GrayKey reveals new feature: iPhones seized by police may remain “evidence-obtainable” for a long time

📅 2026-10-02

Abstract:

Apple has continuously strengthened the data security mechanism of the iPhone in recent years. One of its important measures is to automatically restart the device that has not been unlocked for a long time, so that after the phone is seized by the police or other personnel, it can increase the difficulty of data extraction by changing the encryption status of the device. However, newly exposed information shows that Magnet Forensics, the developer of the well-known mobile phone forensics tool GrayKey, seems to have found a way to bypass this mechanism, allowing the seized iPhone to remain in a state that makes it easier to conduct data forensics for a long time.

This news comes from a training video for law enforcement obtained by 404 Media. The video appears to be made in early 2025, in which Magnet Forensics demonstrates a new device called GrayKey Preserve, as well as the Evidence Preservation Mode feature in existing GrayKey devices. In the video, Magnet staff hailed the feature as a major change in the field of iPhone forensics and said it could solve the problems Apple's "inactive restart" mechanism has caused law enforcement.

Apple will add the "Inactivity Reboot" function to iOS 18.1 released in 2024. If the iPhone is not unlocked by the user for 72 consecutive hours, the system will automatically restart the device. This is not a scheduled restart in the ordinary sense, but will change the security state of the phone, thereby improving the protection of the data in the device.

To understand this mechanism, you need to first understand the two important security states of the iPhone. After the device restarts, it is in the "Before First Unlock" (BFU) state before the user enters the password for the first time. At this stage, some of the encryption keys are still unavailable, making it more difficult for law enforcement to access sensitive data on the phone, even if they have specialized forensic tools.

When the user enters the password to complete the first unlock, the device enters the "After First Unlock" (AFU) state. In this state, more data and keys have been loaded into the system, so some forensic operations become much easier. As long as the device remains running and does not enter the BFU state again, some forensic tools have more room to operate.

One of the practical implications of Apple adding a 72-hour automatic restart mechanism is that even if the seized iPhone has just been in the AFU state, it will not remain in this state indefinitely. Suppose the police seize an iPhone but need to wait for a search warrant, transport the equipment, or queue for digital evidence collection. After 72 hours, the phone automatically restarts and may re-enter the BFU state, making it more difficult to crack.

GrayKey Preserve seems to be designed for this mechanism.

According to the exposure video, Magnet Forensics claims that GrayKey Preserve can "capture" the current AFU status of the iPhone after obtaining preliminary access permissions. Even if the phone is restarted later due to normal maintenance, restarting, or battery exhaustion, the original AFU state will not be lost.

Magnet employees even said in the video that this means that even if the device reboots, the saved AFU state can still be restored. In other words, Apple's original mechanism of automatically restarting the device in 72 hours to re-enter a safer BFU state may lose some of its effect.

However, the outside world currently does not know what technology GrayKey Preserve uses to achieve this goal. The exposure video does not disclose specific vulnerabilities, attack methods or codes, so it cannot be determined whether it exploits security vulnerabilities in iOS, system time mechanism, data life cycle management mechanism, or other undisclosed technologies.

Hasso Plattner Institute researcher Jiska Classen, who studies iPhone security, raised some possibilities after seeing relevant materials. She believes that Magnet may have found a way to manipulate the device's time, such as making the system think that time is not advancing forward normally, thereby preventing the execution of system tasks responsible for triggering automatic restarts or data expiration. Another possibility is to directly block certain background tasks responsible for data lifecycle management.

However, these are just speculations made by security researchers based on the content of the video and have not been confirmed by Magnet Forensics. Therefore, it is currently not possible to determine which vulnerability GrayKey Preserve exploited.

In addition to the 72-hour automatic restart, Magnet also claims that Evidence Preservation Mode can prevent some data from being automatically deleted according to the normal iOS life cycle.

This includes cached location data, recently deleted photos, recently deleted iMessages, etc. According to the exposure video, under normal circumstances, these data may be cleared by the system after a certain period of time, but Evidence Preservation Mode can keep them in a forensic state for a long time.

This means that the goal of GrayKey Preserve is not just to "prevent the phone from restarting", but to try to put the seized iPhone into a long-term frozen forensic state. Law enforcement officials can protect the current data state of the device and wait for a search warrant or other legal process to be completed before deciding whether to proceed with the actual data extraction.

To prevent the phone from continuing to communicate with external networks, GrayKey Preserve also turns off cellular networks, Wi-Fi, and Bluetooth after gaining initial access. Magnet said that even if the phone cannot normally turn on airplane mode or turn off wireless communications through the iOS control center, GrayKey can actively turn off these wireless connections after obtaining initial access.

This feature also has a very important privacy implication: once the device is obtained by the police and enters this "protected state", the phone's ability to communicate with the outside world may be cut off. This prevents data from being changed remotely and reduces the possibility of the device being remotely wiped or other remote operations affecting the forensic process.

It needs to be emphasized that GrayKey is not a mobile phone unlocking software that ordinary consumers can buy, but a professional digital forensics tool for law enforcement agencies. Magnet Forensics previously stated that GrayKey has been used by more than 1,200 law enforcement agencies and 40 countries and regions around the world.

GrayKey itself has long been in a "cat-and-mouse game" between Apple and law enforcement. Apple continues to patch iOS security holes, while forensics companies continue to find new vulnerabilities or ways to obtain data from locked devices. GrayKey has been able to fully access certain iPhones in the past, but as Apple continues to update iOS, the scope of the data it can obtain will change.

Data exposed in 2024 showed that GrayKey could only obtain "partial" access to most devices running iOS 18 and iOS 18.0.1 at that time, and there were obvious differences in forensic capabilities between different iPhone models and iOS versions. After Apple subsequently launches new security mechanisms, forensic tools will also need to find new breakthroughs.

The most special thing about GrayKey Preserve this time is that it does not seem to simply find a new way to directly crack the iPhone password, but tries to "save" this state when the device is already in the AFU state. In this way, the police do not have to complete all evidence collection work immediately after the mobile phone is seized, but can first fix the status of the device and wait for subsequent legal procedures.

However, there is currently no public evidence that this feature can be effective on all iPhones and all iOS versions. The exposed video itself also appears to have been produced in early 2025, so it is unclear whether this technology has been officially made widely available to law enforcement agencies, or whether Apple has patched related issues in subsequent iOS updates.

It is also uncertain what conditions GrayKey Preserve needs to work successfully. If it has to work when the device is in a specific state, on a specific iOS version, or already has some level of initial access, there's still a big difference between it and "can directly hack any locked iPhone."

Neither Apple nor Magnet Forensics has publicly commented on the exposure video. Therefore, it is more accurate to say at this stage that Magnet appears to have developed a forensic preservation solution for the iPhone's "inactive restart" mechanism, rather than that it has confirmed that it can crack all modern iPhones without restrictions.

From the perspective of security mechanism design, this incident once again reflects the continuously escalating technical confrontation between Apple and the mobile phone forensics industry. Apple automatically restarts within 72 hours to actively enter a safer BFU state for iPhones that have been idle for a long time; while Magnet attempts to save the original AFU state of the device before the restart occurs.

If Magnet's related technology can indeed work stably, then it will at least weaken the actual effect of "72-hour automatic restart" as a forensic protection measure. Apple may need to further analyze the implementation of GrayKey Preserve and prevent it from maintaining or restoring the AFU state through iOS updates.

However, even if GrayKey can bypass this security mechanism, it does not mean that the iPhone's complete encryption system has failed. BFU and AFU are just different states in the iPhone data protection system. The specific data that can be extracted still depends on the device model, iOS version, whether there are exploitable vulnerabilities, password complexity, and the forensic capabilities currently supported by GrayKey.

Therefore, what is really noteworthy about this exposure is not that "the police have been able to crack all iPhones", but that Apple's 72-hour automatic restart mechanism is specially designed to delay and limit digital forensics. It seems that it has once again entered a technical attack and defense cycle with professional forensic tool manufacturers.

Related tags

Related articles

Comments

0/500
Captcha (click to refresh)
No comments yet