Apple’s iPhone inactivity reboot feature was designed to make an unattended phone harder to examine after it has gone without an unlock for more than 72 hours. A newly reported law-enforcement training video, however, indicates that Magnet Forensics may have developed GrayKey tools intended to work around the practical impact of that protection.

The reported capability concerns two products: a new GrayKey Preserve tool and an Evidence Preservation Mode for GrayKey. GrayKey is a smartphone-unlocking product sold primarily to police. The video reportedly describes the feature as a major change for iOS forensic work, but it does not publicly explain the technical mechanism behind it. That limitation matters: the report establishes an alleged capability and the products associated with it, not a complete account of how the capability operates or which iPhones and software versions it affects.

Why an inactivity reboot changes the forensic picture

In 2024, Apple began equipping many iPhones with an automatic reboot function that activates after a device has not been unlocked for more than 72 hours. A restart is consequential because an iPhone’s data protection changes depending on whether it has been unlocked since its most recent boot.

The central terms are Before First Unlock, commonly shortened to BFU, and After First Unlock, or AFU. BFU describes the period after a phone starts up but before the owner has entered the passcode for the first time. In the reported account, more data remains encrypted and the device is more difficult for anyone other than its owner to unlock while it is in that state.

AFU is the condition after the phone has been unlocked at least once following startup. More information can be available to forensic access in AFU than BFU. This distinction is why the inactivity reboot feature has posed an obstacle to investigators in practice: a phone that reboots can shift from the comparatively data-accessible AFU condition to the more restrictive BFU condition before investigators can extract information from it.

That is also why the alleged GrayKey development is significant. The reported video suggests the tools can preserve an iPhone’s AFU state even if the phone subsequently reboots, loses power, or restarts for another reason. If accurate, that would blunt the effect of a security design intended to ensure that an extended period without an unlock moves the phone back into a state where more of its contents are encrypted.

What the reported tools are said to do

Magnet Forensics’ reported training materials identify GrayKey Preserve and an Evidence Preservation Mode as the avenues for this workaround. The public reporting does not spell out whether either feature exploits a vulnerability, relies on a particular connection or procedure, or works across a defined set of iPhone models and iOS releases. Those unanswered questions are not minor technical footnotes. They determine how broad, dependable and durable any real-world capability might be.

Still, the claimed outcome is clear enough to frame the privacy concern. The tools are said to retain the practical advantages of AFU despite a reboot. In plain terms, a reboot would no longer necessarily mean that investigators must begin from the more protected BFU position.

Related coverage includes GrayKey Tools Reportedly Target iPhone Inactivity Reboot Protections.

The video also reportedly says the products can stop certain automatic deletion processes. The examples named are cached location data, recently deleted iMessages and recently deleted photos. Data that software removes on a schedule can be especially time-sensitive in an investigation, whether it is relevant to an allegation or supports an innocent explanation. Preservation tools are built around preventing that information from disappearing before it can be assessed.

But preservation has a second meaning for the public. A cache, a recently deleted message folder and a recently deleted photo area can all contain sensitive information a person reasonably expects to expire under the phone’s normal behavior. The prospect of intervention that pauses or blocks those processes expands the amount of personal material that may remain available after a device is seized.

What is known, and what remains uncertain

The reporting is based on a training video said to have been made for law enforcement. It attributes the AFU-preservation claim to Magnet personnel and identifies the two GrayKey offerings connected to the feature. That is meaningful evidence of what the company is presenting to potential users, but it should not be overstated into a universal claim that every locked iPhone can be opened or that Apple’s protections have been defeated across the board.

  • Reported: GrayKey Preserve and Evidence Preservation Mode are presented as ways to address the consequences of iPhone inactivity reboots.
  • Reported: the approach is described as retaining the AFU state even through a reboot or loss of power.
  • Reported: it may prevent deletion of certain time-limited material, including cached locations and recently deleted messages and photos.
  • Not explained publicly: the underlying method, hardware and iOS coverage, limitations, reliability, or conditions needed for use.
  • Not established by the report: that the capability works on all iPhones, defeats all lock-screen protections, or permits unrestricted access in every case.

This uncertainty is important in cybersecurity reporting because a tool’s marketing claim, a demonstration, and broadly repeatable forensic access are different things. Device security is usually shaped by model-specific hardware, software version, patch status and the exact state of a phone at the time it is taken into custody. The information available here does not resolve those variables.

The practical stakes for phone owners

For ordinary users, the immediate takeaway is not that the inactivity reboot feature has become meaningless. Rather, the report raises the possibility that tools used by police can reduce the protection that feature provides in some circumstances. The core purpose of the 72-hour reboot behavior remains easy to understand: if a device stays untouched long enough, it reboots and requires the owner’s passcode before returning to the more accessible post-unlock state.

The reported GrayKey functionality focuses on preserving access around that boundary. It does not change the broader fact that the initial passcode unlock is an important security event. Nor does the available information provide a consumer-facing setting or a verified mitigation beyond the protections iPhone owners already use.

As ever, keeping a device and its operating system current is a sensible baseline security practice, though this report does not say whether updates block, limit or affect the alleged GrayKey features. Users should be skeptical of anyone claiming this report proves a simple universal bypass, because that is not what has been substantiated.

The broader mobile-device landscape is constantly moving between new security features and new methods of examining devices, alongside the hardware competition represented by products such as Samsung’s Galaxy Buds On. But this case is not principally about consumer gadget rivalry. It is about what happens when security measures designed to protect stored personal data meet tools designed to preserve evidence for investigations.

The report arrives amid continuing concerns that local and federal law-enforcement bodies have pushed against the boundaries of digital privacy. Modern phones may hold location traces, private conversations, photographs and records of everyday activity. Even a narrowly framed preservation capability can therefore have wide implications depending on the scope of a seizure and the safeguards governing analysis.

There is also an essential difference between preserving a device’s existing state and independently deciding what investigators may lawfully search or use. The reporting here concerns technical capacity. Questions about authorization, oversight, evidentiary procedure and the limits on access are separate matters, and no specific legal process is detailed in the available material.

For Apple, the report illustrates a familiar security tension. A feature can make an attack or forensic extraction harder by changing the device state after a period of inactivity, while specialized vendors work to maintain access before that defensive change takes effect—or, as alleged here, to preserve the state that makes more data available even after a restart. Neither the video nor the reporting provides a public technical answer from Apple or a detailed response from Magnet Forensics.

Until more is known, the most accurate reading is narrow but consequential: GrayKey tools are reportedly being positioned to prevent an iPhone inactivity reboot from removing the forensic advantages associated with its post-first-unlock state, while also preserving some data that would otherwise be automatically deleted. The exact reach of that capability remains unclear, but the reported claims sharpen the stakes around phone encryption, digital evidence and personal privacy.