[HN Gopher] iPhone 11 emulation done in QEMU
       ___________________________________________________________________
        
       iPhone 11 emulation done in QEMU
        
       Author : 71bw
       Score  : 363 points
       Date   : 2025-06-12 15:04 UTC (1 days ago)
        
 (HTM) web link (github.com)
 (TXT) w3m dump (github.com)
        
       | msgodel wrote:
       | Woah this sounds like it boots all the way to Springboard at
       | least! That's pretty huge!
        
       | ewuhic wrote:
       | Does it support trollstore with ability to decrypt IPAs?
        
         | skvmb wrote:
         | Came here to ask this very question. This would be killer if
         | so!
        
         | mywittyname wrote:
         | For the ignorant: what does this mean?
        
           | tom1337 wrote:
           | trollstore is an inofficial app store for iOS devices which
           | does not require a jailbreak. There are also apps that seem
           | to decrypt the encrypted IPA (which is the file format of an
           | iOS app) so you can view the decrypted app code and the
           | resources. it's kinda the same as decompiling a android java
           | app.
        
           | watusername wrote:
           | Just to expand a bit on the sibling comment, IPAs downloaded
           | from the App Store are encrypted with a DRM scheme with a key
           | tied to the Apple account. The binaries actually stay
           | encrypted on-disk and the OS has facilities to transparently
           | decrypt them when executed. The usual way of decrypting is to
           | actually execute the app, attach a debugger (normally not
           | possible for production apps) and read the decrypted code
           | from memory.
        
       | gnabgib wrote:
       | Discussion on upstream repo (356 points, 2022, 144 comments)
       | https://news.ycombinator.com/item?id=30545425
       | 
       | Related (mentions this repo): _Emulating an iPhone in QEMU_ (268
       | points, 2 months ago, 64 comments)
       | https://news.ycombinator.com/item?id=43592409
        
         | msgodel wrote:
         | Looking at the issue tracker it sounds like they've made
         | significant progress since then.
        
           | walterbell wrote:
           | Progress update, https://eshard.com/posts/emulating-
           | ios-14-with-qemu-part2                 iOS emulated in QEMU
           | with:            * Restore / Boot       * Software rendering
           | * Kernel and userspace debugging       * Pairing with the
           | host       * Serial / SSH access       * Multitouch       *
           | Network       * Install and run any arbitrary IPA
           | 
           | In other news, Cellebrite acquired Corellium iOS/Android
           | virtualization for $170M,
           | https://news.ycombinator.com/item?id=44221982
        
             | throwaway48476 wrote:
             | Presumably to build a exploit test framework.
        
             | bri3d wrote:
             | The eShard thing and this GitHub are fairly different, as
             | far as I know.
             | 
             | The eShard people found an earlier version of this
             | repository and set about patching one billion parts of the
             | iOS kernel, library cache, and userland to make it run on
             | the limited emulator.
             | 
             | Meanwhile, the actual emulator has been advancing, arguably
             | more quickly than the eShard patch set.
             | 
             | The current set of patches needed for the latest commits on
             | this repo to run iOS are less than 10 instructions, all to
             | enable the software-rendering/framebuffer fallback code
             | path instead of trying to use display drivers.
             | 
             | https://github.com/ChefKissInc/QEMUAppleSilicon/wiki/Filesy
             | s...
        
               | walterbell wrote:
               | Thanks for the wiki pointer.
        
               | sheepscreek wrote:
               | > set about patching one billion parts of the iOS kernel,
               | library cache, and userland to make it run on the limited
               | emulator
               | 
               | You don't say! They've hacked the whole process and it
               | feels extremely brittle. Like there's no chance they can
               | sustainably port this to another version of the software,
               | let alone hardware.
        
               | bri3d wrote:
               | In the interest of completeness I looked deeper and there
               | are a few more patches to the kernel and SEP OS done at
               | emulation time:
               | 
               | https://github.com/ChefKissInc/QEMUAppleSilicon/blob/6eff
               | 3ab...
               | 
               | but really nothing too extensive or hard to port. It's
               | mostly flipping various can_has_debug returns, bypassing
               | sigcheck, and the classic patch to flip launchd into
               | research device mode.
        
       | anthk wrote:
       | How does Qemu m68k work for Classic Mac BTW?
        
         | LeoPanthera wrote:
         | Not great. Use Mini vMac instead.
         | 
         | PPC emulation works fine though.
        
         | lioeters wrote:
         | It works. Technical discussions on running classic Macintosh
         | with Qemu m68k:
         | 
         | Qemu-system-m68k to run Mac OS 7-8 -
         | https://www.emaculation.com/forum/viewforum.php?f=37&sid=6a9...
        
       | dd_xplore wrote:
       | Is it emulating iOS? Or only running iOS binaries? Why does it
       | specifically say iPhone 11?
        
         | worldsavior wrote:
         | Probably because it's iPhone 11 binaries.
        
         | dadoum wrote:
         | It's emulating iPhone 11's hardware. It runs iOS 14 and sepOS
         | (Apple Security Enclave's firmware) on top.
        
       | jeswin wrote:
       | This is the ultimate emulation hack bar none - congrats to
       | everyone involved. This also bodes well for the hackintosh
       | project. It's may no longer be a dead end (though miles away),
       | and eventually we might even see efficient emulation as ARM PCs
       | become generally available.
        
         | storus wrote:
         | ARM is not an open platform like IBM PC was. See Android phones
         | and their custom Linux kernels with undocumented parts...
        
       | seany wrote:
       | Seems like the important part would be emulating the security
       | crap so it can be understood and bypassed. Where is this with
       | that set of things? (being able to run things like banking/DMV
       | emulated would be the killer feature)
        
       | VMtest wrote:
       | There is still no proper documentation for using qemu on windows
       | host, the options and arguments etc. We have to google and the
       | info and ideas that are scattered across the internet, or
       | referencing the Linux equivalents of it to come up with a
       | solution
        
         | Liquix wrote:
         | to be fair most folks playing around with qemu are probably
         | running unix. windows has plenty of user friendly
         | virtualization options (virtualbox, vmware, hyper-v), not to
         | mention WSL. so windows users would probably only run qemu in
         | hyperspecific cases like this
        
       | startyz wrote:
       | cool it is my favorite model of iphones.
        
         | Minks wrote:
         | What makes it your favourite model specifically? I can't really
         | notice a lot of differences between them and I've used multiple
         | devices the last 3 years.
        
       | xvilka wrote:
       | They should try to push it upstream, at least partially.
       | Otherwise it's doomed to die like previous attempts.
        
       | hiimwavy wrote:
       | This is incredibly impressive--booting an iPhone 11 all the way
       | to Springboard in QEMU is no small feat. Kudos to the ChefKissInc
       | team and everyone who's contributed to getting this far!
        
       | tifa2up wrote:
       | Noob question: can you install iOS apps using this?
        
       ___________________________________________________________________
       (page generated 2025-06-13 23:01 UTC)