# vphone‑cli Firmware Variants Explained: All 5 Options for iOS Virtualization

> Explore the 5 vphone-cli firmware variants less regular dev jb and exp for iOS virtualization. Understand boot chain patches and custom firmware installation easily.

- Repository: [Lakr/vphone-cli](https://github.com/Lakr233/vphone-cli)
- Tags: deep-dive
- Published: 2026-09-06

---

**vphone‑cli supports five firmware variants—`less`, `regular`, `dev`, `jb`, and `exp`—that control boot‑chain patches and custom firmware installation phases via the `--variant` or `-V` flag.**

Choosing the right firmware variant is essential when creating iOS virtual machines with vphone‑cli. Each variant applies a specific number of binary patches to the boot chain and runs a corresponding number of custom firmware (CFW) installation phases, ranging from minimal security‑preserving configurations to full jailbreak environments with research‑grade anti‑detection patches.

## What Are vphone‑cli Firmware Variants?

Firmware variants in vphone‑cli are predefined patch profiles that determine how aggressively the tool modifies the original iOS firmware. The variant system lives in the repository's `scripts/` directory and is documented in [`README.md#L90‑L99`](https://github.com/Lakr233/vphone-cli/blob/main/README.md#L90-L99).

When you specify a variant, vphone‑cli:

1. Selects the appropriate patch set from `scripts/patchers/`
2. Applies boot‑chain patches during the `fw patch` step
3. Executes the matching CFW install phases via `scripts/cfw_install_*.sh`

## Complete List of vphone‑cli Firmware Variants

| Variant | Boot‑Chain Patches | CFW Phases | Purpose |
|---------|-------------------|------------|---------|
| `less` | 4 patches | 2 phases | **Patch‑less** — preserves all original iOS security mitigations |
| `regular` | 42 patches | 10 phases | Bypasses AMFI, SSV, Img4, and TXM restrictions |
| `dev` | 53 patches | 12 phases | Adds TXM entitlement and debug‑mode bypass |
| `jb` | 113 patches | 14 phases | Full jailbreak with Sileo and TrollStore installation |
| `exp` | 141 patches | 18 phases | Experimental research patches that defeat VM‑detection |

The patch counts and phase mappings originate from [[`research/0_binary_patch_comparison.md`](https://github.com/Lakr233/vphone-cli/blob/main/research/0_binary_patch_comparison.md)](https://github.com/Lakr233/vphone-cli/blob/main/research/0_binary_patch_comparison.md), which provides a component‑by‑component breakdown of what each variant modifies.

## How to Select a Firmware Variant

Use the `--variant` or `-V` flag with `vm create` to choose your firmware variant at VM creation time:

```bash

# Minimal patches, maximum security (recommended for testing)

vphone-cli vm create myphone -V less

# Standard development environment

vphone-cli vm create myphone -V regular

# Full jailbreak with package manager

vphone-cli vm create myphone -V jb

# Experimental anti‑VM research configuration

vphone-cli vm create myphone -V exp

```

The variant selection propagates through the entire VM lifecycle. The `VPhoneVirtualMachine` Swift implementation passes this value to subsequent commands.

## Manual Firmware Patching by Variant

You can also apply variants directly during the firmware patch step using `vphone-cli fw patch`:

```bash

# Apply development variant patches manually

vphone-cli fw patch myphone --variant dev

```

This command invokes the patcher scripts in `scripts/patchers/` with the specified variant profile. The implementation details reside in [[`scripts/fw_patch.sh`](https://github.com/Lakr233/vphone-cli/blob/main/scripts/fw_patch.sh)](https://github.com/Lakr233/vphone-cli/blob/main/scripts/fw_patch.sh).

## Custom Firmware Installation Phases

After patching, the CFW installer runs variant‑specific phases. Each variant has a dedicated install script that executes the correct number of phases:

```bash

# Install CFW for the regular variant (10 phases)

vphone-cli cfw install myphone --variant regular

```

The jailbreak variant uses [[`scripts/cfw_install_jb.sh`](https://github.com/Lakr233/vphone-cli/blob/main/scripts/cfw_install_jb.sh)](https://github.com/Lakr233/vphone-cli/blob/main/scripts/cfw_install_jb.sh), which handles all 14 installation phases including Sileo and TrollStore setup on first boot.

## Choosing the Right Variant

**`less`** — Use when you need authentic iOS behavior with security mitigations intact. Only 4 patches applied.

**`regular`** — Balance between functionality and modification. Bypasses core signature checks with 42 patches.

**`dev`** — Extended debugging capabilities. The 53 patches include TXM entitlement bypass for advanced development.

**`jb`** — Full jailbreak environment. 113 patches install complete userland modifications with package management.

**`exp`** — Research and anti‑detection work. 141 patches include experimental modifications that interfere with VM detection mechanisms.

## Summary

- vphone‑cli provides **five firmware variants**: `less`, `regular`, `dev`, `jb`, and `exp`
- Variants control **boot‑chain patch count** (4 to 141 patches) and **CFW installation phases** (2 to 18 phases)
- Select variants with **`--variant`** or **`-V`** in `vm create`, `fw patch`, and `cfw install` commands
- Variant definitions live in **[`README.md`](https://github.com/Lakr233/vphone-cli/blob/main/README.md)**, patch details in **[`research/0_binary_patch_comparison.md`](https://github.com/Lakr233/vphone-cli/blob/main/research/0_binary_patch_comparison.md)**, and install logic in **`scripts/cfw_install_*.sh`**

## Frequently Asked Questions

### How do I check which firmware variant my VM is using?

vphone‑cli stores the variant selection in the VM configuration. Check the original creation command or re‑run `vphone-cli vm create` with the `-V` flag to verify. The variant propagates automatically through `fw patch` and `cfw install` operations.

### Can I change the firmware variant after VM creation?

No—variants must be selected at creation time. The boot‑chain patches are applied during initial firmware processing, and CFW phases run during first boot. To use a different variant, create a new VM with `vphone-cli vm create` specifying your preferred `-V` option.

### What is the difference between `jb` and `exp` variants?

The `jb` variant applies 113 patches for a standard jailbreak with Sileo and TrollStore. The `exp` variant adds 28 additional research patches (141 total) targeting VM‑detection mechanisms. Use `exp` only for specific anti‑detection research, as these patches may cause instability.

### Which variant preserves original iOS security?

The `less` variant applies only 4 patches across 2 CFW phases, retaining all original AMFI, SSV, Img4, and TXM security mitigations. This is the closest to stock iOS behavior available in vphone‑cli.