// the find
opa334/opainject
iOS runtime dylib injection tool
A narrow, single-purpose iOS tool that injects a dylib into another process by grabbing its task port and forcing it to execute a ROP chain, rather than going through the usual debugger/injection APIs. It's aimed at iOS jailbreak/security researchers who need to get code running inside a target process without Apple's blessing, not app developers.
The scope is tight — arm64.m, rop_inject.m, dyld.m, task_utils.m, thread_utils.m each map to one piece of the injection pipeline, so the whole thing is readable in an afternoon instead of being buried in a framework. It explicitly handles ARM64e pointer authentication (pac.h), which is the part that actually breaks most naive ROP/injection tricks on newer hardware — a lot of similar tools just don't bother. The claimed compatibility range (iOS 14 through 27, theoretically back to 11) for a technique built on task ports and ROP chains means the core approach has held up across major dyld/kernel changes instead of being a one-OS-version hack.
The README is two sentences — no build steps, no usage example, nothing about what entitlements.plist actually needs to contain or why CoreSymbolication/sandbox private headers are required, so anyone cloning this has to reverse-engineer the setup from the Makefile and source. There's no test suite and no CI for a tool that pokes at another process's memory and thread state — that's exactly the kind of code where a subtle bug silently corrupts a target process, and there's no safety net catching regressions across the many iOS versions it claims to support. No changelog or per-version notes despite spanning iOS 14–27, so when something inevitably breaks on a new release there's no history showing what previously had to change to keep it working.