Report: GrayKey Bypasses Apple's Inactivity Reboot, Keeping iPhones in Weaker Security State
GrayKey reportedly bypasses Apple's Inactivity Reboot, keeping iPhones in a weaker security state and recovering purged data.
Inactivity Reboot automatically restarts an iPhone after 72 hours without an unlock, moving it into a state called Before First Unlock, or BFU. In BFU, certain sensitive data is protected by encryption keys that are not released until the user enters the device passcode. After the first unlock, the iPhone enters After First Unlock, or AFU, a less secure state in which GrayKey can more easily access data.
404 Media uncovered a leaked video from Magnet Forensics. In the video, the company claims a new device called GrayKey Preserve can freeze an iPhone in AFU mode, according to the report. The video also claims AFU status is maintained even if the iPhone restarts. The report says this gives GrayKey easier access because the device is not as strongly encrypted as it would be in BFU mode.
GrayKey Preserve and a related mode for the standard GrayKey, called Evidence Preservation Mode, can recover material that iOS automatically purges after a certain period, according to the report. That material includes location data, iMessages, and deleted images. In the leaked video, a Magnet employee says, “We’re gonna be able to preserve that data for an infinite amount of time,” according to 404 Media.
The leaked video did not show Magnet Forensics' technical solution in detail, the report says. An employee hinted that enabling Airplane Mode and blocking radio transmissions, including Wi-Fi, Bluetooth, and cellular, could play a role. Security expert Jiska Classen told 404 Media that the new GrayKey might be manipulating iOS's built-in clock, slowing down time for investigators or stopping the clock from ticking entirely. That would indefinitely prevent Inactivity Reboot and iOS's automatic deletion workflows from running.
According to 404 Media, the video is dated to at least early 2025, suggesting the exploit has been in use since then. The report did not say whether Apple has responded or released a fix.
Apple has publicly opposed efforts to weaken iPhone protections. The company says it complies with legitimate police requests, but it has worked to block tools such as GrayKey and has resisted law enforcement requests to build a backdoor into its operating systems. Apple has argued that a backdoor designed for good actors could be exploited by hackers, stalkers, identity thieves, and others. iPhones hold highly private data, including credit card details, medical records, and personal photos, and the devices are used by billions of people worldwide.
The report also notes that tools like GrayKey have been used by authoritarian regimes and hostile nation states to suppress free speech and harass critics, according to the article. Apple has faced criticism for concessions to repressive governments in countries such as China and Russia, but building an iOS backdoor is apparently a step too far for the company. In the past, Apple has moved quickly to patch exploits used by Magnet Forensics and its competitors. The 404 Media report is likely to prompt urgent work on a fix in Cupertino, but the fact that the vulnerability has reportedly been exploited since at least early 2025 will be troubling for people inside and outside Apple.