Skip to main content

Simulator Setup

The iOS Simulator runs on macOS and is great for fast, repeatable testing without hardware. It is not a substitute for a physical device, but it is the fastest way to get an app running, patched, and instrumented.

Launching the Simulator​

Two ways: through Xcode or straight from the CLI with xcrun simctl.

# Open Simulator.app
open -a Simulator

# List all available runtimes and devices
xcrun simctl list
xcrun simctl list runtimes

# Boot a specific device by name or UDID
xcrun simctl boot "iPhone 15 Pro"
open -a Simulator

# Shut down all simulators
xcrun simctl shutdown all

Installing and Launching Apps​

simctl handles install/launch/uninstall without Xcode.

xcrun simctl install "iPhone 15 Pro" /path/to/app.app
xcrun simctl install "iPhone 15 Pro" /path/to/app.ipa

# Launch by bundle ID (get it from Info.plist or simctl listapps)
xcrun simctl launch "iPhone 15 Pro" com.example.app

# List installed apps and their container paths
xcrun simctl listapps "iPhone 15 Pro"

# Uninstall
xcrun simctl uninstall "iPhone 15 Pro" com.example.app

# Erase the device back to factory state
xcrun simctl erase "iPhone 15 Pro"

Getting the App Container​

You can read and write the app's data directory directly on disk — this is where a lot of quick testing happens.

# Absolute path to the app's data container
xcrun simctl get_app_container "iPhone 15 Pro" com.example.app data

# Open the container in Finder
open $(xcrun simctl get_app_container "iPhone 15 Pro" com.example.app data)

# Copy files in/out
cp file.db "$(xcrun simctl get_app_container "iPhone 15 Pro" com.example.app data)/Documents/"

Simulator + Burp Proxy​

The simulator shares the Mac's network stack, so it uses the host's loopback directly.

  • Burp listener: 127.0.0.1:8080.
  • In the simulator: no Settings proxy UI per network — configure the proxy at the OS level or via the app's own HTTP settings.
# Global HTTP proxy for the simulator (system-level, using the Mac's network)
xcrun simctl spawn "iPhone 15 Pro" defaults write globaldomain HTTPProxy 127.0.0.1
xcrun simctl spawn "iPhone 15 Pro" defaults write globaldomain HTTPPort 8080

# Or use the "HTTP Proxy" field in Simulator > Settings > Wi-Fi (works on newer runtimes)

The Burp CA must be installed in the simulator's keychain, then enabled in Certificate Trust Settings — the same flow as on a physical device but clickable on the Mac.

# Add the CA to the simulator keychain by opening the der in the simulator
# (drag burp-ca-cert.der onto the Simulator window), then:
# Settings > General > About > Certificate Trust Settings > Enable Full Trust

Simulator with Frida​

Frida on the simulator does not need a jailbreak or a device server — just run Frida on the host.

pip3 install frida-tools

# The simulator is an x86_64/arm64 process tree on the Mac, so target it directly
frida-ps # list simulator processes
frida -f com.example.app # spawn-and-attach
frida-trace -f com.example.app -m "-[NSString stringWithFormat:]"

Limitations vs Physical Devices​

Know what the simulator will not tell you:

  • No real hardware keychain/secure enclave behavior — Keychain works but with relaxed entitlements.
  • ATS rules are still enforced, but there is no hardware/network stack to test against real carrier/proxy conditions.
  • Biometrics (Touch ID/Face ID) are simulated; you cannot test the real enrollment/prompt UX.
  • No real cellular, GPS, or NFC/Apple Pay flows.
  • App sandbox and entitlements behave differently; some hardened apps detect the simulator and refuse to run.
  • No push notifications from real APNs unless configured with an entitlement.
  • Debugger attach and runtime patching are far easier than on a device, so results don't always translate.

Rule of thumb: use the simulator for fast iteration (install, patch, reinstall), then validate the findings on a physical device before writing the report.