Skip to content

Banking apps Jailbreak detection #355

@honestyan

Description

@honestyan

Device Model

iPhone 13 Mini, A15 Bionic

iOS Version

16.6

Bootstrap Version

2.2

Appstore Link

https://apps.apple.com/id/app/permata-me/id1323973644

Packages Update

Yes

Kernel Exploit

Yes

Blacklist in RootHide Manager

Yes

varClean in RootHide Manager

Yes

RootHide Manager Warnings

No warning

More info

Bug: Jailbreak detection still triggered and apps force close despite RootHide mitigation

Summary

Several Indonesian banking/finance apps are still detecting jailbreak/root-related traces and force closing immediately after launch. This happens even after applying multiple RootHide-related cleanup and tweak-isolation steps.

Affected Apps

  1. Permata ME
    App Store: https://apps.apple.com/id/app/permata-me/id1323973644

  2. Jenius
    App Store: https://apps.apple.com/id/app/jenius/id1079340119

  3. Superbank
    App Store: https://apps.apple.com/id/app/superbank-save-borrow-grow/id6444720285

  4. Bibit
    App Store: https://apps.apple.com/id/app/bibit-reksadana-obligasi/id1445856964

Steps to Reproduce

Jenius

  1. Open the Jenius app.
  2. Proceed through the onboarding screens.
  3. Tap Next until the onboarding flow is finished.
  4. The app detects jailbreak/root-related traces and force closes.

Permata ME, Superbank, and Bibit

  1. Open the app.
  2. Immediately after launch, a jailbreak detection warning appears.
  3. The app force closes.

Expected Behavior

The apps should open normally when RootHide and related hiding/cleanup steps are enabled.

Actual Behavior

The apps still detect jailbreak/root-related traces.

  • Jenius: Detection happens after completing onboarding screens.
  • Permata ME, Superbank, Bibit: Detection happens immediately after opening the app.
  • The apps either show a jailbreak detection popup, force close, or both.

Troubleshooting Already Tried

I already tried the following, but the apps are still detected:

  • Using Darksword kernel
  • Adding the apps to RootHide blacklist
  • Running RootHide full varClean
  • Running RootHide clear data for each affected app
  • Uninstalling and reinstalling each app
  • Using Choicy to disable tweak injection for the apps

Result

None of the above steps resolved the issue. The apps continue to detect the environment and force close.

Log output

Acknowledgement of README and FAQ

  • I have read both the README and the FAQ.

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions