Ios 9.3 6 Jailbreak Untethered May 2026
The last true untethered jailbreak for a 32-bit device was (Pangu9). Everything after 9.1 moved to semi-untethered because the exploits required to persist across reboots were burned by Apple or reserved for higher bounties. 3. The "OTA" Anomaly iOS 9.3.6 was not a full IPSW for most devices. It was an OTA (Over-The-Air) patch specifically for GPS and cellular radios. Because the update was small, it didn't fix the underlying tfp0 (task for port zero) exploits that Phoenix uses. However, it did break older untether attempts. No developer wasted time building an untether for a version that less than 0.1% of the iOS user base would ever install. Debunking the YouTube Fakes Search "iOS 9.3.6 jailbreak untethered" on YouTube today. You will see thousands of videos with a Download link in the description, a fake Cydia logo in the thumbnail, and a robotic voice claiming "100% working."
That safety net is worth the extra tap of "Kickstart." The jailbreak development community has moved on. The last untethered jailbreak for any version was iOS 9.0.2 , released over eight years ago by Pangu (which they quickly patched in 9.1). ios 9.3 6 jailbreak untethered
The reality is that .
Why? Because the iPhone 4s on 9.3.6 is incredibly unstable. If you had an untethered jailbreak, and a bad tweak caused a bootloop, your device would be permanently bricked (restore to 9.3.6 is no longer signed by Apple). With a semi-untethered jailbreak, you can simply reboot the phone, delete the bad tweak from safe mode (via Volume Up button), and re-jailbreak. The last true untethered jailbreak for a 32-bit
Key developers (tihmstar, Siguza, Luca Todesco) have publicly stated that they have no interest in developing an untether for 9.3.6. The effort required to weaponize a new iBoot bug or bootrom exploit for a 32-bit device is immense, and there are no financial incentives (bug bounties for old firmware are zero). The "OTA" Anomaly iOS 9
Let us explain why. The only functional jailbreak for iOS 9.3.6 is Phoenix , released by the Corellium Team (Siguza, tihmstar, etc.). Phoenix is a semi-untethered jailbreak. You install the Phoenix IPA via Cydia Impactor (now AltStore or Sideloadly). When you reboot, you lose the jailbreak. You must open the Phoenix app and press "Kickstart." 2. The Missing KPP Bypass On 64-bit devices, Apple introduced KPP (Kernel Patch Protection). iOS 9 on 32-bit devices does not have KPP, but it does have KASLR (Kernel Address Space Layout Randomization). While 32-bit devices are easier to exploit, untethered requires a bootrom-level exploit or a persistent kernel code injection that survives a reboot.