All stories
AI

New GrayKey Tools Reportedly Bypass Apple iPhone Security Feature

A leaked training video reveals Magnet Forensics has developed tools to bypass Apple's 72-hour inactivity reboot on iPhones, potentially giving law enforcement extended access to sensitive user data.

By TECH NEWS Editorial·Source:Engadget·4 min read·3h ago

✨ This content was summarized and interpreted by AI; it may contain errors — please verify accuracy with the original sources. Learn more

Share

Listen to this story

0:00 / 0:00
New GrayKey Tools Reportedly Bypass Apple iPhone Security Feature

A leaked training video has reportedly revealed that Magnet Forensics, the company behind the widely used GrayKey device, has developed new tools that enable law enforcement to bypass Apple's "inactivity reboot" security feature on iPhones, potentially allowing extended access to sensitive user data. This development, reported by 404 Media, describes a "game changer" for iOS forensics, countering an Apple security measure introduced in iOS 18 in 2024, which automatically reboots an iPhone after 72 hours of inactivity, returning it to a more secure "Before First Unlock" (BFU) state. Magnet Forensics' new offerings, "GrayKey Preserve" and an "Evidence Preservation Mode" for existing GrayKey devices, aim to keep iPhones in an "After First Unlock" (AFU) state, even after a reboot or power loss, thereby making more data accessible to investigators.

This breakthrough significantly impacts user privacy and the ongoing cat-and-mouse game between device manufacturers and forensic companies. Apple's inactivity reboot was a critical enhancement, designed to return an idle iPhone to a state where its most sensitive data, protected by encryption keys tied to the Secure Enclave, becomes much harder, if not impossible, to access without the passcode. The BFU state ensures that even brute-force attacks are severely hampered, as the device's main encryption keys are not derived until the passcode is entered. Magnet Forensics' claimed ability to maintain an AFU state effectively neutralizes this safeguard, granting law enforcement a longer window to extract data that would otherwise become inaccessible. This includes data like cached locations, recently deleted iMessages, and photos, which the new tools also purportedly prevent from automatic deletion. The implications for individuals whose devices are seized are profound, as the window for Apple's security to re-engage and protect their data appears to be circumvented.

The history of digital forensics is replete with this kind of technological arms race. The 2016 Apple-FBI encryption dispute over a locked iPhone 5C from the San Bernardino shooting, where the FBI demanded Apple create a "government OS" backdoor, highlighted the fundamental tension between national security and user privacy. Apple famously resisted, arguing that such a backdoor would compromise the security of all its users. Since then, companies like Grayshift (the developer of GrayKey) and Cellebrite have emerged as key players, providing tools to law enforcement agencies globally for accessing locked devices. While leaked 2024 documents suggested GrayKey's effectiveness against iOS 18+ was limited to partial access, and courts are increasingly scrutinizing evidence obtained via these methods under stricter Daubert standards, the new Magnet Forensics capability represents a significant leap forward for forensic acquisition. Cellebrite also claims comprehensive device access, including AFU and BFU states on the latest iOS versions, and offers services for a fee that can be as low as $1,500 per unlock. Android devices, while also subject to forensic tools, often present a different set of challenges and opportunities for law enforcement, with some offering more open-source approaches to security and others, like Google's Pixel phones, adopting similar inactivity reboot features to iPhones.

Apple's security architecture, centered around the Secure Enclave Processor (SEP), is designed to isolate and protect cryptographic keys and biometric data, making it extremely difficult to extract sensitive information even if the main processor is compromised. Features like USB Restricted Mode and Lockdown Mode (introduced in iOS 16) further harden devices against physical attacks and sophisticated cyber exploits. However, the reported success of GrayKey Preserve suggests that forensic companies continue to find ways to exploit transient states or subtle vulnerabilities. The specific technical details of how Magnet Forensics achieves this bypass remain undisclosed in the leaked video, though researchers speculate it could involve clock manipulation or disabling internal iPhone tasks that trigger data expiration.

Looking ahead, this development will undoubtedly provoke a strong response from Apple. The company consistently emphasizes privacy as a core tenet and invests heavily in security enhancements, as evidenced by its rapid patching of zero-day vulnerabilities like CVE-2026-86950, a CoreGraphics flaw actively exploited in targeted attacks on iOS 26. Apple's next move will likely involve identifying the technical mechanism behind GrayKey Preserve and releasing iOS updates to counteract it, continuing the perpetual cycle of security and circumvention. This ongoing battle underscores the broader societal debate about digital rights, law enforcement access, and the limits of encryption. Governments, facing an increasingly "going dark" problem where end-to-end encryption makes communication content inaccessible, are also exploring legislative avenues to compel access or are resorting to purchasing data from brokers, circumventing warrant requirements. The emergence of AI-powered police tools capable of rapid processing of seized devices further intensifies this landscape. For users, the message is clear: while Apple strives to build a "fortress", the vigilance required to protect digital privacy remains paramount, necessitating strong passcodes, regular software updates, and an understanding of the evolving capabilities of forensic tools.

Sources