A sophisticated new attack tool targeting jailbroken iOS devices has emerged, representing a significant escalation in digital identity fraud capabilities.
The discovery by the iProov threat team reveals a highly specialized tool designed to perform advanced video injection attacks on iOS 15 and later devices, specifically crafted to bypass weak biometric verification systems and exploit identity verification processes that lack appropriate biometric safeguards.
See also: iOS 26 notifies when AirPods case runs out of battery

This discovery represents a worrying shift towards more programmatic and scalable attack approaches, with the tool’s suspected Chinese origins adding geopolitical significance amid growing concerns about technical dominance and digital supply chain security. The tool’s emergence highlights the critical need for robust biometric verification systems capable of detecting sophisticated deepfake and import attacks.
The newly discovered tool works through a multi-layered process that exploits the compromised security architecture of jailbroken iOS devices. The attack begins with a jailbroken device running iOS 15 or later, where Apple’s inherent security restrictions have been removed to allow deep system modifications. Attackers establish a connection using a Remote Presentation Transfer Mechanism (RPTM) server, creating a bridge between their computer and the compromised iOS device.
See also: iOS 26: New automation features in Apple Home

The core of the attack involves inserting sophisticated deepfakes directly into the device’s video stream, bypassing the physical camera hardware entirely. Deepfakes can take the form of face swapping, where a victim’s face is superimposed onto another video, or motion reenactment, where still images are animated using the actions of another person. The inserted synthetic media trick apps into believing that the fraudulent video represents a live, real-time stream, potentially allowing for the impersonation of legitimate users or the creation of synthetic identities.
The emergence of video intrusion attacks renders traditional identity verification methods inadequate, requiring comprehensive, multi-layered defense approaches. Organizations must implement verification systems that simultaneously confirm the right person through identity matching with official documents and databases, verify a real person using built-in image and metadata analysis to detect malicious media, and ensure real-time authentication through unique passive challenge-response interactions, preventing replay attacks.
The discovery of the tool coincides with alarming trends documented in iProov’s 2025 Threat Report , including a 2,665% increase in native virtual camera attacks and a 300% increase in deepfake face-swapping attacks. With security experts tracking over 120 different face-swapping tools, malicious actors are rapidly adopting new technologies to bypass verification systems, making robust liveness detection capabilities essential to organizational security.
See also: Apple fixes vulnerability (backports) on old devices

This layered approach increases the complexity for attackers seeking to tamper with identity verification systems, as advanced attacks find it difficult to bypass all security measures while maintaining the physical characteristics of real human contact.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
