Breaking
SecurityDeveloping Story

GrayKey Freezes iPhone Lock State

Leaked video shows Magnet Forensics can keep iPhones in a less-secure state, potentially exposing private data to tooling built for police.

··2 hours ago·4 min read
black Android smartphone at 16:55
Photo by Todd Jiang on Unsplash

A leaked video appears to show that a forensics firm working with law enforcement has found a way around one of the iPhone's most important protections for your private data. The company behind the GrayKey device has developed a workaround that keeps an iPhone in a weaker encryption state, according to reporting by 404 Media. If the claim holds up, it complicates the security model Apple has built around the passcode and the automatic protections that kick in when a phone sits idle.

What Inactivity Reboot Does

Apple's iOS includes an Inactivity Reboot feature that restarts an iPhone automatically if it hasn't been unlocked for 72 hours. The restart pushes the device into a state called Before First Unlock (BFU). In BFU, certain sensitive data is encrypted with keys that aren't released until you actually enter your passcode.

Once you log in, the iPhone moves to a less restrictive state known as After First Unlock (AFU). Data is more accessible in AFU, which is why forensic tools want to keep a phone there rather than let it reboot into BFU.

The tension is straightforward: Apple designed Inactivity Reboot to shrink the window in which a seized or stolen phone can be mined for data, and the new GrayKey workaround is aimed at keeping that window open.

The Leaked Video and GrayKey Preserve

According to 404 Media, the revelation comes from a video that shows Magnet Forensics, the company behind GrayKey, describing a new device called GrayKey Preserve. In that video, the company claims it can freeze an iPhone in AFU mode, maintaining that state even through a restart.

Holding a phone in AFU gives GrayKey easier access to device data because it is not as strongly encrypted as it would be in BFU. The video was seen by 404 Media and dated to early 2025, which suggests the capability has been in use since at least then.

Recovering Data iOS Would Normally Purge

The reporting goes beyond the lock-state question. GrayKey Preserve — and a related mode for the standard GrayKey called Evidence Preservation Mode — can reportedly recover material that iOS automatically purges after a set period. That includes location data, iMessages, and deleted images.

In the video, a Magnet employee describes the retention goal in blunt terms.

We're gonna be able to preserve that data for an infinite amount of time

— a Magnet employee, speaking in the leaked video

The video does not lay out Magnet Forensics' technical approach in full. An employee hints that enabling Airplane Mode and blocking radio transmissions — Wi-Fi, Bluetooth, and cellular — could be part of the method.

Manipulating the Clock

Security expert Jiska Classen told 404 Media that the new GrayKey might be manipulating iOS's built-in clock. By slowing down time or stopping the clock from ticking entirely, the tool could indefinitely prevent Inactivity Reboot and iOS's automatic deletion workflows from running.

If that is what is happening, it would explain how the device stays in AFU mode across a restart: the timer that triggers the reboot and the purge routines never reaches its threshold.

Apple's Security Stance

Apple is well known for the security posture of its devices and for resisting efforts to weaken the protections it gives users. According to the reporting, Apple says it complies with legitimate police requests, but it has actively worked to thwart tools like GrayKey from accessing iPhone data. It has also pushed back on law enforcement requests to build a backdoor into its operating systems.

Part of Apple's stated justification is that a backdoor that only works for the good guys doesn't exist. Any software flaw can be exploited by hackers, stalkers, identity thieves, and other bad actors. With highly private data — credit card details, medical records, and personal photos — on billions of iPhones worldwide, the company has framed that risk as one it isn't willing to take.

The reporting also notes that tools like GrayKey are known to be used by authoritarian regimes and hostile nation-states to suppress free speech and harass critics. Apple has drawn criticism for making concessions to repressive governments in countries like China and Russia, but building an iOS backdoor for them is apparently a step too far for John Ternus's company.

Patch Cycles and Patch Gaps

Historically, Apple has moved quickly to patch exploits used by Magnet Forensics and its competitors. The report suggests 404 Media's findings will have rung alarm bells in Cupertino and prompted work on a fix.

But the claim that the vulnerability has been actively exploited since at least early 2025 is the uncomfortable part. It implies a gap between when a workaround was in use and when Apple might close it, and that gap is measured in months, not days.

The source material doesn't specify which iOS versions are affected, how many devices are in scope, or what a fix would look like. What it does establish is that a device built for law enforcement has been described, in a leaked video, as holding iPhones in a weaker state and retaining data iOS was designed to delete.

Why It Matters for the Rest of Us

The immediate read is about police access, but the same capability sits inside a commercial product. If a tool can freeze an iPhone in After First Unlock and stop the clock on automatic deletions, then the practical protection of Inactivity Reboot depends on Apple closing this specific gap — and on how quickly it does so.

For anyone who carries an iPhone, the takeaway is that the strongest protections are only as good as the last patch. The iOS security feature that automatically reboots an idle device is one layer among several, and this report suggests that layer has been worked around. Whether that remains true after Apple's next round of fixes is the question the company now has to answer.

#iphone#graykey#ios security#magnet forensics#mobile forensics

Sources

Iliyas

Founder & Editor, Xploitwire

This article was written and reviewed against the sources listed above before publication, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories