跳到正文

0xjohnnydev

airlift

AirLift — paired-Mac AirTraffic/ATAirlock sandbox escape for iOS 27.0

README 已保存到本站,可直接阅读

Documentation snapshot

README 快照

这篇是英文原文

下面正文是项目自己的英文 README。想读全文就用浏览器自带的整页翻译: Chrome / Edge 点地址栏右侧的翻译图标,或用右键菜单里的「翻译成中文」; 手机浏览器一般在菜单里。

本页保存的是公开项目资料快照,阅读过程不需要连接 GitHub。

airlift

An AirTraffic sandbox escape for iOS 27.0.

This is a simple proof-of-concept for developers and security researchers.

If you are worried about 🔥🪲4⃣☁️ (burning bugs for clout) - there are always more bugs

AirTraffic syncs media, including Books, from a Mac to iOS. airlift abuses that path to read and write files outside AirTraffic’s intended directory scope. It runs from a paired Mac over Wi-Fi or USB, with no iOS app required. Tested on iOS 27.0 RC (24A435); it should also work on iOS 27.0 final (24A437). Other iPhone builds are allowed with a warning.

Verified scope

Fresh-file writes were confirmed in the following directories:

/var/mobile
/var/mobile/Documents
/var/mobile/Library
/var/mobile/Library/Preferences
/var/mobile/Library/Caches
/var/mobile/Library/SpringBoard
/var/mobile/Library/SMS
/var/mobile/Library/Safari
/var/mobile/Containers
/var/mobile/Containers/Data/Application
/var/mobile/Containers/Shared/AppGroup
/var/tmp

Reads are indirect: a known file is moved into Media, read through AFC, and moved back.

As of now, this does not work on the MobileGestalt plist.

Components
──────────────── macOS ────────────────
MobileDevice.framework
↓
AirTrafficHost.framework

───────────────── iOS ─────────────────
com.apple.streaming_zip_conduit
↓
com.apple.afc
↓
com.apple.atc / AirTrafficDevice
↓
Books sync client
↓
ATLegacyAssetLink
↓
ATAirlock
↓
NSFileManager
ATAirlock path validation

Effective logic in -[ATAirlock processCompletedAsset:] for these Book assets:

// Books "Persistent ID" reaches asset.identifier without path validation.
NSString *source =
    [@"/var/mobile/Media/Airlock/Book"
        stringByAppendingPathComponent:asset.identifier];

// FileComplete.AssetPath controls asset.path.
NSString *destination =
    [[@"/var/mobile/Media/"
        stringByAppendingPathComponent:asset.path]
        stringByStandardizingPath];

// This checks the path string, not where a symlink resolves.
if (![destination hasPrefix:@"/var/mobile/Media/"])
    return;

// The source is unchecked and the destination follows ancestor symlinks.
[fileManager moveItemAtPath:source
                     toPath:destination
                      error:&error];

The unchecked source accepts .. components from a Books asset identifier. StreamingZip accepts the relative symlink while it is still contained in its extraction directory. The first move relocates it below Media; the second uses it as part of the destination and writes the payload outside Media.

The included PoC writes a random canary, verifies it, and removes it. Existing Books sync files are preserved and restored after the run.

Build and run

airlift lists compatible paired iPhones and asks which one to use. Pass a UDID with --device to skip the prompt. Failed runs include helper diagnostics; pass --verbose to include them on successful runs too.

make
./airlift.py

# Choose another destination.
./airlift.py --target /var/mobile/Library/Safari

The default destination is /var/mobile/Library/SpringBoard.

Official distribution

获取与安装

暂未发现可确认的官方软件包地址

当前 README 快照没有出现 npm、PyPI、Crates.io、pub.dev 等官方包页链接。本站不会根据仓库名称猜测下载地址。

本站不托管项目文件;需要安装时,请以项目维护者发布的官方文档为准。

使用前核验

本站保存公开资料用于阅读,不代表安全审计或功能背书。安装前请核对许可证、依赖来源和发布签名,不要直接运行来源不明的二进制文件或高权限脚本。