Library / SDK
mekos2772/ios-location-spoofer avatar
mekos2772/ios-location-spoofer

ios-location-spoofer: Spoofing iPhone GPS Location via Proxy MITM Without Jailbreak

Standalone iOS app to spoof GPS location without jailbreak. Includes Shadowrocket/Surge/Loon/QX/Stash module.

4,358 stars897 forksJavaScriptAGPL-3.0

At a glance

What is it?
ios-location-spoofer is a set of proxy modules for Shadowrocket, Surge, Loon, Quantumult X, and Stash that intercept Apple's location service requests and replace the returned coordinates with any target location. It works on an unmodified iPhone without a computer connection, operating entirely through the proxy's HTTPS decryption feature.
Who is it for?
ios-location-spoofer fits iPhone users who already run one of the five supported proxy apps and want to change their GPS-based location without jailbreaking their device or connecting to a computer. Users on iOS 26 or later need to restart the device each time they change the target location, which limits its convenience for frequent location changes.
Can I use it commercially?
Yes, with strict conditions. AGPL-3.0 is a network copyleft licence: if people use a modified version over a network, for example as a hosted service, you must offer them its source code under the same licence.
Is it still maintained?
Yes. The repository last received commits 2 days ago.
What is it written in?
Mainly JavaScript, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on October 1, 2026, and from our analysis. They are not legal advice.

Editorial analysis

How Location Spoofing Without Jailbreak Works

iPhone determines its location by sending a list of nearby Wi-Fi BSSIDs and cellular tower IDs to Apple's location service endpoint at /clls/wloc. Apple responds with the coordinates of those devices, and iOS uses them to calculate the phone's position. This exchange happens over HTTPS.

ios-location-spoofer works by placing the proxy app's MITM (man-in-the-middle) capability between the iPhone and Apple. The proxy decrypts the HTTPS request, the module's JavaScript intercepts Apple's response, replaces the latitude and longitude fields with the configured target coordinates, and forwards the modified response to iOS. The phone receives coordinates it cannot distinguish from a real Apple location response.

The README notes that this approach is treated as real positioning at the system level, unlike apps that simulate a location in software, which iOS identifies as simulated. The module only affects network-based location (Wi-Fi and cellular), not the GPS hardware signal. In areas with GPS coverage, apps that use direct GPS hardware rather than the Apple location service will not be spoofed.

Supported Proxy Platforms and Module Files

The repository provides separate module files for five proxy applications:

- ios-location-spoofer.sgmodule for Shadowrocket - ios-location-spoofer-surge.sgmodule for Surge - ios-location-spoofer.lnplugin for Loon - ios-location-spoofer.snippet for Quantumult X - ios-location-spoofer.stoverride for Stash - ios-location-spoofer-ios12.sgmodule for Shadowrocket on iOS 12 and older

The core logic lives in location-spoofer.js, which is shared across Shadowrocket, Surge, and Stash. A separate location-spoofer-qx.js handles Quantumult X's scripting model. The iOS 12 build uses a BigInt-free int64 implementation in location-spoofer.js because older devices' JavaScriptCore engine does not support BigInt.

Setting Up the Module: Required Steps

The README lists the setup steps in order:

1. Enable HTTPS decryption (MITM) in the proxy app. 2. Install and trust the proxy app's CA certificate. In iOS Settings, go to General, then VPN and Device Management, install the certificate, then under Certificate Trust Settings, enable full trust for it. 3. Import the module file for the relevant proxy app and enable it. 4. Disconnect and reconnect the VPN, then toggle location services off and on. 5. Open the Maps app to confirm the spoofed location.

All five of the following domains must be present in the proxy's HTTPS decryption hostname list for the module to intercept location requests:

code
gs-loc.apple.com
gs-loc-cn.apple.com
gsp-ssl.ls.apple.com
bluedot.is.autonavi.com
bluedot.is.autonavi.com.gds.alibabadns.com

The README warns that using an overly broad wildcard such as *.apple.com is not recommended, as it intercepts more than intended and can cause unrelated services to fail.

The iOS 26 Cache Problem

Starting with iOS 26, Apple significantly strengthened locationd's location caching. The system caches a real location in memory and reuses it for an extended period. The README states that even when the module has successfully rewritten the WLOC response (visible in the proxy logs as having been modified), iOS may continue to display the old location because it is still reading from its cache.

Toggling airplane mode or turning location services off and on does not clear this cache on iOS 26 and later. Only a full device restart clears the locationd memory cache and causes iOS to issue a fresh WLOC request that the module can intercept.

The README provides a specific sequence for iOS 26 and later: set the target coordinates in the module, enable airplane mode, turn off location services, restart the device, then after reboot, disable airplane mode (with Wi-Fi also off), connect to the proxy, enable location services, and verify with the Maps app. On iOS 15 through 18, toggling location services a few times is typically sufficient.

Configuring Target Coordinates

The default target is Apple Park at coordinates 37.3349, -122.00902. Coordinates are set in the module's argument string. The README gives this example of the parameter format:

code
latitude=39.9042&longitude=116.4074

The available parameters are latitude, longitude, and horizontalAccuracy (in meters, default 39). The module performs minimal rewriting: it only replaces latitude, longitude, and accuracy, leaving altitude, vertical accuracy, and motion state fields at their original Apple values. The README states this minimizes the risk of iOS rejecting the modified response as malformed, which would cause the location to show as unavailable.

A debug mode is available by setting debug=true in the argument string. When enabled, the proxy log will show messages tagged with "Location spoofer" indicating whether a request was intercepted and patched, which helps diagnose issues.

Optional: The location-picker Web Tool

The repository includes a location-picker/ subdirectory with an optional web server for selecting coordinates on a map rather than entering them manually. The server (location-picker/server.js) requires Node.js 24 or later and uses the built-in node:sqlite module with no additional npm dependencies.

The server can be deployed to Cloudflare Workers, Railway, or a self-hosted VPS or Docker environment. When deployed, the proxy module can be configured with a configUrl pointing to the server, and the module reads the target coordinates from that URL automatically. The Loon plugin uses a 15-minute cron job to refresh the coordinates from the remote server.

The README notes that TOKEN and ADMIN_TOKEN are the two authentication parameters. At least one must be set; a server that starts with neither and an empty database will refuse to run rather than expose an open endpoint. The admin panel, when enabled, allows creating, revoking, and deleting tokens through a web interface without redeploying.

Limitations and Failure Cases

ios-location-spoofer only intercepts network-based location requests. Applications that use the GPS hardware chip directly, bypassing the Apple location service, will not receive the spoofed coordinates. The README states this is a deliberate scope constraint and makes no claim about spoofing GPS hardware output.

The module depends on the proxy app's MITM capability working correctly. A MITM failed error in the proxy log typically means the CA certificate is not fully trusted in iOS, the intercepted domain is not in the MITM hostname list, or QUIC/HTTP3 is interfering with the connection. The README recommends disabling QUIC/HTTP3 options in the proxy and reconnecting if MITM errors persist. It also recommends against using broad hostname wildcards.

For Loon users, the README notes a specific issue: when a gzip-compressed response causes a zip decompress error or script timeout, updating the plugin and confirming that all three scripts (Prepare, Response, and the Geocode cron) are enabled resolves the problem.

The AGPL-3.0 license applies to all code in this repository. Any modified version of the module code that is used as part of a networked service offered to others must be released under the same license.

Comparison with Computer-Based Location Spoofing Tools

Tools such as AnyGo or iTools are commercial macOS or Windows applications that connect an iPhone via USB and use Xcode's developer mode to override the GPS location at the OS level. They simulate GPS hardware output, which means they affect all apps including those that bypass the Apple location service.

The key practical difference is the setup requirement. Computer-based tools require a Mac or Windows PC, a USB cable connection, and typically a paid license. ios-location-spoofer runs entirely on-device using a proxy app the user already has, requires no computer connection, and is free. The trade-off is that it only intercepts network-based location requests and cannot override GPS hardware signals. For apps that do not use GPS hardware directly, the proxy approach is sufficient and significantly simpler to operate.

Editorial conclusion

ios-location-spoofer fits iPhone users who already run one of the five supported proxy apps and want to change their GPS-based location without jailbreaking their device or connecting to a computer. Users on iOS 26 or later need to restart the device each time they change the target location, which limits its convenience for frequent location changes. Before using it, confirm that HTTPS decryption is enabled in the proxy app, the CA certificate is trusted in iOS settings under Certificate Trust Settings, and all five Apple location service domains are in the MITM hostname list.

Frequently asked questions

Is there a way to fake your location on an iPhone without jailbreaking?

ios-location-spoofer does this by intercepting Apple's network-based location service through a proxy app's HTTPS decryption feature. It works without jailbreak or a computer, but requires a supported proxy app (Shadowrocket, Surge, Loon, Quantumult X, or Stash) with HTTPS decryption enabled and a trusted CA certificate.

Is there a way to change your location on iPhone?

ios-location-spoofer changes the coordinates returned by Apple's Wi-Fi and cellular location service by intercepting the HTTPS response through a proxy module. The default target is Apple Park; you change it by editing the latitude and longitude parameters in the module's argument string.

How can you fake your live location on an iPhone?

After installing the proxy module and setting a target location, the iPhone's location-based apps read the spoofed coordinates. On iOS 15 through 18, toggling location services off and on usually applies the change. On iOS 26 and later, the README states that a full device restart is required to clear the location cache before the new coordinates take effect.

How do you make an iPhone appear in a different location?

Set the target latitude and longitude in the proxy module's argument string, ensure HTTPS decryption is active with the five Apple location domains in the MITM hostname list, then restart location services (or restart the device on iOS 26+). The Maps app can be used to verify the spoofed position.

Official sources

  1. Issues
  2. License: AGPL-3.0
  3. mekos2772/ios-location-spoofer on GitHub
  4. README
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/mekos2772-ios-location-spoofer.svg)](https://hysenlabs.com/projects/mekos2772-ios-location-spoofer)