A newly circulated training video appears to show how law enforcement officers can bypass a key Apple security feature that protects data on locked iPhones. The revelation comes amid ongoing concerns about the balance between digital privacy and investigative powers.
Since 2024, Apple has included an inactivity reboot function in many iPhone models. This security measure automatically restarts the device if it remains locked for more than 72 hours, a step designed to make forensic access significantly more difficult for investigators. Previously, this meant that information stored on smartphones that had been inactive for three days or more became largely inaccessible to police.
According to a report by 404 Media, the training video showcases capabilities within software made by Magnet Forensics, a company best known for its GrayKey tool sold to law enforcement agencies to unlock smartphones. The footage allegedly demonstrates a workaround for the inactivity reboot in both a new GrayKey Preserve tool and an Evidence Preservation Mode.
While the video does not explicitly detail the technical mechanism behind the bypass, 404 Media suggests that Magnet Forensics has found a way to place the device into an “After First Unlock” (AFU) state. In forensic terms, the AFU state allows for greater data access compared to the “Before First Unlock” (BFU) state. In BFU mode, the device is more heavily encrypted and protected, making it far more difficult for anyone other than the owner to retrieve information.
A representative from Magnet Forensics is quoted in the training material stating, “Even if that device does reboot for any number of reasons, memory maintenance or the power is lost or whatever, the AFU state is not lost.” Another comment in the video described the development as “an absolute game changer for iOS forensics and a function that I wish we had years ago.”
Additionally, the new tools are reportedly designed to counteract automatic iPhone features that delete certain types of data after a set period. This includes cached location data, recently deleted iMessages, and photos, which are typically purged after several days.
The potential expansion of forensic capabilities raises significant privacy questions. It occurs against a backdrop where both local and federal agencies have faced accusations of pushing the boundaries of citizens’ digital rights. Recent controversies have involved the use of facial recognition technology, the misuse of surveillance tools by Customs and Border Protection, and allegations that federal entities have accessed location data through subpoenas.
Wait, so cached data survives even after reboot? That contradicts what I thought I knew about AFU states.
Does Apple know about this bypass yet? If they do, I expect a patch to close this loophole very soon.
As an investigator, this is exactly the kind of tool we needed for cold cases. Privacy shouldn’t override justice.
This feels like a major breach of user trust. I thought the 72-hour reboot was a solid safeguard against forced extraction.