Full Report
404Media is reporting (alternate link) that a cyber-weapons arms manufacturer is exploiting a vulnerability in iOS to bypass its automatic reboot security feature. This is the feature that automatically puts an iPhone into a more secure state if it hasn’t been used for 72 hours. The new technology to get around inactivity reboot was developed by Magnet Forensics, the company behind GrayKey, a popular tool sold to law enforcement agencies that allows them to unlock and access data stored in iPhones and Android smartphones. Magnet has developed a new device called GrayKey Preserve and a feature for its regular GrayKey devices called Evidence Preservation Mode, according to the video...
Analysis Summary
# Vulnerability: Apple iOS Inactivity Reboot Bypass
## CVE Details
- **CVE ID**: Not yet assigned (Zero-day / Proprietary exploit)
- **CVSS Score**: N/A (Estimated High for physical access scenarios)
- **CWE**: CWE-693 (Protection Mechanism Failure)
## Affected Systems
- **Products**: Apple iPhone (iOS)
- **Versions**: Targeted at versions containing the "Inactivity Reboot" feature (iOS 18+ and potentially earlier versions with backported security logic).
- **Configurations**: Devices in a "Before First Unlock" (BFU) or "After First Unlock" (AFU) state that have not reached the 72-hour inactivity threshold.
## Vulnerability Description
The flaw allows a specialized hardware device to intercept or suppress the iOS "Inactivity Reboot" timer. This security feature is designed to automatically reboot an iPhone if it has not been unlocked for 72 hours, transitioning the device from AFU (After First Unlock) to BFU (Before First Unlock) mode. In BFU mode, encryption keys are purged from memory, making file system extraction significantly harder. The exploit—leveraged via a mode called "Evidence Preservation Mode"—prevents this transition, maintaining the device in a state where data remains accessible to forensic unlocking tools for an "infinite amount of time."
## Exploitation
- **Status**: Exploited in the wild (Limited to Law Enforcement/Forensic agencies via Magnet Forensics GrayKey).
- **Complexity**: High (Requires specialized proprietary hardware/software).
- **Attack Vector**: Physical (Requires direct connection to the device's Lightning or USB-C port).
## Impact
- **Confidentiality**: High (Allows persistent access to user data, cached locations, and deleted messages that would otherwise be secured by a reboot).
- **Integrity**: Low (Primary goal is data extraction, not modification).
- **Availability**: None (Does not target system uptime).
## Remediation
### Patches
- **No official patch currently available**: Apple has not released a specific CVE or security update addressing this bypass as of the report date. Users are advised to keep iOS updated to the latest version (currently iOS 18.x) as Apple frequently iterates on anti-forensic measures.
### Workarounds
- **Manual Reboot**: Users concerned about forensic extraction should manually power off or reboot their device if they suspect it may be seized, as this immediately forces the device into the secure BFU state.
- **USB Restricted Mode**: Ensure "Accessories" is toggled **OFF** under *Settings > FaceID & Passcode* to prevent USB communication when the device has been locked for more than an hour.
## Detection
- **Indicators of Compromise**: No software-based IOCs are currently known. Physical evidence of GrayKey/GrayKey Preserve hardware attachment is the only definitive indicator.
- **Detection methods**: Law enforcement forensic logs would be the primary record of this exploitation.
## References
- **404 Media Report**: hxxps[://]www[.]404media[.]co/cops-can-bypass-iphone-automatic-inactivity-reboot-graykey/
- **Schneier on Security Advisory**: hxxps[://]www[.]schneier[.]com/blog/archives/2026/10/possible-vulnerability-in-apples-automatic-reboot[.]html
- **Gizmodo Analysis**: hxxps[://]gizmodo[.]com/cops-may-hav-found-a-way-around-one-of-apples-toughest-iphone-security-features-2000820383