Simulator Setup
The iOS Simulator runs on macOS and is great for fast, repeatable testing without hardware. It is not a substitute for a physical device, but it is the fastest way to get an app running, patched, and instrumented.
Launching the Simulator
Two ways: through Xcode or straight from the CLI with xcrun simctl.
# Open Simulator.app
open -a Simulator
# List all available runtimes and devices
xcrun simctl list
xcrun simctl list runtimes
# Boot a specific device by name or UDID
xcrun simctl boot "iPhone 15 Pro"
open -a Simulator
# Shut down all simulators
xcrun simctl shutdown all
Installing and Launching Apps
simctl handles install/launch/uninstall without Xcode.
xcrun simctl install "iPhone 15 Pro" /path/to/app.app
xcrun simctl install "iPhone 15 Pro" /path/to/app.ipa
# Launch by bundle ID (get it from Info.plist or simctl listapps)
xcrun simctl launch "iPhone 15 Pro" com.example.app
# List installed apps and their container paths
xcrun simctl listapps "iPhone 15 Pro"
# Uninstall
xcrun simctl uninstall "iPhone 15 Pro" com.example.app
# Erase the device back to factory state
xcrun simctl erase "iPhone 15 Pro"
Getting the App Container
You can read and write the app's data directory directly on disk — this is where a lot of quick testing happens.
# Absolute path to the app's data container
xcrun simctl get_app_container "iPhone 15 Pro" com.example.app data
# Open the container in Finder
open $(xcrun simctl get_app_container "iPhone 15 Pro" com.example.app data)
# Copy files in/out
cp file.db "$(xcrun simctl get_app_container "iPhone 15 Pro" com.example.app data)/Documents/"
Simulator + Burp Proxy
The simulator shares the Mac's network stack, so it uses the host's loopback directly.
- Burp listener:
127.0.0.1:8080. - In the simulator: no Settings proxy UI per network — configure the proxy at the OS level or via the app's own HTTP settings.
# Global HTTP proxy for the simulator (system-level, using the Mac's network)
xcrun simctl spawn "iPhone 15 Pro" defaults write globaldomain HTTPProxy 127.0.0.1
xcrun simctl spawn "iPhone 15 Pro" defaults write globaldomain HTTPPort 8080
# Or use the "HTTP Proxy" field in Simulator > Settings > Wi-Fi (works on newer runtimes)
The Burp CA must be installed in the simulator's keychain, then enabled in Certificate Trust Settings — the same flow as on a physical device but clickable on the Mac.
# Add the CA to the simulator keychain by opening the der in the simulator
# (drag burp-ca-cert.der onto the Simulator window), then:
# Settings > General > About > Certificate Trust Settings > Enable Full Trust
Simulator with Frida
Frida on the simulator does not need a jailbreak or a device server — just run Frida on the host.
pip3 install frida-tools
# The simulator is an x86_64/arm64 process tree on the Mac, so target it directly
frida-ps # list simulator processes
frida -f com.example.app # spawn-and-attach
frida-trace -f com.example.app -m "-[NSString stringWithFormat:]"
Limitations vs Physical Devices
Know what the simulator will not tell you:
- No real hardware keychain/secure enclave behavior — Keychain works but with relaxed entitlements.
- ATS rules are still enforced, but there is no hardware/network stack to test against real carrier/proxy conditions.
- Biometrics (Touch ID/Face ID) are simulated; you cannot test the real enrollment/prompt UX.
- No real cellular, GPS, or NFC/Apple Pay flows.
- App sandbox and entitlements behave differently; some hardened apps detect the simulator and refuse to run.
- No push notifications from real APNs unless configured with an entitlement.
- Debugger attach and runtime patching are far easier than on a device, so results don't always translate.
Rule of thumb: use the simulator for fast iteration (install, patch, reinstall), then validate the findings on a physical device before writing the report.