A sandbox escape vulnerability affects iPhones and iPads running iOS 26.0.1 or earlier. The proof-of-concept (POC) exploits weaknesses in the itunesstored and bookassetd, allowing attackers to modify sensitive files in areas of the device's data partitions that are typically protected from unauthorized access.
See also: Fortinet FortiWeb: Exploit released for critical vulnerability

Researcher Kim shared the details in a blog post on October 20, 2025, emphasizing that the findings came from her reverse engineering efforts and urging readers to verify independently.
The vulnerability relies on a maliciously crafted database “downloads.28.sqlitedb”, which tricks the itunesstored daemon into downloading and placing a secondary database, “BLDatabaseManager.sqlite”, in a shared system group container.
While itunesstored operates under strict sandbox boundaries, the next stage leverages bookassetd, a daemon that handles iBooks downloads with broader permissions.
This allows writes to mobile-owned paths such as /private/var/mobile/Library/FairPlay/, /private/var/mobile/Media/, and even to system caches such as /private/var/containers/Shared/SystemGroup/systemgroup.com.apple.mobilegestaltcache/Library/Caches/com.apple.MobileGestalt.plist.
See also: Pwn2Own Ireland 2025 – Day 2: 56 zero-day exploits & $792,750 in prizes

In a demonstration on an iPhone 12 running iOS 16.0.1, Kim modified the MobileGestalt cache to spoof the device as an iPod touch (iPod model 9.1), demonstrating the scope of the exploit.
The process requires preparing the target file in modified EPUB format, the compressed uncompressed format of the mimet file type, and hosting supporting elements such as iTunesMetadata.plist on a server.
Attackers must then use tools like 3uTools or afcclient to import the databases into /var/mobile/Media/Downloads/, followed by targeted reboots to trigger the downloads.
The expected behavior stops writes to unauthorized paths, but the flaw allows modifications unless the destination is controlled by root.
See also: Pwn2Own Ireland 2025 – Day 1: 34 zero-day exploits and $522,500 in prizes

Apple has yet to comment, and Kim notes that the issue is likely to be fixed soon. He provides key files on GitHub for educational use, emphasizing that the research is intended for learning purposes only and not for illegal activities.
