Possible Vulnerability in Apple’s Automatic Reboot
BLUF
A new exploit allows law enforcement tools to circumvent iOS security timeouts and access locked devices.
NEWS
404Media reports Magnet Forensics is exploiting a vulnerability in iOS to bypass the automatic reboot feature designed to secure inactive iPhones. The company released a device called GrayKey Preserve specifically to maintain access for law enforcement agencies using GrayKey tools. This undermines the security guarantee that devices become more protected after three days of non-use.
Why I Care
This compromises the privacy and data security of iPhone users who rely on inactivity timeouts to protect against physical access attacks. It affects anyone concerned about law enforcement surveillance or physical device theft where the device might be left unattended for extended periods.
Next Steps
iPhone users should ensure devices are physically secured at all times and update to the latest iOS version immediately upon release; enterprise security teams should assess physical device policies for high-risk personnel; Apple users must monitor official advisories for patches addressing the GrayKey Preserve exploit.
Source: Schneier on Security ·