The unc0ver group had announced to wait for the release of iOS 13.5 to publish the new version of its jailbreak tool.
Apple has released iOS 13.5, unc0ver has released version 5.0.0 of its jailbreak tool, followed quickly by a stable version 5.0.1, fixing some problems: https://github.com/pwn20wndstuff/Undecimus/releases and https://www.unc0ver.dev/
This tool allows you to jailbreak (unlock) all Apple devices running on iOS versions 11 to 13.5 ie:
- iPhone 11, 11 Pro, 11 Pro Max, XR, XS, XS Max, 8, 8 Plus, 7, 7 Plus, 6S, 6S Plus, SE, 6, 6 plus
- iPad Pro 2018, 1st generation, 2nd generation, 10.5 inch
- iPad 7th, 6th and 5th generation
- iPad Mini 4, Air 2, Air 3
This jailbreak relies on the checkm8 vulnerability already mentioned earlier but also on a kernel vulnerability discovered by pwn20wnd (https://twitter.com/pwn20wnd) allowing to specifically unlock iOS 13.5.
As the jailbreak tool has been released, it didn't take long for others to analyze it and extract the core vulnerability. This is the case of the Russian company ElcomSoft, which has already communicated on the integration of the vulnerability in its tools:
The jailbreak tool requires physical access to the terminal and to have the code to unlock it, but this still presents a risk with respect to Apple equipment in business and for individuals, let's not forget them 😉. There is also a way to jailbreak iOS 13.5 without going through a computer and therefore without physical access in the sense of "plugging a cable", using the kinds of alternative application stores, allowing to add internal application stores, mainly for businesses (enterprise store).
It is necessary to install in the trusted profiles of its iPhone or iPad as :
This technique requires an unlocked iPhone or iPad (or with the code) and with access to the Internet (or a WiFi relaying an Internet access) but it is not "zero click" as could be the chain of vulnerabilities Mail and a core.
Note that the jailbreak method using Cydia Impactor does not really work since fall 2019 because Apple has changed the operation of the signatures of applications, no longer allowing to have a free account and therefore requiring a paid developer account: https://twitter.com/saurik/status/1196888477830221824