How iOS app installation really works
This site explains the parts of iOS that Apple does not spell out: how code signing is enforced, why some installation methods only work on specific versions, and how to tell which one applies to your device. Everything here is organised for readers who want the mechanism, not just a sequence of taps.
Where to start
Check your iOS version and chip
Start with the device model and system version. That combination alone decides which method is even possible. Get it wrong and nothing else will work.
Pick the method for that version
Each supported version range has its own installation path. Follow the one that matches — do not mix steps from different guides.
Set up the persistence helper
On iOS 15 and later, apps may refuse to open after a restart. That is a known consequence of the mechanism, and it is fixable in advance.
What TrollStore actually is
TrollStore takes advantage of a specific defect in CoreTrust, the iOS component that validates an app's signing state. Because of that defect, an app can be written with a system-level signing state instead of an ordinary user-level one.
It is not a jailbreak. It does none of the following:
- It does not grant root access
- It does not modify the system partition
- It does not disable system security mechanisms
That difference in signing state produces three concrete results:
- Apps do not expire when a certificate lapses, so no periodic re-signing
- Apps still open after the device is restarted
- No developer certificate or Apple ID is involved
The prerequisite is strict. The flaw exists only in certain iOS versions. This is a hard limit set by the version, not something a different tool can work around. iOS 17.0.1 and later have the fix, and there is currently no public method for them. Check your version first.
Official repository: https://github.com/opa334/TrollStore
Compared with ordinary self-signing tools
| Property | This mechanism | Typical self-signing tool |
|---|---|---|
| Do apps expire? | No | Usually every 7 days |
| Re-signing required? | No | Yes |
| Jailbreak required? | No | No |
| Version coverage | Narrow, hard limit | Wider |
| Stability | High | Mixed |
Compatibility at a glance
Recommended method per version range. Blue pills are clickable once the corresponding guide exists in English; amber means no method is currently available for that range, and grey means the version is unsupported.
| Version range | arm64 (A8–A11) | arm64e (A12 and later) |
|---|---|---|
| iOS 13.7 and earlier | Unsupported | Unsupported |
| iOS 14.0 – 14.8.1 | TrollHelper | TrollHelperOTA |
| iOS 15.5 | TrollInstallerMDC | TrollHelperOTA |
| iOS 15.7.2 – 15.7.6 | TrollHelper | No method yet |
| iOS 16.2 – 16.5 | TrollHelper | Misaka |
| iOS 16.6.1 | TrollHelper | TrollHelper |
| iOS 17.0 | TrollHelper | No method yet |
| iOS 17.0.1 and later | Unsupported | Unsupported |
Guides
Installation methods are split strictly by iOS version. Use the lookup above to find yours, then read only that guide.
Installing via TrollHelper
Install TrollStore Helper through a package manager. Required for jailbroken arm64 devices, and for some models after iOS 15.7.2 that have no non-jailbreak path.
Installing via TrollHelperOTA
Use the system OTA update flow to install the helper. No computer and no jailbreak required — the least effort path on older iOS versions.
Installing via TrollInstallerMDC
Uses an MDC-class exploit installer. Covers the mainstream iOS 15.5–16.1.2 range with a short procedure and a high success rate.
Installing via Misaka
Combine the Misaka file manager with a kernel exploit. Primarily for arm64e devices on iOS 16.2–16.6.
Configuring and Recovering the Persistence Helper
Why installed apps stop opening after a reboot, and how to fix it: bind the persistence helper to a built-in system app.
Updating and Migrating
Upgrade through the OTA mechanism, plus what to watch out for when switching devices or restoring, and the correct order for migrating data.
Common questions
Does it require a jailbreak?
No. It runs on stock devices, does not grant root, and does not modify the system partition. Some installation paths do assume a jailbroken device — that is a limit of the delivery method, not of the mechanism itself.
Do installed apps expire?
No — and this is the main practical difference from ordinary self-signing. Self-signed apps depend on a personal developer certificate and usually need re-signing every 7 days. Apps installed this way do not expire on supported versions.
How wide is the supported range?
Narrow, and hard-limited. It covers part of iOS 14.0 through 16.6.1, plus iOS 17.0. The underlying flaw was fixed in iOS 17.0.1 and later, so those versions have no public method.
Does this site host download files?
No. We publish explanations and procedures only. Installation files come from the project’s official repository, and the download page links straight to it.
About this site
巨魔研究所 is an independently operated technical reference. The material here is written from project documentation, community-maintained guides and publicly verifiable sources, and then rewritten for readers rather than copied.
This site does not host, mirror or redistribute installation files, IPAs or any other binaries, and it does not assist with circumventing software licensing. Links to downloads always point at the project's own repository. Everything published here is for reference; device modifications are carried out at your own risk.