Magnet Forensics Bypassed Apple Inactivity Reboot Security

The new tool maintains iPhone access for law enforcement by preventing the device from entering a locked state.

Updated on Oct. 1, 2026 in Cybersecurity

Isometric editorial illustration of a metallic forensic interface port connected to a data cable, representing smartphone security bypass technology.
Magnet Forensics has released GrayKey Preserve, a tool that circumvents Apple’s 2024 inactivity reboot feature to keep seized iPhones in an accessible state. AI Illustration. Upload story photo >

Live Poll

Should law enforcement have the ability to bypass smartphone security encryption to access seized devices?

Magnet Forensics has developed GrayKey Preserve, a tool that circumvents Apple’s 2024 inactivity reboot security feature. This technology allows law enforcement agencies to keep seized iPhones in an After First Unlock (AFU) state to maintain data access.

Why it matters

The development provides a workaround for police departments that previously faced significant data encryption challenges once a device remained inactive for 72 hours. It addresses a specific security hurdle introduced by Apple to protect data on seized or lost hardware.

GrayKey Preserve maintains the After First Unlock (AFU) state on iPhones by forcing the device into Airplane Mode, which eliminates wireless connectivity that could trigger a security event. The tool bypasses the 72-hour inactivity threshold that Apple implemented in 2024 to force a reboot and higher-level encryption.

The players

Magnet Forensics

A developer of digital investigation tools used by law enforcement to extract and analyze data from mobile devices.

Apple

A global technology company that designs the iOS mobile operating system and hardware security features for iPhones.

The details

GrayKey Preserve utilizes a mechanism that cuts off external communication to ensure the iPhone remains in its active session state. By triggering Airplane Mode, the tool prevents the device from receiving remote signals that might interact with the system's security protocols. This method specifically targets the 2024 Apple inactivity reboot feature, which normally secures data after 72 hours of non-use by transitioning the device into a more restrictive encryption state known as Before First Unlock (BFU).

Timeline

  1. 2024: Apple introduced the inactivity reboot security feature for iOS.

  2. 72 hours: The duration of inactivity before an iPhone reverts to a more secure encryption state.

The Tech Race

This development marks a new phase in the ongoing cycle between Apple's security hardening and forensic tool capabilities. It follows the industry pattern where manufacturers implement stricter privacy protections that law enforcement entities then seek to circumvent through specialized software.

This tool is currently limited to use by law enforcement agencies already utilizing the broader GrayKey platform. It changes the capability of forensic investigators to access data on seized devices that would have otherwise triggered an automatic security reboot.

The takeaway

The move by Magnet Forensics highlights the continued tension between device-level encryption and law enforcement investigative needs. Analysts should monitor future iOS updates to determine if Apple releases further modifications to the 72-hour reboot policy in response to this capability.

Further reading

For broader trends in mobile device security and law enforcement software, visit the Cybersecurity section.

Live Poll

Should law enforcement have the ability to bypass smartphone security encryption to access seized devices?