Magnet Forensics Tool Bypasses iOS Automatic Reboot Security
Law enforcement tools can now circumvent iOS's security feature that automatically reboots iPhones after 72 hours of inactivity, preserving data that would otherwise be secured or deleted.

Cyber-weapons manufacturer Magnet Forensics has developed a new method to bypass a critical security feature in Apple's iOS operating system, potentially granting law enforcement agencies unprecedented access to sensitive data on locked iPhones. The technique targets the 'automatic reboot' function, a security measure designed to enhance device protection after 72 hours of inactivity.
This inactivity reboot feature is crucial for iOS security. When an iPhone is left unused for an extended period, it automatically enters a more secure state. This process is intended to protect user data by requiring re-authentication and potentially clearing certain sensitive temporary data, such as location caches or recently deleted messages, to prevent unauthorized access.
Magnet Forensics, known for its GrayKey tool used by law enforcement to unlock mobile devices, has introduced 'GrayKey Preserve' and an 'Evidence Preservation Mode' for its existing GrayKey devices. According to leaked video demonstrations, these new capabilities are specifically engineered to circumvent the inactivity reboot mechanism. This allows investigators to access data that would typically be secured or purged by the system's inactivity protocols.
Beyond the inactivity reboot, the new Magnet Forensics tools also aim to combat another iPhone security feature that automatically deletes specific data points after a set number of days. This includes cached location history and recently deleted photos or iMessages. The 'Evidence Preservation Mode' reportedly promises to keep such data available for an "infinite amount of time," significantly extending the window for forensic analysis.
The development is presented by Magnet Forensics employees in leaked materials as a "game changer for iOS forensics," highlighting the long-standing need for such capabilities in digital investigations. The ability to preserve data that would normally be ephemeral or secured by inactivity locks represents a significant advancement for digital forensics tools.
While the specific technical details of the vulnerability exploited by Magnet Forensics have not been publicly disclosed, it is presumed that Apple engineers will be alerted to its existence. The company has a history of addressing such security loopholes, particularly when they are exploited by tools designed for law enforcement or other governmental agencies.
The existence of such tools raises broader questions about the balance between digital privacy and law enforcement's investigative needs. As forensic technology advances, the cat-and-mouse game between device manufacturers and tool developers continues, with each seeking to bolster or bypass security measures.
This development underscores the ongoing arms race in cybersecurity and digital forensics. The ability to bypass built-in security features like automatic reboots and data purging highlights the constant need for vigilance and adaptation from both security researchers and device manufacturers.