Open-source project
leminlimez/Nugget avatar
leminlimez/Nugget

Nugget: iOS device tweaks via sparserestore and BookRestore

Unlock the fullest potential of your device

7,264 stars404 forksPythonAGPL-3.0

At a glance

What is it?
Nugget is a Python and PySide6 desktop app that writes tweaks to iOS 17.0 through 26.1 by abusing the restore process. It is powerful, it is not reversible in the README's terms, and the README itself warns against iOS 27.
Who is it for?
Nugget suits people with a spare or already-backed-up iPhone on iOS 17.0 through 26.1 who want to change carrier text, enable Dynamic Island or Stage Manager, or disable daemons, and who accept that the README calls some options risky. It is the wrong tool for a primary phone you cannot restore, for anything on iOS 27, and for anyone who will not read documentation.md before writing a batter file.
Can I use it commercially?
Yes, with strict conditions. AGPL-3.0 is a network copyleft licence: if people use a modified version over a network, for example as a hosted service, you must offer them its source code under the same licence.
Is it still maintained?
Yes. The repository last received commits 7 days ago.
What is it written in?
Mainly Python, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 30, 2026, and from our analysis. They are not legal advice.

Editorial analysis

What Nugget actually changes on an iPhone

Nugget is not a jailbreak and it does not install a package manager. It is a desktop application that talks to a connected iPhone over USB and asks the device's restore service to write files it would not normally accept. The README frames the result as customization: animated wallpapers through PosterBoard, carrier name and battery text in the status bar, Springboard options such as the Lock Screen footnote, internal debugging flags, and a list of daemons you can switch off. The audience is narrow and technical. You need a computer, a cable, and enough patience to follow a multi-step setup that includes a separate Shortcuts app on the phone. The payoff is access to settings Apple does not expose, on stock iOS, without a jailbreak.

The feature list is split by iOS version, and that split is the single most important thing to understand before downloading. PosterBoard, status bar edits, Springboard options, internal options, daemon disabling, and the risky thermalmonitord option are listed under iOS 17.0 to 26.0 and later. Mobile Gestalt edits such as enabling Dynamic Island on unsupported devices, iPadOS on an iPhone, Stage Manager, charge limit, and the EU Enabler sit under iOS 17.0 to 26.1, with feature flags in the same range. AI Enabler and Device Spoofing are listed only for iOS 18.1 to 26.1. If your device is outside a range, that group of tweaks is not documented as available to you.

Sparserestore, BookRestore and the mobilegestalt file

The mechanism is a partial restore. The README states that Nugget uses the sparserestore exploit to write to files outside the intended restore location, mobilegestalt being the named example. Version coverage is explicit: sparserestore works on iOS 17.0 through 18.1.1, and BookRestore works on iOS 18.2 through 26.1. Those two ranges cover the whole supported span, so the app is choosing a different write path depending on the firmware you plug in. That is why the version tables in the feature list are not marketing segmentation; they reflect which code path can reach which file.

Mobile Gestalt is where the interesting tweaks live, and it is also where the setup cost lands. On iOS 26.1 and below the README says you may need the mobilegestalt file specific to your device. The documented way to get it is to install the Shortcuts app from the iOS App Store, download the Save MobileGestalt shortcut, save the file, share it to your computer, and put it in the same folder as the Python file or point the program at its path. There is no command-line flag documented for this and no automatic fetch. If you skip it, expect the Mobile Gestalt group to be unavailable rather than to fail loudly.

Installing Nugget on Windows, Linux and macOS

Nugget is distributed as source. The README gives two ways to run it, and the Python route is the one with full instructions. Requirements differ by platform: on Windows you need either the Apple Devices app from the Microsoft Store or iTunes from Apple's website; on Linux you need usbmuxd and libimobiledevice. Running the Python program additionally needs pymobiledevice3, PySide6 and Python 3.9 or newer.

The README recommends a virtual environment, and says to create it once. Run this in the repository root:

bash
python3 -m venv .env

Activate it on macOS or Linux with the first command below, or on Windows with the second:

bash
source .env/bin/activate
bash
.env/Scripts/activate.bat

Then install the pinned dependencies once and start the app. The README notes that depending on your system configuration you may need python and pip instead of python3 and pip3:

bash
pip3 install -r requirements.txt
python3 main_app.py

requirements.txt pins pymobiledevice3 at 8.0.0 or newer, PySide6-Essentials on non-Linux platforms and PySide6 on Linux, plus PyInstaller, readchar, ffmpeg, ffmpeg-python, opencv-python, pyperclip, and pyuac on Windows only. The ffmpeg and opencv entries are there for the PosterBoard video conversion path, not for the tweaks themselves. If you would rather not run Python, the repository root contains compile.py and the README says the application itself can be compiled by running it, with PyInstaller already in requirements.txt. A first real use is the smallest one: connect the device, let the app enumerate it, and apply a status bar change such as the carrier name, which needs no mobilegestalt file and no Shortcut on the phone.

The iOS 27 warning and other ways Nugget breaks your day

The README opens its warnings with a blunt one: do not use this on iOS 27, because it will most likely result in data loss, and Apple has patched the partial restore method Nugget uses. That is not a caveat about a beta; it is the project saying the technique is dead on that firmware. Anyone on iOS 27 has no supported path through Nugget regardless of which feature they want.

The second limitation is that the tool edits system state without a documented undo. The README tells you to back up your data before using the project, notes that Nugget may cause unforeseen problems, and disclaims responsibility for damage. There is no rollback command, no restore-original-values button described in the README, and no mention of how to revert a Mobile Gestalt change other than restoring the device. Treat every toggle as one-way until you find documentation saying otherwise. The feature list also labels a group Risky (Hidden) Options, with disabling thermalmonitord as the sole entry; thermal monitoring is the system that throttles a hot phone, and the README does not describe the consequences beyond the label. Enabling always-on display on unsupported hardware carries its own warning in the README about burn-in. Some entries are explicitly at your own risk, including enabling iPadOS on iPhones and showing internal storage info.

A third constraint is that iOS 27 aside, the coverage tables are the contract. A tweak listed under iOS 17.0 to 26.1 is not promised for a device on 26.1.1, and the README's silence on that point is the answer. If your firmware is not in a listed range, assume the feature is unavailable.

Nugget compared with jailbreak-based tweaking

The obvious alternative is a jailbreak with a tweak loader such as Cydia or Sileo. The difference is architectural, not cosmetic. A jailbreak modifies the running system and gives you a package manager, persistent tweaks, and a community of hooks that can be updated independently of the exploit. Nugget does none of that. It rides the restore process once, writes the file, and the change lives in the system as if it had always been there. There is no daemon to keep alive and nothing to re-inject after a reboot, which is why the tweaks survive normally. The cost is that you get exactly the switches the app exposes, and nothing else. You cannot write your own tweak against an API.

The second alternative is doing nothing and living with Apple's defaults. That sounds flippant, but it is the honest comparison for a primary phone. Nugget's value is concentrated in cosmetic and diagnostic changes plus a handful of capability unlocks on hardware Apple gated. If you want a carrier name change badly enough to risk a restore, the tool is proportionate. If you want a stable daily driver, the restore-based approach is a single point of failure with no undo, and Apple's patch history shows the window closing. The Templates feature is the closest thing to extensibility, letting you define custom operations and file edits through batter files, and the README points to documentation.md for the structure of tendies and batter files. That is a real extension path, but it is a file format you write, not a package ecosystem you install from.

Licence, maintenance and what an upgrade costs you

Nugget is licensed AGPL-3.0. The practical implication for most users is nil, since you are running it locally. If you fork it, host a modified version, or ship it inside a service, the AGPL's network clause is the part to read with a lawyer rather than a blog post. The repository does not carry a separate commercial licence file in its top-level entries, so there is no dual-licensing escape hatch visible in the layout.

Maintenance looks current rather than dormant. The last push to main was on 2026-09-21, and the most recent release is v7.4 from 2026-09-18, following v7.3.2 on 2026-08-24 and v7.3.1 on 2026-03-27. The gap between v7.3.1 and v7.3.2 is five months, and the gap between v7.3.2 and v7.4 is under a month, so release cadence is uneven rather than steady. The repository is not archived. Upgrading is cheap in the mechanical sense: pull the branch, re-run pip3 install -r requirements.txt, and start main_app.py again. It is not cheap in the risk sense, because a new release can change which exploit path is used or which firmware is covered, and the README's version tables are the only changelog you get for that. Re-read them after every upgrade before you reconnect a device you care about.

Editorial conclusion

Nugget suits people with a spare or already-backed-up iPhone on iOS 17.0 through 26.1 who want to change carrier text, enable Dynamic Island or Stage Manager, or disable daemons, and who accept that the README calls some options risky. It is the wrong tool for a primary phone you cannot restore, for anything on iOS 27, and for anyone who will not read documentation.md before writing a batter file. Before installing, confirm your iOS version against the two exploit ranges, confirm your PC has the Apple Devices app or iTunes on Windows or usbmuxd and libimobiledevice on Linux, and check whether your device needs a mobilegestalt file saved via the Shortcuts shortcut.

Frequently asked questions

How do I install Nugget on Windows?

Install either the Apple Devices app from the Microsoft Store or iTunes from Apple's website, then create a virtual environment, install requirements.txt with pip3, and run main_app.py. The README also notes that pyuac is pulled in on Windows only.

How do I install Nugget for iOS tweaking?

Nugget is a desktop program, not something you install on the iPhone. On the computer you need Python 3.9 or newer, pymobiledevice3 and PySide6, and on Linux also usbmuxd and libimobiledevice; then run pip3 install -r requirements.txt followed by python3 main_app.py.

Can I use Nugget on iOS 26?

Yes for the ranges the README lists. PosterBoard, status bar, Springboard, internal options and daemon disabling are documented for iOS 17.0 to 26.0 and later, Mobile Gestalt and feature flags for iOS 17.0 to 26.1, and AI Enabler and Device Spoofing for iOS 18.1 to 26.1. BookRestore is the write path for iOS 18.2 through 26.1.

Can I use Nugget on iOS 27?

No. The README warns not to use Nugget on iOS 27 because it will most likely result in data loss, and states that Apple has patched the partial restore method the project relies on.

Official sources

  1. Issues
  2. leminlimez/Nugget on GitHub
  3. License: AGPL-3.0
  4. README
  5. Releases
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/leminlimez-nugget.svg)](https://hysenlabs.com/projects/leminlimez-nugget)