Possible Vulnerability in Apple’s Automatic Reboot
Magnet Forensics' GrayKey Preserve reportedly bypasses iPhone inactivity reboot so forensic data stays available.
Bruce Schneier points to 404Media reporting that Magnet Forensics is exploiting an iOS flaw to bypass Apple's automatic reboot, which puts an unused iPhone into a more secure state after 72 hours. Leaked material describes a GrayKey Preserve device and an Evidence Preservation Mode meant to keep forensic access and stop automatic deletion of cached locations, recently deleted photos, and iMessages. No CVE is named, and the post does not say Apple has patched the issue. Schneier writes that Apple can now look for and fix the flaw.
- Unused iPhones enter a more secure state after 72 hours.
- GrayKey Preserve is described as defeating that inactivity reboot.
- Evidence Preservation Mode also aims to retain auto-deleted data.
- The report names no CVE and no Apple fix.
Full article268 words · extracted from schneier.com · click to collapse
404Media is reporting (alternate link) that a cyber-weapons arms manufacturer is exploiting a vulnerability in iOS to bypass its automatic reboot security feature. This is the feature that automatically puts an iPhone into a more secure state if it hasn’t been used for 72 hours.
The new technology to get around inactivity reboot was developed by Magnet Forensics, the company behind GrayKey, a popular tool sold to law enforcement agencies that allows them to unlock and access data stored in iPhones and Android smartphones. Magnet has developed a new device called GrayKey Preserve and a feature for its regular GrayKey devices called Evidence Preservation Mode, according to the video.
“This is an absolute game changer for iOS forensics and a function that I wish we had years ago,” a Magnet employee says in the leaked video, specifically mentioning that the solution is targeted at the iPhone’s inactivity reboot feature and the data it makes unavailable. GrayKey Preserve and Evidence Preservation Mode are also designed to combat another iPhone feature that automatically deletes certain data - such as cached locations, and recently deleted photos and iMessages - after a certain number of days. “We’re gonna be able to preserve that data for an infinite amount of time.”
Presumably, now that Apple engineers know that this flaw exists they can find and fix it. AI turns out to be really good at this sort of thing.
Another news article.
Tags: iPhone, law enforcement, police, vulnerabilities
Sidebar photo of Bruce Schneier by Joe MacInnis.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.schneier.com/blog/archives/2026/10/possible-vulnerability-in-apples-automatic-reboot.html