How Dopamine Jailbreak PAC Bypass Works on arm64e Devices: A Technical Deep Dive

Dopamine uses a multi-stage PAC bypass exploit that strips Pointer Authentication Codes from kernel pointers using the XPACI instruction, enabling stable kernel call primitives on arm64e devices.

The Dopamine jailbreak implements a sophisticated PAC (Pointer Authentication Code) bypass designed specifically for arm64e Apple devices. This exploit runs as a prerequisite before any other jailbreak primitives, clearing the cryptographic signatures that protect kernel pointers on modern iPhones and iPads. Understanding these techniques requires examining how Dopamine detects arm64e hardware, selects appropriate exploits, and leverages low-level CPU instructions to disable PAC enforcement.

Detecting arm64e Devices in Dopamine

Before attempting any bypass, Dopamine must confirm the target device uses arm64e architecture. This detection occurs in Application/Dopamine/Exploits/DarkSword/DarkSword.m.

// Lines 46-48 in DarkSword.m
cpu_subtype_t cpusubtype;
size_t len = sizeof(cpusubtype);
sysctlbyname("hw.cpusubtype", &cpusubtype, &len, NULL, 0);
isArm64e = (cpusubtype == CPU_SUBTYPE_ARM64E);

The isArm64e boolean flag determines whether PAC bypassing is necessary. Non-arm64e devices skip all PAC-related operations entirely.

Selecting and Loading the PAC Bypass Exploit

Dopamine's exploit selection architecture treats PAC bypass as a specialized exploit category with type EXPLOIT_TYPE_PAC.

UI-Based Exploit Selection

The settings controller (DOSettingsController.m) filters and presents only PAC-compatible exploits when running on arm64e hardware. Users select their preferred bypass, which DOJailbreaker.m retrieves via DOExploitManager.sharedManager.selectedPACBypass.

From Application/Dopamine/Jailbreak/DOJailbreaker.m (lines 176-183):

DOExploit *pacBypass = [DOExploitManager sharedManager].selectedPACBypass;
if (!pacBypass && [DOEnvironmentManager sharedManager].isPACBypassRequired) {
    return [NSError errorWithDomain:JBErrorDomain
                               code:JBErrorCodeFailedExploitation
                           userInfo:@{NSLocalizedDescriptionKey:
                 @"PAC bypass is required but we did not find any"}];
}

Exploit Execution Flow

The jailbreak core loads and executes the selected PAC bypass through a standardized interface:

if (pacBypass) {
    [[DOUIManager sharedInstance] sendLog:
        [NSString stringWithFormat:DOLocalizedString(@"Bypassing PAC (%@)"),
                                   pacBypass.name] debug:NO];
    
    if ([pacBypass load] != 0) { /* handle load failure */ }
    if ([pacBypass run] != 0)  { /* handle run failure */ }
    
    // Critical: mark system as having active PAC bypass
    gSystemInfo.jailbreakInfo.usesPACBypass = true;
}

This flag (usesPACBypass = true) gates all subsequent operations that depend on unsigned kernel pointers.

The XPACI Instruction: Core PAC Stripping Mechanism

Dopamine's low-level PAC removal relies on the XPACI (eXtract PAC from Instruction address) ARM64 instruction. This instruction is implemented as naked assembly in DarkSword.m (lines 100-108):

static uint64_t __attribute((naked)) __xpaci(uint64_t a)
{
    asm(".long 0xDAC143E0");   // XPACI X0 – clears PAC bits from pointer
    asm("ret");
}

uint64_t unpac_ptr(uint64_t kptr)
{
    if (!isArm64e) return kptr;      // Skip on non-arm64e devices
    return __xpaci(kptr);            // Strip PAC using CPU instruction
}

Key technical details:

  • The 0xDAC143E0 opcode encodes XPACI X0, which zeroes the upper PAC bits while preserving the canonical address
  • The __attribute((naked)) prevents compiler prologue/epilogue generation
  • All kernel pointer dereferencing flows through unpac_ptr() on arm64e

Enabling Stable Kernel Call Primitives

With PAC bypass active, Dopamine's kcall primitives become operational. The libjailbreak core checks this state before attempting kernel calls.

From BaseBin/libjailbreak/src/main.c (lines 33-34):

// primitives.c and kcall operations check this flag
if (jbinfo(usesPACBypass)) {
    // Enable full kernel read/write via stable kcall primitives
}

The primitives.h header defines supporting macros:

#define PAC_MASK    0xFFFFFF8000000000ULL  // PAC bit mask for arm64e
#define UNSIGN_PTR(ptr)  (jbinfo(usesPACBypass) ? unpac_ptr(ptr) : (ptr))

Key Source Files in Dopamine's PAC Bypass Implementation

File Function
Application/Dopamine/Jailbreak/DOJailbreaker.m Orchestrates exploit loading and execution; sets usesPACBypass flag
Application/Dopamine/Jailbreak/DOSettingsController.m UI for selecting among EXPLOIT_TYPE_PAC exploits
Application/Dopamine/Exploits/DarkSword/DarkSword.m Implements __xpaci() and unpac_ptr() with naked assembly
BaseBin/libjailbreak/src/primitives.h Defines PAC_MASK and UNSIGN_PTR macros
BaseBin/libjailbreak/src/main.c Checks jbinfo(usesPACBypass) for primitive stability
Application/Dopamine/Exploits/* Concrete PAC bypass payloads (platform-specific)

Summary

Dopamine's arm64e PAC bypass operates through five coordinated stages:

  • Architecture detection via hw.cpusubtype sysctl in DarkSword.m
  • Exploit selection filtered by EXPLOIT_TYPE_PAC category
  • Runtime execution through standardized load/run exploit interface
  • Pointer un-signing using the XPACI instruction in naked assembly
  • Primitive stabilization enabling kernel calls via usesPACBypass flag

This architecture allows Dopamine to support multiple PAC bypass implementations while maintaining a consistent internal API for kernel operations.

Frequently Asked Questions

What is PAC and why does Dopamine need to bypass it?

Pointer Authentication Code is a hardware security feature in arm64e Apple CPUs that cryptographically signs pointers to prevent code-reuse attacks. Dopamine must strip these signatures to read and write kernel memory, as signed pointers would fault when dereferenced in unauthorized contexts. The bypass achieves this without disabling PAC system-wide, only removing signatures from specific kernel pointers the jailbreak controls.

How does the XPACI instruction work at the hardware level?

XPACI (eXtract PAC from Instruction address) is an ARMv8.3-A instruction that zeroes the Pointer Authentication Code bits embedded in the upper address bits of a 64-bit pointer. The 0xDAC143E0 encoding targets the X0 register. Unlike AUTIA (authenticate), XPACI unconditionally clears PAC bits without verification, making it ideal for jailbreak scenarios where the correct PAC key is unknown.

Can Dopamine jailbreak arm64e devices without a PAC bypass?

No. According to the source code in DOJailbreaker.m, if isPACBypassRequired returns true and no selectedPACBypass exploit is available, the jailbreak aborts with JBErrorCodeFailedExploitation. The PAC bypass is mandatory for kernel read/write primitives on arm64e; non-arm64e devices (older iPhones) bypass this requirement entirely.

What PAC bypass exploits does Dopamine support?

Dopamine's architecture accepts any exploit advertising EXPLOIT_TYPE_PAC through its plugin system. The repository includes reference implementations such as DarkSword, with historical support for Fugu15-derived and C3-based PAC bypasses. Specific available exploits depend on the iOS version and device generation being targeted.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →