# How Dopamine Jailbreak PAC Bypass Works on arm64e Devices: A Technical Deep Dive

> Dopamine jailbreak uses XPACI instruction for PAC bypass on arm64e devices. Learn how this multi-stage exploit enables stable kernel call primitives in our technical deep dive.

- Repository: [Lars Fröder/Dopamine](https://github.com/opa334/Dopamine)
- Tags: deep-dive
- Published: 2026-08-12

---

**Dopamine uses a multi-stage PAC bypass exploit that strips Pointer Authentication Codes from kernel pointers using the XPACI instruction, enabling stable kernel call primitives on arm64e devices.**

The Dopamine jailbreak implements a sophisticated **PAC (Pointer Authentication Code) bypass** designed specifically for arm64e Apple devices. This exploit runs as a prerequisite before any other jailbreak primitives, clearing the cryptographic signatures that protect kernel pointers on modern iPhones and iPads. Understanding these techniques requires examining how Dopamine detects arm64e hardware, selects appropriate exploits, and leverages low-level CPU instructions to disable PAC enforcement.

## Detecting arm64e Devices in Dopamine

Before attempting any bypass, Dopamine must confirm the target device uses arm64e architecture. This detection occurs in `Application/Dopamine/Exploits/DarkSword/DarkSword.m`.

```objc
// Lines 46-48 in DarkSword.m
cpu_subtype_t cpusubtype;
size_t len = sizeof(cpusubtype);
sysctlbyname("hw.cpusubtype", &cpusubtype, &len, NULL, 0);
isArm64e = (cpusubtype == CPU_SUBTYPE_ARM64E);

```

The `isArm64e` boolean flag determines whether PAC bypassing is necessary. Non-arm64e devices skip all PAC-related operations entirely.

## Selecting and Loading the PAC Bypass Exploit

Dopamine's exploit selection architecture treats PAC bypass as a specialized exploit category with type `EXPLOIT_TYPE_PAC`.

### UI-Based Exploit Selection

The settings controller (`DOSettingsController.m`) filters and presents only PAC-compatible exploits when running on arm64e hardware. Users select their preferred bypass, which `DOJailbreaker.m` retrieves via `DOExploitManager.sharedManager.selectedPACBypass`.

From `Application/Dopamine/Jailbreak/DOJailbreaker.m` (lines 176-183):

```objc
DOExploit *pacBypass = [DOExploitManager sharedManager].selectedPACBypass;
if (!pacBypass && [DOEnvironmentManager sharedManager].isPACBypassRequired) {
    return [NSError errorWithDomain:JBErrorDomain
                               code:JBErrorCodeFailedExploitation
                           userInfo:@{NSLocalizedDescriptionKey:
                 @"PAC bypass is required but we did not find any"}];
}

```

### Exploit Execution Flow

The jailbreak core loads and executes the selected PAC bypass through a standardized interface:

```objc
if (pacBypass) {
    [[DOUIManager sharedInstance] sendLog:
        [NSString stringWithFormat:DOLocalizedString(@"Bypassing PAC (%@)"),
                                   pacBypass.name] debug:NO];
    
    if ([pacBypass load] != 0) { /* handle load failure */ }
    if ([pacBypass run] != 0)  { /* handle run failure */ }
    
    // Critical: mark system as having active PAC bypass
    gSystemInfo.jailbreakInfo.usesPACBypass = true;
}

```

This flag (`usesPACBypass = true`) gates all subsequent operations that depend on unsigned kernel pointers.

## The XPACI Instruction: Core PAC Stripping Mechanism

Dopamine's low-level PAC removal relies on the **XPACI** (eXtract PAC from Instruction address) ARM64 instruction. This instruction is implemented as naked assembly in `DarkSword.m` (lines 100-108):

```c
static uint64_t __attribute((naked)) __xpaci(uint64_t a)
{
    asm(".long 0xDAC143E0");   // XPACI X0 – clears PAC bits from pointer
    asm("ret");
}

uint64_t unpac_ptr(uint64_t kptr)
{
    if (!isArm64e) return kptr;      // Skip on non-arm64e devices
    return __xpaci(kptr);            // Strip PAC using CPU instruction
}

```

**Key technical details:**
- The `0xDAC143E0` opcode encodes `XPACI X0`, which zeroes the upper PAC bits while preserving the canonical address
- The `__attribute((naked))` prevents compiler prologue/epilogue generation
- All kernel pointer dereferencing flows through `unpac_ptr()` on arm64e

## Enabling Stable Kernel Call Primitives

With PAC bypass active, Dopamine's **kcall** primitives become operational. The `libjailbreak` core checks this state before attempting kernel calls.

From [`BaseBin/libjailbreak/src/main.c`](https://github.com/opa334/Dopamine/blob/main/BaseBin/libjailbreak/src/main.c) (lines 33-34):

```c
// primitives.c and kcall operations check this flag
if (jbinfo(usesPACBypass)) {
    // Enable full kernel read/write via stable kcall primitives
}

```

The [`primitives.h`](https://github.com/opa334/Dopamine/blob/main/primitives.h) header defines supporting macros:

```c
#define PAC_MASK    0xFFFFFF8000000000ULL  // PAC bit mask for arm64e
#define UNSIGN_PTR(ptr)  (jbinfo(usesPACBypass) ? unpac_ptr(ptr) : (ptr))

```

## Key Source Files in Dopamine's PAC Bypass Implementation

| File | Function |
|------|----------|
| `Application/Dopamine/Jailbreak/DOJailbreaker.m` | Orchestrates exploit loading and execution; sets `usesPACBypass` flag |
| `Application/Dopamine/Jailbreak/DOSettingsController.m` | UI for selecting among `EXPLOIT_TYPE_PAC` exploits |
| `Application/Dopamine/Exploits/DarkSword/DarkSword.m` | Implements `__xpaci()` and `unpac_ptr()` with naked assembly |
| [`BaseBin/libjailbreak/src/primitives.h`](https://github.com/opa334/Dopamine/blob/main/BaseBin/libjailbreak/src/primitives.h) | Defines `PAC_MASK` and `UNSIGN_PTR` macros |
| [`BaseBin/libjailbreak/src/main.c`](https://github.com/opa334/Dopamine/blob/main/BaseBin/libjailbreak/src/main.c) | Checks `jbinfo(usesPACBypass)` for primitive stability |
| `Application/Dopamine/Exploits/*` | Concrete PAC bypass payloads (platform-specific) |

## Summary

Dopamine's **arm64e PAC bypass** operates through five coordinated stages:

- **Architecture detection** via `hw.cpusubtype` sysctl in `DarkSword.m`
- **Exploit selection** filtered by `EXPLOIT_TYPE_PAC` category
- **Runtime execution** through standardized `load`/`run` exploit interface
- **Pointer un-signing** using the `XPACI` instruction in naked assembly
- **Primitive stabilization** enabling kernel calls via `usesPACBypass` flag

This architecture allows Dopamine to support multiple PAC bypass implementations while maintaining a consistent internal API for kernel operations.

## Frequently Asked Questions

### What is PAC and why does Dopamine need to bypass it?

Pointer Authentication Code is a hardware security feature in arm64e Apple CPUs that cryptographically signs pointers to prevent code-reuse attacks. Dopamine must strip these signatures to read and write kernel memory, as signed pointers would fault when dereferenced in unauthorized contexts. The bypass achieves this without disabling PAC system-wide, only removing signatures from specific kernel pointers the jailbreak controls.

### How does the XPACI instruction work at the hardware level?

XPACI (eXtract PAC from Instruction address) is an ARMv8.3-A instruction that zeroes the Pointer Authentication Code bits embedded in the upper address bits of a 64-bit pointer. The `0xDAC143E0` encoding targets the X0 register. Unlike `AUTIA` (authenticate), XPACI unconditionally clears PAC bits without verification, making it ideal for jailbreak scenarios where the correct PAC key is unknown.

### Can Dopamine jailbreak arm64e devices without a PAC bypass?

No. According to the source code in `DOJailbreaker.m`, if `isPACBypassRequired` returns true and no `selectedPACBypass` exploit is available, the jailbreak aborts with `JBErrorCodeFailedExploitation`. The PAC bypass is mandatory for kernel read/write primitives on arm64e; non-arm64e devices (older iPhones) bypass this requirement entirely.

### What PAC bypass exploits does Dopamine support?

Dopamine's architecture accepts any exploit advertising `EXPLOIT_TYPE_PAC` through its plugin system. The repository includes reference implementations such as DarkSword, with historical support for Fugu15-derived and C3-based PAC bypasses. Specific available exploits depend on the iOS version and device generation being targeted.