Note that, unlike Corellium, this isn't about emulating an iPhone. Apple is providing an iOS kernel for Virtualization.framework in PCC/cloudOS images and this project pairs it with the iOS user-space and patches to make everything run. Applications can very easily tell it apart from the real thing.
That would surprise me. I don't recall having to change my iPhone's region after moving to Japan. Transport IC cards in Apple Pay have "just worked".
I am vaguely aware that some phone manufacturers silently remove certain NFC hardware (or disable some driver) in order to avoid paying Sony patent fees. Apple doesn't seem to do that, though.
It will be to prevent access to third-party app stores as both the EU and Japan legislated they must be allowed.
> In a support document about alternative app marketplaces in the EU, Apple explained that “device eligibility for alternative app marketplaces is determined using on-device processing with only an indicator of eligibility sent to Apple.” In practice, iOS users in the EU who want to install alternative marketplaces will need to set the country or region of their Apple ID to an eligible country or region. Moreover, they will also need to be physically located in supported EU countries.
> In the case iOS users in the EU leave eligible regions, Apple will offer a “grace period” until apps downloaded from alternative app stores can no longer be updated. “If you’re gone for too long, you’ll lose access to some features, including installing new alternative app marketplaces. Apps you installed from alternative app marketplaces will continue to function, but they can’t be updated by the marketplace you downloaded it from,” the company explained.
It is wild that Apple finds it cheaper to build and maintain different App store behaviors than to simplify and make alt app stores available in all markets. Other governments/markets don't care?
It's a very slow process, first there is investigations, then legislation, then enactment, then enforcement which is separately a very slow process. It requires a lot of willpower to get and keep the ball rolling and in fact nobody has even achieved the full extent of what they require yet! The EU may still be years away from meaningful compliance, Japan has only taken baby steps forming a new bureau just to enforce compliance of two companies widely accused of malicious compliance.
And then there is additional discouragement and pressure in the form of sanction and trade deal threats for regulating American tech platforms.
It's vastly more profitable to maintain their monopoly on iOS apps and the 30% cut than to allow users to stop paying apple a cut of their transactions.
As someone using AltStore PAL to install some third-party apps that would never be allowed on the App Store (such as emulators and manga readers), I heavily disagree.
Everything that didn’t turn out exactly like some people wanted is useless or the Worst Thing Ever — which is a boring and cringe rule of the internet.
In addition to the third-party installation capability mentioned by siblings, Japan also has a regional capability for reassigning the side button to a third-party voice assistant (`com.apple.developer.side-button-access.allow`).
This is a strong indicator that Apple's privacy claims are little more than a virtue signal. Network sandboxing an app is arguably the strongest privacy protection measure possible.
Xiaomi phones support it in all regions. Think about it, a company famous for putting ads in system apps has the feature but "privacy conscious" Apple literally put in extra work to disable it everywhere it's not legally required.
That iOS toggle isn’t about privacy but about mobile data usage. Users with data caps can limit the usage for non-essential or high data volume apps (streaming or cloud storage apps come to mind).
Companies have never been “democracies”. Most companies are more like dictatorships internally (for employees) and past a certain size also externally (for customers). Everything is dictated by a small group of leaders and shareholders not chosen by either employees or customers.
If you really want to imagine them like democracies, you are voting with your wallet. Maybe you’re just in the minority.
Nobody said companies _are_ democracies ... you're reading something that is not there.
The point is that Apple thinks it can somehow bend the rules of the EU that were established democratically. As if users are better off with Apple's rules.
The iOS Simulator consists of (some of) the userspace components of iOS compiled to run on macOS. This would be a full iPhone image running as-is via virtualization.
It’s been years but I ran into a problem with a notification extension years ago. Worked fine on simulator, not on device. Turned out it was because I was using a HEIF image and (I think) the on-device extension was trying to use hardware decoding and didn’t have access to it. Meanwhile the simulator had no such sandboxing restrictions.
The difference doesn’t matter until it does, and then it’s infuriating to work out what’s going on.
It would also make testing far easier. I got bit with something that failed on real life iPhones with language set to es_US that worked fine on the simulator.
The simulator doesn't have a camera. The android emulator allows to configure the camera and use a picture, it's very handy to test your qr/barcode reader without needing to use a physical device. Maybe this also allows to use an image as camera?
Incorrect. The iOS simulator is and always has been, simply iOS frameworks running fully natively on
macOS. It’s best to think of it as an alternative window managers but the apps are native Mac processes. They can be seen and debugged via the terminal using top and ps and lldb alongside all other processes. They just present gui via the Simulator Mac app container.
They do not live in a VM and are certainly not emulated at an instruction set level. They are Mac apps.
I would think that "Mac apps," means that they are, actually, a different OS (I actually already knew that, which was why I said what I said. The Intel thing was a spitball).
But one of the few joys geeks get, these days, is telling other geeks they are wrong, so I feel as if I’ve done my bit to make this a happier place.
The simulator is a different SDK target than iOS itself.
You have to compile completely independently for it, and depending on your dependencies they may not compile for the simulator.
Additionally the simulator runs a really ancient and feature restricted version of Metal. That means you can’t test a lot of graphical things that the hardware actually supports. I’m not sure if this supports GPU passthrough but the macOS VMs do, so that alone would be a huge improvement if possible.
If you’re talking about the simulator, no. That doesn’t virtualize - it literally just runs it locally on your machine. Less RAM overhead and CPU since it uses your normal instruction set and doesn’t run a separate kernel and userspace.
At least historically, it actually did run its own entire userspace, including daemons (all the way to launchd, IIRC), etc. All compiled for Intel, back in the day. Shared the kernel though.
Many of the nominally shared system pieces between Mac and iPhone (like Foundation) actually had many subtle compile-time differences.
What a release! Congrats to the builder, lots of great work done here and in IOS profiling in general has been done here recently. Corellium went research only and I lost the ability to actually profile my applications the way I'd like. I've got a fun thing over coffee in the morning!
This is virtualization, so localhost will just be the virtual iphone itself. But you should have some command of how hosts are resolved, so you can always point the browser to the device hosting what you want to test, no?
Even easier, of course, is just using the iOS simulator included with xcode, which runs on your host computer. There, localhost resolves to your host computer.
Private cloud compute I think. I learnt about it today too from this reddit post which mentions how:
> At WWDC, Apple announced that starting in the 27.x versions of iOS, macOS, etc., devs would be able to call Private Cloud Compute directly from Swift with no additional API configuration. Presently, the only way to get free cloud inference is by joining the App Store Small Business Program.
Note that, unlike Corellium, this isn't about emulating an iPhone. Apple is providing an iOS kernel for Virtualization.framework in PCC/cloudOS images and this project pairs it with the iOS user-space and patches to make everything run. Applications can very easily tell it apart from the real thing.
More details here: https://github.com/wh1te4ever/super-tart-vphone-writeup
> during iOS setup, don't pick Japan or the EU as your region (extra regulatory checks the VM can't satisfy)
I'm curious what are these checks
For Japan it might be the Felica chip.
That would surprise me. I don't recall having to change my iPhone's region after moving to Japan. Transport IC cards in Apple Pay have "just worked".
I am vaguely aware that some phone manufacturers silently remove certain NFC hardware (or disable some driver) in order to avoid paying Sony patent fees. Apple doesn't seem to do that, though.
There were iPhones with Japan-specific hardware for transit cards in the past but as of a couple years ago, all iPhones have been compatible.
Only iPhone 7 had that limitation. 8 and later don't, and that was since like a decade ago.
It will be to prevent access to third-party app stores as both the EU and Japan legislated they must be allowed.
> In a support document about alternative app marketplaces in the EU, Apple explained that “device eligibility for alternative app marketplaces is determined using on-device processing with only an indicator of eligibility sent to Apple.” In practice, iOS users in the EU who want to install alternative marketplaces will need to set the country or region of their Apple ID to an eligible country or region. Moreover, they will also need to be physically located in supported EU countries.
> In the case iOS users in the EU leave eligible regions, Apple will offer a “grace period” until apps downloaded from alternative app stores can no longer be updated. “If you’re gone for too long, you’ll lose access to some features, including installing new alternative app marketplaces. Apps you installed from alternative app marketplaces will continue to function, but they can’t be updated by the marketplace you downloaded it from,” the company explained.
https://www.thurrott.com/apple/298862/apple-adds-some-condit...
Wait so a third party app-store is allowed in the EU? I was not aware these even existed...
Since 2024: https://www.macstories.net/news/altstore-is-now-available-in...
https://altstore.io
Any working way to spoof your locale to trick this into any form of usability?
I have never tried. I'm sure there are some reddit threads about this though.
You need to fake the cell towers and change your accounts billing address. It's not trivial.
changing account billing is easy, but how to simulate fake cell tower, is there no tools in amazon?
It is wild that Apple finds it cheaper to build and maintain different App store behaviors than to simplify and make alt app stores available in all markets. Other governments/markets don't care?
"Other governments/markets don't care?"
its the least of their problems
There's an endless supply of bodies of water to be renamed.
It's a very slow process, first there is investigations, then legislation, then enactment, then enforcement which is separately a very slow process. It requires a lot of willpower to get and keep the ball rolling and in fact nobody has even achieved the full extent of what they require yet! The EU may still be years away from meaningful compliance, Japan has only taken baby steps forming a new bureau just to enforce compliance of two companies widely accused of malicious compliance.
And then there is additional discouragement and pressure in the form of sanction and trade deal threats for regulating American tech platforms.
> And then there is additional discouragement and pressure in the form of sanction and trade deal threats for regulating American tech platforms.
What people don't realise is that local companies aren't just competing with each other, they're competing against the US military.
Who said it's cheaper?
It's vastly more profitable to maintain their monopoly on iOS apps and the 30% cut than to allow users to stop paying apple a cut of their transactions.
It’s like a cookie banner. Absolutely useless initiative.
As someone using AltStore PAL to install some third-party apps that would never be allowed on the App Store (such as emulators and manga readers), I heavily disagree.
Everything that didn’t turn out exactly like some people wanted is useless or the Worst Thing Ever — which is a boring and cringe rule of the internet.
Apple is required to have a process to approve them. Apple has not approved any. Apple is not required to approve any.
> Apple has not approved any...
They've approved - at the very least - AltStore, Epic Games Store, Aptoide, Onside, and Setapp Mobile.
In addition to the third-party installation capability mentioned by siblings, Japan also has a regional capability for reassigning the side button to a third-party voice assistant (`com.apple.developer.side-button-access.allow`).
I also found out the Chinese version has the ability to block an app for accessing both mobile data and Wifi/WLAN data.
All other versions only allow denying mobile data to an app, not Wifi.
I really wish there was a way to enable this feature.
This is a strong indicator that Apple's privacy claims are little more than a virtue signal. Network sandboxing an app is arguably the strongest privacy protection measure possible.
Xiaomi phones support it in all regions. Think about it, a company famous for putting ads in system apps has the feature but "privacy conscious" Apple literally put in extra work to disable it everywhere it's not legally required.
That iOS toggle isn’t about privacy but about mobile data usage. Users with data caps can limit the usage for non-essential or high data volume apps (streaming or cloud storage apps come to mind).
I think the point is that the code path to deny network access for arbitrary apps exists (at least according to this comment):
> I also found out the Chinese version has the ability to block an app for accessing both mobile data and Wifi/WLAN data.
Yet Apple is choosing not to enable it for everyone. It seems like it would be an easy and obvious privacy win, no?
I'm tired of Apple and its stupid rules, and its arrogant assumption that it is better than a democracy.
Companies have never been “democracies”. Most companies are more like dictatorships internally (for employees) and past a certain size also externally (for customers). Everything is dictated by a small group of leaders and shareholders not chosen by either employees or customers.
If you really want to imagine them like democracies, you are voting with your wallet. Maybe you’re just in the minority.
Nobody said companies _are_ democracies ... you're reading something that is not there.
The point is that Apple thinks it can somehow bend the rules of the EU that were established democratically. As if users are better off with Apple's rules.
This seams neat, but I'm not sure I understand the purpose/difference between this and using the iOS simulator.
The iOS Simulator consists of (some of) the userspace components of iOS compiled to run on macOS. This would be a full iPhone image running as-is via virtualization.
That explains the difference, but what's the purpose?
You can test your application, game, website without a physical phone?
Can do that with the simulator too
Running on ported userspace components, with a shim, isn't the same as running on the OS in itself.
That really matters, sometimes.
But not the vast majority of the time.
(source: been coding iOS since pre-SDK iPhone OS 1.0)
Can you give some examples of where it matters? I'm genuinely curious.
Last I checked, VPN network extensions wouldn't run in the simulator.
It’s been years but I ran into a problem with a notification extension years ago. Worked fine on simulator, not on device. Turned out it was because I was using a HEIF image and (I think) the on-device extension was trying to use hardware decoding and didn’t have access to it. Meanwhile the simulator had no such sandboxing restrictions.
The difference doesn’t matter until it does, and then it’s infuriating to work out what’s going on.
> The difference doesn’t matter until it does, and then it’s infuriating to work out what’s going on.
I love this quote, reminds me how annoying it can be when something isn’t reproducible locally… only in production…
Testing AR apps, or any app that relies on hardware you can't simulate easily.
https://www.youtube.com/watch?v=T43b5ywnYpo
Is the simulator faster than this? I would suspect so.
I have had instances where the app runs fine on the simulator but crashes on the device. This might solve that.
If functional, you can download apps from the App Store, sign in to iCloud.. probably do a bunch of agentic stuff as if you had a real device
Looks like apple services compatibility is not currently supported for this [0]
[0] https://github.com/Lakr233/vphone-cli/discussions/175
Exactly. It means it cannot download apps from the App Store or use Apple services and Apple knows this deliberate limitation.
If you read a bit further, there's a jailbroken variant that has Sileo and Trollstore installed, so you can run whatever IPAs
Where?
Edit: ah now I see, in the main readme under heading Firmware Variants. https://github.com/Lakr233/vphone-cli#firmware-variants
Spam. Click farms. Etc.
It would also make testing far easier. I got bit with something that failed on real life iPhones with language set to es_US that worked fine on the simulator.
oh. is this why icloud spam texts are running wild now
No, it’s just trivial to generate iCloud email addresses that won’t get picked up by spam filter.
The simulator doesn't have a camera. The android emulator allows to configure the camera and use a picture, it's very handy to test your qr/barcode reader without needing to use a physical device. Maybe this also allows to use an image as camera?
You cannot run Network Extensions on the simulator
It's useful for security research since you can do kernel debugging and inspection of the device not possible in the simulator.
As others pointed out it's also useful for e.g. click/spam farms which need a "real" iPhone.
The simulator is a completely different OS. It may even still be using Intel.
I always figured that Apple never set up a true emulator (like what Android does), because they didn't want people exploring their OS with a debugger.
Incorrect. The iOS simulator is and always has been, simply iOS frameworks running fully natively on macOS. It’s best to think of it as an alternative window managers but the apps are native Mac processes. They can be seen and debugged via the terminal using top and ps and lldb alongside all other processes. They just present gui via the Simulator Mac app container.
They do not live in a VM and are certainly not emulated at an instruction set level. They are Mac apps.
Ah. That makes sense.
I would think that "Mac apps," means that they are, actually, a different OS (I actually already knew that, which was why I said what I said. The Intel thing was a spitball).
But one of the few joys geeks get, these days, is telling other geeks they are wrong, so I feel as if I’ve done my bit to make this a happier place.
Looks like this tool can provide a jailbroken environment for the latest iOS versions whereas one does not exist on iOS simulator or a real device
Here are some reasons to use this instead of the simulator: security research, testing, automation
The simulator is a different SDK target than iOS itself.
You have to compile completely independently for it, and depending on your dependencies they may not compile for the simulator.
Additionally the simulator runs a really ancient and feature restricted version of Metal. That means you can’t test a lot of graphical things that the hardware actually supports. I’m not sure if this supports GPU passthrough but the macOS VMs do, so that alone would be a huge improvement if possible.
Fantastic project, I use it regularly to test apps and there is a vphone-mcp which allows agents to control it, take screenshots and navigate the UI!
I better not get more spam iMessages!!
Is this what apple does in xcode?
If you’re talking about the simulator, no. That doesn’t virtualize - it literally just runs it locally on your machine. Less RAM overhead and CPU since it uses your normal instruction set and doesn’t run a separate kernel and userspace.
At least historically, it actually did run its own entire userspace, including daemons (all the way to launchd, IIRC), etc. All compiled for Intel, back in the day. Shared the kernel though.
Many of the nominally shared system pieces between Mac and iPhone (like Foundation) actually had many subtle compile-time differences.
so can this receive web push notifications?
Is this safe?
There are some binaries in scripts/resources that you need to run as root. No idea what's inside them.
Can Appium be used to control this?
What a release! Congrats to the builder, lots of great work done here and in IOS profiling in general has been done here recently. Corellium went research only and I lost the ability to actually profile my applications the way I'd like. I've got a fun thing over coffee in the morning!
Feels weird that after their attempts to shut down corellium they themselves shipped the necessary bits to allow this
https://github.com/wh1te4ever/super-tart-vphone-writeup
Will this project make it easier to performance test Apps on the virtual iPhone?
Ya totally, it's real hardware.... I mean, the PCC machines are actually m5's but ya.
I don't really think it is a super accurate performance simulator
Does this include a virtual baseband?
No, only virtual GarageBand
You have my angry upvote.
GarageBand is an excellent app.
This project is really cool its a shame you have to disable or partial disable SIP which can break some things.
Yeah real shame that I know I could never run this on a corporate machine and only ever as a hobbyist.
That means you're working for the wrong companies ;-)
Have corporate buy you a research Air that isn’t on the MDM.
If corporate wants they can still accept/trust a machine with partially disabled SIP on the MDM
Interesting project. If it actually works it opens up a ton of possibilities for testing and reverse engineering.
Will there ever be a day where I could run this on a PC or something like it?
Probably not, but you can run it on a Mac today.
Can this be used to test the phone's browser on localhost?
This is virtualization, so localhost will just be the virtual iphone itself. But you should have some command of how hosts are resolved, so you can always point the browser to the device hosting what you want to test, no?
Even easier, of course, is just using the iOS simulator included with xcode, which runs on your host computer. There, localhost resolves to your host computer.
Will Apple break this?
They will find a way to break it.
That's how all your cat-and-mouse games eventually end.
what is "PCC"?
Private cloud compute I think. I learnt about it today too from this reddit post which mentions how:
> At WWDC, Apple announced that starting in the 27.x versions of iOS, macOS, etc., devs would be able to call Private Cloud Compute directly from Swift with no additional API configuration. Presently, the only way to get free cloud inference is by joining the App Store Small Business Program.
https://www.reddit.com/r/appledevelopers/comments/1vztibh/re...
Can this be used for account recovery?
this is potentially useful for me do you know if this can fully handle callkit?