Report Claims Cops Breached One of iOS’ Most Secure Features and Could Put Your Private Data at Risk
- Police can bypass one of iOS’s strongest security features
- The revelation comes from a leaked video from the creator of the GrayKey device.
- It has worrying ramifications for your data privacy.
A company that works with law enforcement says it has bypassed a key iOS security feature that protects your sensitive information from being taken from your iPhone without your permission. But it could be a step backwards for user privacy and the security of their personal data.
According to a report from 404 Media, Magnet Forensics, the company behind the GrayKey device that police use to unlock iPhones, has developed a new solution that allows anyone with a GrayKey to bypass Apple’s inactivity reset feature, and much more. And it has been using this exploit since at least early 2025, when a video seen by 404 Media was dated.
Idle Reset is an iOS feature that automatically restarts your iPhone if it hasn’t been unlocked within 72 hours. This puts you in a more secure state called Before First Unlock (BFU), which protects certain sensitive data with encryption keys that aren’t released until you enter your device’s password. After signing in, your iPhone enters a less secure state called After First Unlock (AFU).
Latest videos ofTechnologyRadar
In a video discovered by 404 Media, Magnet Forensics claims that it can now freeze the iPhone in AFU mode using a new device called GrayKey Preserve, and that AFU mode apparently remains even if your iPhone is rebooted. That frozen state gives GrayKey easier access to the device’s data because it is not as strongly encrypted as in BFU mode.
Additionally, GrayKey Preserve, and an associated mode for regular GrayKey called Evidence Preserve Mode, can recover materials that iOS automatically deletes after a certain period, including location data, iMessages, and deleted images. “We will be able to retain that data for an infinite amount of time,” a Magnet employee says in the leaked video.
The video did not reveal Magnet Forensics’ technical solution in detail, but one employee hinted that enabling Airplane Mode and blocking radio transmissions (including Wi-Fi, Bluetooth, and cellular) could play a role. And security expert Jiska Classen told 404 Media that the new GrayKey could be manipulating iOS’ built-in clock, “slowing down time” for police officers or even “stopping the clock” entirely, thus indefinitely preventing iOS’s idle reset and auto-delete workflows from running.
Apple’s security posture
Apple is known for the security of its devices and its strong stance against weakening the protections provided to its users. While Apple says it complies with legitimate law enforcement requests, it has actively worked to prevent tools like GrayKey from accessing iPhone data. It has also rejected requests from authorities to build a backdoor into its operating systems that police can use.
Why would Apple try to frustrate authorities this way? Well, part of the justification Apple has given is that there is no backdoor that only works for the good guys. Any software flaw can be exploited by hackers, stalkers, identity thieves, and all sorts of other bad actors. Given the highly private data (including credit card details, medical records and personal photos) on billions of iPhones around the world, that’s a serious risk that Apple is unwilling to take.
Additionally, authoritarian regimes and hostile nation-states around the world are known to use tools like GrayKey to stifle free speech and harass critics. Apple has received its fair share of criticism for making concessions to repressive governments in countries like China and Russia, but building an iOS backdoor for them is apparently a step too far for John Ternus’ company.
In the past, Apple has worked quickly to patch exploits used by Magnet Forensics and its competitors, and there’s no doubt that 404 Media’s report will have set off alarm bells in Cupertino and sparked a furious effort to fix it. But the fact that this vulnerability has been actively exploited since at least early 2025 will be disturbing news for people both inside and outside of Apple.
Follow TechRadar on Google News and add us as a preferred source to receive news, reviews and opinions from our experts in your feeds.



Post Comment