May 26, 2020

unc0ver Jailbreak

Lookout Recommendation for Admins

Lookout Mobile Endpoint Security has a default policy to alert the device user and the organization’s Lookout admin when a device is jailbroken. Lookout also covers Android devices being rooted, which is key for any organization running both iOS and Android devices in their mobile fleet.

Since a jailbreak for iOS or rooting for Android can lift many native protections and restrictions on a device, jailbreaking/rooting should be prohibited as part of an organization’s security and mobility policies. In the event that a user violates this policy, Lookout can block jailbroken and rooted devices from accessing any company apps or data until the device is brought back into compliance. Users can disable the unc0ver jailbreak by rebooting their device.

Overview

Unc0ver is a widely used jailbreak that has been present in the market for some time, and more recently started taking advantage of an iOS kernel vulnerability discovered in 2019. It can be installed on iOS devices from Windows, Linux, or macOS machines. Unc0ver supports iOS 11.0 through iOS 13.5 with the exception of 12.3-12.3.1 and 12.4.2-12.4.5.

This makes it widely consumable and means that even the newest devices such as the iPhone 11, 2020 iPad Pro, and iPhone SE can all be jailbroken using unc0ver. Lookout can detect unc0ver and protect organizations against it.

How Does it Work?

Like other jailbreaks, unc0ver takes advantage of a vulnerability in the device’s operating system to enable the user to have more control over the device than is normally allowed by the manufacturer. From a macOS, Windows, Linux, or iOS device, the user only has to follow a few basic steps in order to download the necessary tools to support the mobile jailbreak and have full access to their iOS device with the native iOS security and protections lifted. Everything to support this process is open-source and accessible on unc0ver’s website, GitHub, and other sources, making it widely available. Once the jailbreak is complete it installs Cydia, a 3rd-party app store, and its pre-configured app repositories to the device.

Authors

Lookout

Cloud & Endpoint Security

Lookout is a cybersecurity company that makes it possible for tens of millions of individuals, enterprises and government agencies to be both mobile and secure. Powered by a dataset of virtually all the mobile code in the world -- 40 million apps and counting -- the Lookout Security Cloud can identify connections that would otherwise go unseen and predict and stop mobile attacks before they do harm. The world’s leading mobile network operators, including AT&T, Deutsche Telekom, EE, KDDI, Orange, Sprint, T-Mobile and Telstra, have selected Lookout as its preferred mobile security solution. Lookout is also partnered with such enterprise leaders as AirWatch, Ingram Micro, Microsoft, and MobileIron. Headquartered in San Francisco, Lookout has offices in Amsterdam, Boston, London, Sydney, Tokyo, Toronto and Washington, D.C.

Platform(s) Affected
iOS
Threat Type
Vulnerability
Entry Type
Threat Guidances
Platform(s) Affected
iOS
Vulnerability
Threat Guidances

Stop Cyberattacks Before They Start With Industry-Leading Threat Intelligence.

HeaderHeaderHeaderHeader
CellCellCellCell
CellCellCellCell
CellCellCellCell
CellCellCellCell