Screenshot of iPhone settings showing the automatic reboot after 72 hours of inactivity

Possible Vulnerability in Apple’s Automatic Reboot

Apple’s iPhone automatic reboot, designed to lock a device after 72 hours of inactivity, is being bypassed by a forensic tool that can keep a dormant phone fully accessible. The technique, demonstrated by Magnet Forensics’ GrayKey Preserve and its Evidence Preservation Mode, threatens the privacy expectations of any user who relies on that inactivity lock to protect lingering data.

How the Inactivity Reboot Feature Works

The iOS inactivity reboot automatically puts the device into a hardened state after 72 hours without user interaction, limiting background processes and encrypting volatile memory. This behavior is intended to reduce the attack surface for devices that sit idle for extended periods, such as lost or confiscated phones. By forcing a reboot, Apple ensures that cached credentials, temporary files, and certain logs are cleared before the next power‑on.

Apple’s implementation also triggers a secondary safeguard that erases cached location data, recently deleted photos, and iMessages after a predefined retention window. The erasure is meant to protect users from forensic recovery of sensitive information that they have deliberately removed. When the device reboots, these data stores are overwritten, making recovery practically impossible without exploiting a flaw.

The GrayKey Preserve Bypass

Magnet Forensics, the maker of the law‑enforcement tool GrayKey, unveiled a new device called GrayKey Preserve that can prevent the automatic reboot from entering its secure state. The accompanying Evidence Preservation Mode disables the reboot trigger and the automatic data‑deletion routines, allowing an analyst to keep the phone’s volatile state intact indefinitely. In a leaked video, a Magnet employee called the capability “a function that I wish we had years ago,” highlighting its forensic value.

The device works by injecting low‑level commands that keep the iOS kernel from recognizing the inactivity timer, essentially freezing the system’s power‑management logic. By doing so, it preserves cached locations, deleted media, and iMessage fragments that would otherwise vanish after the reboot. This method transforms a privacy‑preserving feature into a data‑retention loophole that can be weaponized by any party with access to the GrayKey hardware.

Implications for Privacy and Security

For ordinary users, the existence of a tool that can nullify Apple’s inactivity lock means that a stolen or seized phone may remain fully exploitable far beyond the intended protection window. The ability to retain deleted content indefinitely raises concerns about long‑term surveillance and the erosion of “right‑to‑be‑forgotten” expectations. Even though the technology is marketed to law‑enforcement agencies, its availability to other actors could broaden the threat landscape.

From a defensive standpoint, the discovery that Apple engineers are now aware of the flaw suggests a patch may be forthcoming, but the timeline is uncertain. In the interim, users cannot rely on the automatic reboot as a sole safeguard against forensic extraction, especially if the device falls into hands equipped with GrayKey Preserve. The episode underscores how quickly a security feature can become a liability when a specialized exploit is introduced.

What This Actually Means For You

  1. Do not assume that a phone left untouched for three days is automatically secure; the inactivity reboot can be disabled by advanced forensic tools.
  2. Deleted photos, iMessages, and location caches may be recoverable indefinitely if an attacker employs GrayKey Preserve, negating the expectation of data erasure.
  3. Apple’s response will likely involve a software update, but until it arrives, consider manual lockout practices such as powering down the device or using strong passcodes.
  4. Law‑enforcement access to GrayKey devices means that a subpoena could compel the use of this technology on seized iPhones, potentially exposing personal data beyond what the user intended to retain.
  5. Awareness of this vulnerability should inform your risk assessment when handling sensitive information on mobile devices, especially in high‑stakes environments.

Immediate Action Steps

Until Apple releases a fix, the most reliable mitigation is to manually power off the iPhone when it will not be used for extended periods. Turning the device off forces a full hardware shutdown, which cannot be intercepted by the GrayKey Preserve bypass that relies on an active operating system.

Additionally, enable a strong alphanumeric passcode and consider encrypting sensitive files with third‑party apps that store data in containers inaccessible to iOS’s standard forensic pathways. These measures raise the effort required for any tool, including GrayKey, to extract usable information.

Frequently Asked Questions

Can GrayKey Preserve keep an iPhone from rebooting after 72 hours?

Yes. The leaked demonstration shows the device disables the inactivity reboot timer, allowing the phone to stay in its current state indefinitely.

Does the tool also stop automatic deletion of cached data?

According to the video, Evidence Preservation Mode blocks the routines that erase cached locations, recently deleted photos, and iMessages after a set period.

Is there a software update from Apple that fixes this flaw?

Apple engineers are now aware of the issue, but the source does not confirm a patch has been released; users must rely on manual power‑off and strong passcodes for now.

What Do You Think?

Given that a forensic tool can nullify Apple’s built‑in inactivity safeguards, should users continue to trust default OS security features, or is a more proactive personal security regimen now essential?

Back to blog

Leave a comment

Please note, comments need to be approved before they are published.