IOS 5 HFS Heap Buffer Overflow

An exploit is available in iOS 5's iBoot that abuses a heap buffer overflow bug. The exploit was discovered by p0sixninja.

The exploit has been shown to be able to untethered verbose boot the original iPad.

Support for untethered downgrades on the iPod touch (3rd generation) via this exploit was planned in powdersn0w, and eventually accomplished in Legacy iOS Kit after the discontinuation of powdersn0w.

The exploit should also be available in iOS 4 or earlier. It was patched in iOS 6.

= See also =
 * De Rebus Antiquis, another iBoot exploit with similar uses

= External links =
 * Source code
 * Guide to exploitation
 * Jonathan Seals’ tools for exploitation
 * Ralph0045’s tools for exploitation