How to find out and recover from jailbroken iPhone?

I heard about the Pegasus spyware on iOS and have updated my iPhone 6 plus to the latest iOS 9.3.5 and run the lookout app. I was shocked to find find that my iPhone, while not infected with Pegasus, was detected been jailbroken without my knowledge. Is it possible to find out how and when did the jailbreaking happen (installation date of jailbreaking data etc)? Cydia was not even installed.


Also, how can I restore or remove the jailbreak? A restore from iTunes has failed.


User uploaded file

iPhone 6 Plus, iOS 9.3.5

Posted on Aug 31, 2016 8:47 PM

Reply
11 replies

Aug 31, 2016 8:55 PM in response to Boon Hong Wong

Jailbreaking requires a considerable amount of effort and does not just "happen." There is no way to determine when was done. I suggest you talk to the previous owner or those who had access to your phone. To get it removed, try restoring to factory setting, but this does not always work. Jailbreaking can cause permanent damage to the firmware which can't be removed.


Use iTunes to restore your iOS device to factory settings

Aug 31, 2016 9:00 PM in response to modular747

I read that updating the firmware or restoring to factory default can get it removed. But it didn't work for me. Anyway, my phone was brand new directly purchased from my Telcom, and it has no sign of any jailbreak at all. Everything seems to be working fine and I have no app that are outside of the official app store. This make me wonder what and how did lookout think that my iphone has been jailbroken.

Aug 31, 2016 9:01 PM in response to Boon Hong Wong

Boon Hong Wong wrote:


Lookout app - https://itunes.apple.com/sg/app/lookout-security-backup-missing/id434893913?mt=8


Lookout claims that iOS 9.3.5 does not uninstall or detect Pegasus on previously infected devices - https://www.lookout.com/

Read the app review for a start.

Anyway, I will not trust a 3rd party tool for my security.

BTW, all 3rd parties apps are sandboxed so how they get the info is a mystery.

If I am you, I will delete the app right away.

Sep 1, 2016 7:22 AM in response to Boon Hong Wong

Boon Hong Wong wrote:


Lookout app - https://itunes.apple.com/sg/app/lookout-security-backup-missing/id434893913?mt=8


Lookout claims that iOS 9.3.5 does not uninstall or detect Pegasus on previously infected devices - https://www.lookout.com/

While I see no point to the app, I would point out that Lookout Inc was one of the companies that originally identified the operating system exploits that allowed the Trident exploit to work. They reportedly worked with Apple itself to identify the issues (validation issues and memory utilization issues) that were patched with iOS 9.3.5. The iOS patch fixes those kernel exploits so the operating system exploits that allow pegasus and Trident to work no longer exist. So even if some Pegasus code remained on the device, it can no longer function in iOS 9.3.5.


iOS 9.3.5 never claimed to seek, identify nor remove any malicious code. It does fix the operating system exploits that allowed the code to run and work. With those exploits patched, the malicious code itself is useless and cannot function.


As for the jailbreak, that could only have happened if someone had complete unrestricted physical access to your device for some period of time to install the j/b. If you erase all content and settings, or restore as new in iTunes, or remote wipe it with iCloud, it should be removed. You would then have to set up the device anew. If you restore from a backup, you may simply re-apply the jailbreak.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

How to find out and recover from jailbroken iPhone?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.