A hidden iOS 18.1 upgrade made it harder to extract data from iPhones

Apple Intelligence was the most notable upgrade that arrived on iPhones with the iOS 18 series of updates. But it seems Apple reinforced the security protocols in the background that could prevent bad actors from gaining unauthorized access to iPhones that haven’t been unlocked in a while by their legitimate owner.

Earlier this month, 404Media reported that law enforcement officials are troubled by iPhones that are mysteriously rebooting. Citing a report courtesy of officials in Michigan, the outlet notes that the reboots are hampering the ability to access what’s stored on the phones through brute-force unlock methods.

Recommended Videos

Following the report, Dr.-Ing. Jiska Classen, a wireless and mobile security researcher at the Hasso Plattner Institute, shared on social media about a new iOS 18.1 feature called “inactivity reboot.” It kicks into action when an unlock action is attempted on an iPhone.

Related

  • The iPhone 18 Pro may get a camera feature never before seen on the iPhone

  • iOS 18.2 may make charging your iPhone even easier. Here’s how

  • I did an iPhone 16 Pro Max and Galaxy S24 Ultra camera test. The results shocked me

“While most people won’t have their phone forensically analyzed, many more will have their devices stolen. It protects user data in both cases,” she explained. The whole system is tied to patterns of inactivity, and how a phone taps into a secure state after being restarted.

Specifically, a phone enters a BFU (Before First Unlock) state following a restart. It only exits that stage after the phone has been unlocked. Now, BFU is a critical security measure, as it encrypts files individually on the phone, which means they can be accessed only after the phone has been unlocked.

A Cellebrite device used that is used to extract data from smartphones. Cellebrite

On iPhones, unlocking it after a restart (or the BFU phase) generates a decryption key, which subsequently decrypts the files and allows access to them. “Almost all the content of an iPhone is encrypted until the point when the user unlocks it to enable the phone to start up,” explains Celleberite, a company that makes devices used by law enforcement to extract data from phones.

BFU state doesn’t seem to block access to all data, but it does impose some serious restrictions. “Remember, if you seize an iPhone and it is already powered on, try to keep it that way,” Cellebrite warns investigators in another blog post.

Apple’s new “inactivity reboot” system throws another obstacle in the way of accessing the data on an iPhone even if it hasn’t been unlocked in a while, thanks to the automatic reboot process that puts the phone in BFU mode.

Now, the BFU state itself is not impenetrable on its own. Cellebrite claims that its Premium package — which includes a UFED device and special software — can help extract data from devices in the BFU state.

However, as per a research paper by experts at the Department of Electrical Engineering (Faculty of Engineering, Universitas Indonesia), they could “see just around 40% of the media obtained in BFU locked device extraction” using the Cellbrite Premium system.

Apple hasn’t officially commented on the “inactivity reboot” system that it implemented with iOS 18.1 yet. However, the company still co-operates with law enforcement authorities to unlock iPhones with proper warrant or legal authorization.

Editors’ Recommendations

  • Apple quietly nixed this Apple Intelligence feature from iOS 18.2

  • I’ve had the iPhone 16 Pro for over a month. Here’s why I still love it

  • Why this 3-year-old iOS feature is one of my favorite things about the iPhone

  • These are the real prices of the Pixel 9 Pro and iPhone 16 Pro

  • There’s an easy way to follow election results on your iPhone. Here’s how




Related posts

Latest posts

Black Friday deal: Samsung Galaxy Watch FE for $160

The Samsung Galaxy Watch FE is on sale now at Samsung bringing it down to $160. You can even save an extra $50 with the right trade-in.

Disk Drill vs. DMDE: best no-subscription data recovery app

If you've lost photos, videos, or other important files but don't want a data recovery subscription, one of these apps could be the perfect solution.

There’s a new Samsung Galaxy S25 spec leak, and it’s a bit disappointing

The Samsung Galaxy S25 line isn't going to arrive for another couple of months, but we just got a good look at what to expect for specs.

I can’t believe it! Samsung’s brand-new Chromebook can be yours for just $99!

Samsung made a splash in 2024 with the Galaxy Chromebook Plus, but if you thought the price was too steep,

Walk off the turkey with this EPIC Black Friday smartwatch deal — score 40% off the Ticwatch Pro 5 (while you still can)

As part of its lineup of Black Friday deals, Amazon is carving a record-smashing 40% off the top-rated Ticwatch Pro

Don’t miss out on this Black Friday deal for the best Chromebook tablet

Black Friday sales are already underway, and one surprising inclusion is the Lenovo Chromebook Duet 11. It's on sale basically

My favorite e-reader is on sale for Black Friday but you should buy this one instead

The Onyx Boox Palma is one of the best reviewed e-readers in years, but its Black Friday sale isn't good

iOS 18.1 and Beyond: Siri’s Apple Intelligence Features

With Apple Intelligence, Apple is aiming to make Siri smarter than ever before. The personal assistant is going to be

2024 was a huge rebound for smartphone sales, but not for the iPhone

2024 is proving to be a very good year for increased smartphone sales. However, the same can't be said for the iPhone.

Babbel’s got an Early Black Friday price of just $130 through StackSocial

Study 14 languages for life with a Babbel lifetime subscription on sale for Black Friday. Don't miss out if you want to learn new languages.