds it, checks the download really is the library archive (and retries), and shows a clear "the provisioning server may be down or your network is blocking it" message instead.

If you're already stuck on that error on 1.1.1 or earlier, deleting %LOCALAPPDATA%\iPASide\anisette\anisette.bin and signing in again clears it.


Verified end to end on a physical iPhone: a 4.19 GB IPA provisioned, signed, and installed (0→100%). The installer is unsigned, so SmartScreen will warn — the SHA‑256 is in SHA256SUMS.txt, and the in‑app updater checks it automatically.