MagicCode is an app that mocks parts of the Apple Watch pairing process using Apple's private VisualPairing framework. This project builds on top of https://github.com/insidegui/VisualPairingHack and is part of the artifacts for Watch Your Back: Smartwatch Impersonation Attacks in Apple's iOS Ecosystem to be published at NDSS 2027.
To build and test the app for yourself, you need:
- an Apple account
- a computer running macOS with Xcode installed
- an iPhone running iOS 15.6 or later
Building using Xcode should be straightforward. Import the project into Xcode and connect your iPhone. In the project settings under signing and capabilities, update the team to your personal team and/or change the app's bundle identifier if prompted. Then run the app on your target iPhone.
If prompted, follow Xcode instructions to set up a personal development team and/or change the app's bundle identifier.
Note
While the app will launch in the iOS Simulator, scanning actual codes only works on real iPhones.
If you have an iPhone running iOS 15.6 or later with TrollStore or TrollStore Lite installed, you can skip the Xcode setup and directly install the magiccode.tipa archive in build.
To test the scanning feature, you may want to run the app on two phones simultaneously or try scanning one of the sample videos. Make sure your display is sufficiently bright when scanning the code. You should see a popup showing Apple Watch version details and Bluetooth pairing information as show in the screenshots above.
If you have a real Apple Watch at hand that you don't mind resetting, you can also scan the code it displays during pairing.