本文评测对象

Shadowrocket WLOC

供应商
Shadowrocket / WLOC
适用国家
Global
覆盖地区
Global

评分基于套餐透明度、覆盖范围、使用体验和服务支持综合得出。产品信息可能变化,请在购买前核对官方说明。

This guide shows how to combine Shadowrocket, the third-party WLOC module and two Shortcuts to alter Apple network-location responses on an iPhone, then restore the real location. It does not require a jailbreak, but it does require trusting a CA certificate that enables Shadowrocket to decrypt matching HTTPS traffic. That creates a genuine privacy and account-security risk.

The current module and supplied links were checked while preparing this page, but the workflow has not been independently tested across every iOS, Apple Maps or WeChat version. Results depend on the OS, the app’s location methods and future module updates. No app is guaranteed to accept the changed location.

Understand the risk first

WLOC is not an official location feature built into Shadowrocket. The current module is hosted in a third-party GitHub repository and intercepts these Apple endpoints:

gs-loc.apple.com
gs-loc-cn.apple.com

It also loads JavaScript from the repository at runtime. A remote script can change after this guide is published. Always open and inspect the module URL before importing it. Stop if its hosts, script paths or requested scope differ materially from those described here.

Keep these limits in mind:

  • HTTPS decryption allows Shadowrocket to read traffic matched by the module.
  • Location-sensitive apps may compare GPS, IP, Wi-Fi, mobile network and account history.
  • Banking, payment, attendance and gaming services may prohibit location manipulation.
  • Do not use a changed location to falsify attendance, transactions or identity information.
  • Learn how to revoke certificate trust before installing the CA.

What you need

  • Shadowrocket installed from the App Store
  • An iPhone with Safari and the Shortcuts app
  • The active Shadowrocket configuration profile
  • The device passcode for profile installation
  • The WLOC module URL and both iCloud Shortcut links

Shadowrocket is a paid network utility and does not include proxy servers. Its current App Store listing supports importing rules from URLs, decrypting HTTPS and rewriting URLs. WLOC and its Shortcuts remain third-party components.

Step 1: Add the WLOC module

In Shadowrocket, open:

Config → Modules → “+”

Paste this URL:

https://raw.githubusercontent.com/Yu9191/wloc/refs/heads/main/modules/wloc.module

After saving, a module named Apple WLOC 定位修改, or a similar WLOC location label, should appear. Open its details and verify that:

  1. the author or homepage points to Yu9191/wloc;
  2. the MITM hosts are limited to gs-loc.apple.com and gs-loc-cn.apple.com;
  3. the scripts still come from the same GitHub repository; and
  4. no banking, payment, email or account domains have been added.

Enable the module only after these checks. Do not rely on its name or icon alone.

Step 2: Enable HTTPS decryption

Return to Config and find the profile currently in use, such as default.conf. Tap its button, then open HTTPS Decryption.

  1. Enable HTTPS traffic decryption.
  2. Choose the option to generate a new CA certificate.
  3. Tap the certificate installation option.
  4. When iOS asks to download a configuration profile, verify the source and allow it.

The profile has only been downloaded at this stage. It is not yet fully trusted by iOS.

Step 3: Install and trust the CA

Open iPhone Settings. Depending on the iOS version, use the “Profile Downloaded” item near the top or go to:

Settings → General → VPN & Device Management

Select the new Shadowrocket CA profile, tap Install, enter the device passcode and complete the prompts.

Next, open:

Settings → General → About → Certificate Trust Settings

Find the new Shadowrocket CA and enable full trust after reading Apple’s warning. Return to the HTTPS Decryption screen in Shadowrocket. It should now report that the certificate is trusted by the system. Save with the checkmark, return to the home screen and enable Shadowrocket’s main switch.

If Certificate Trust Settings is missing, confirm that the profile was actually installed. Avoid installing several certificates with the same name.

Step 4: Add both Shortcuts

Open these links in Safari:

Before adding either Shortcut, expand its actions. Check the URLs it contacts, the coordinates it passes, and every permission request. Cancel if it asks for unrelated access to contacts, photos, passwords or an unfamiliar service.

Keep both Shortcuts. One writes the selected coordinates; the other clears the stored value. Installing only the setter makes recovery harder if something goes wrong.

Step 5: Select a place in Apple Maps

  1. Open Apple Maps.
  2. Search for a destination or press and hold to drop a pin.
  3. Open the location’s Share menu.
  4. Scroll down and select wloc 设置地理位置.
  5. Run the Shortcut and review the displayed place or coordinates.
  6. Follow any prompt that takes you to Location Services.

Then go to:

Settings → Privacy & Security → Location Services

Turn Location Services off, wait about 10 seconds, then turn it back on. Return to Apple Maps and allow the location to refresh.

The useful success indicator is Apple Maps placing the current location at the selected destination. If nothing changes, do not repeatedly reinstall certificates; use the troubleshooting checks below.

Step 6: Verify the result carefully

Start with Apple Maps instead of a bank, payment service or important account.

To inspect WeChat, open the location view in an ordinary chat and check its map preview. Different releases may use different APIs. A changed location in Apple Maps does not guarantee that WeChat, Live Location or another app will show the same result.

Do not confuse:

  • the map’s displayed position;
  • the network exit IP;
  • the SIM and mobile network country; and
  • the usual region stored by an app account.

WLOC primarily changes an Apple network-location response. It does not automatically change the IP address, SIM country or every account-region signal.

Step 7: Clear WLOC and restore the real location

When finished, open Shortcuts and run:

wloc 清理恢复位置

Turn Location Services off, wait about 10 seconds and turn it on again. Open Apple Maps and confirm that the real position has returned.

Then complete the cleanup:

  1. Disable the WLOC module in Shadowrocket.
  2. Disable HTTPS decryption.
  3. Revoke full trust for the Shadowrocket CA in Certificate Trust Settings.
  4. Remove the unneeded CA profile from VPN & Device Management.
  5. Restart Shadowrocket or the iPhone and verify the real location once more.

Removing the CA does not delete the Shadowrocket configuration, but HTTPS decryption that relies on the certificate will stop working.

Troubleshooting

The imported module does not appear

Check the complete URL, including the .module suffix. Open the raw GitHub address in Safari. If the phone cannot reach it, Shadowrocket may be unable to download it either.

Shadowrocket says the CA is not trusted

Installing the profile alone is insufficient. Open Certificate Trust Settings at the bottom of About and enable full trust for the matching CA. If several certificates share the same name, remove the old ones and generate one clean certificate.

WLOC is missing from the Share menu

Confirm that the setter has been added in Shortcuts and is allowed to appear in the Share Sheet. Run it once inside Shortcuts to expose any permission prompt or error.

Apple Maps does not change

Check the main Shadowrocket switch, WLOC module, HTTPS decryption and CA trust in that order, then restart Location Services. If it still fails, the module may not be compatible with the current iOS or Shadowrocket release.

Apple Maps changes but WeChat does not

This is possible and does not prove that a step was missed. Apps can use different location APIs, caches and risk signals. Do not expand the MITM host list or install an unknown module merely to force another app to accept it.

The virtual location remains after cleanup

Run the cleanup Shortcut again, disable WLOC and HTTPS decryption, then restart Location Services and the phone. If only one app is stale, refresh its map cache or location permission before considering a full device reset.

Security checklist

  • Obtain Shadowrocket only through the App Store.
  • Review hosts and script URLs whenever importing a remote module.
  • Never trust a MITM module that includes banking, email, payment or authentication domains.
  • Do not share CA private material, proxy profiles, server details or screenshots containing a precise home address.
  • Reinspect a remote script after an update; one review does not make it permanently safe.
  • Disable HTTPS decryption and remove the CA when it is no longer needed.
  • Follow local rules and service terms, and never use location changes for fraud or to bypass required verification.

If the purpose is to prepare a UK SIM activation environment from China, continue with the Giffgaff to CTExcel porting guide. Virtual GPS, network IP and SIM origin are separate signals.

Conclusion

The complete sequence is to inspect and import WLOC, enable HTTPS decryption, install and trust the CA, add both the set and cleanup Shortcuts, choose a destination in Apple Maps, and restart Location Services. When finished, run the cleanup Shortcut, disable the module and decryption, and revoke the CA. Because the workflow depends on a third-party remote script and changing iOS location behaviour, it should never be presented as guaranteed for every app.

Frequently asked questions

Frequently asked questions

Does the Shadowrocket WLOC method require jailbreaking?

No jailbreak is required for this workflow, but it does require a third-party WLOC module, a Shadowrocket CA certificate trusted by iOS, and HTTPS decryption.

Is it safe to trust the Shadowrocket CA certificate?

The certificate allows Shadowrocket to decrypt HTTPS traffic matched by the module, so it carries meaningful security risk. Enable it temporarily only after reviewing the module, then revoke trust and remove it.

Why has Apple Maps not moved to the selected place?

Confirm that WLOC, HTTPS decryption, the CA trust setting and the main Shadowrocket switch are all enabled. Restart Location Services after waiting about ten seconds. Compatibility can still vary.

Will the virtual location work in every app?

No. WLOC targets Apple network-location requests, while an app may also use GPS, IP address, cellular data, Wi-Fi signals, cached data or server-side risk checks.

How do I restore the real iPhone location?

Run the WLOC cleanup shortcut and restart Location Services. Once the real location returns, disable the module and HTTPS decryption, then revoke or remove the CA certificate.