finds.dev← search

// the find

opa334/ChOma

★ 446 · C · MIT · updated Aug 2026

C library for manipulating MachO/FAT files and their code signatures

ChOma is a low-level C library for parsing and rewriting MachO/FAT binaries and their CMS code-signature blobs on Apple platforms, built specifically to implement the CoreTrust CMS-multi-signer bypass (CVE-2023-41991). It's the shared format-parsing engine behind TrollStore, XPF, and Dopamine, so it's aimed at jailbreak/sideloading tool authors, not general app developers.

The MemoryBuffer abstraction (function pointers for read/write/resize/clone, backed by either a file or a plain buffer) is a genuinely useful design choice — it lets the same MachO/CMS manipulation code run against a 20-byte in-memory patch or a multi-GB dyld shared cache without duplicating logic. The README actually explains the exploit mechanics (the CMS two-signer confusion, CodeDirectory hash juggling) instead of hand-waving, which is rare and shows the author understands the format at the byte level. It's also battle-tested: Dopamine and TrollStore exercise this code against a huge variety of real-world binaries, so the MachO/FAT/DSC parsing paths have had real adversarial input thrown at them.

There's a `cert.p12` committed at the repo root with no explanation of what it is, who holds the private key, or whether it's test-only — that's the kind of thing that should never be in source control regardless of intent. There's no CI configuration anywhere in the tree, which is concerning for a binary-format parser where a bad offset calculation silently corrupts output instead of crashing. The public API in `include/choma` has no doc comments or usage guide beyond one README section, so integrating it means reading the C source directly. And the CoreTrust bypass that the README leads with is a dead exploit on any patched device — the arm64 patchfinder it ships is explicitly called out as superseded by a separate project (XPF), so there's stale/half-relevant code left in the tree.

View on GitHub →

// want more like this?

We dig through GitHub every week and send a few repos picked for what you actually care about — each with an honest take like this one.

Get finds in your inbox → Search again →