The phone has been sitting in a Faraday bag for two days. Nobody has touched the screen. That idle stretch is a cybersecurity control Apple marketed as an inactivity reboot: after 72 hours unused, the handset restarts into a colder state, keys drop out of memory, and brute-force tools have a harder night. Then the extraction cart rolls up with a mode that has no interest in letting that clock complete.
If the 404 Media reporting Bruce Schneier flagged this week holds, Magnet Forensics has a way to keep iOS from running that automatic reboot. The company already sells GrayKey to law enforcement for unlocking phones. The new kit is called GrayKey Preserve, with Evidence Preservation Mode on existing boxes. Time without a user is no longer time working for you.
The reboot was a bet on patience
Apple built the inactivity reboot as security hardening with a calendar. Leave the device unused long enough and it returns toward a Before First Unlock posture, where data-protection class keys are not sitting in RAM waiting for a lab. That helps against offline guessing. It also helps against extractors that need a warm, after-first-unlock session. You already tell users that a lock screen buys time. This feature tried to buy time after they walked away from the phone.
The design assumes idle means idle. It also assumes nobody with physical custody will spend those 72 hours keeping the device in a useful forensic state. Defense in depth was supposed to cover the rest: passcodes, USB restrictions, Stolen Device Protection, remote lock. The reboot was the delayed closer, the control you invoke when the user is gone and the MDM ping might not land.
You cannot run threat detection against a phone in a bag. Your SIEM will not get a beacon. Cyber security teams still write the stolen-device step as “wait for the safer state.” That sentence is now the problem. A clock the holder can stall is a courtesy, not containment.
Preserve mode bought the lab a warm phone
Schneier describes a vendor in the cyber-weapons business exploiting a possible iOS flaw so the inactivity reboot never lands. GrayKey is already familiar to anyone who does mobile incident response. Agencies buy it to unlock and image iPhones and Android devices. Preserve and Evidence Preservation Mode exist to hold the handset in the state the lab wants, which is the state Apple tried to expire.
Treat that as a product requirement. If a commercial extractor can pause the safer-state transition, every playbook that says “if we cannot wipe it, wait 72 hours” donates dwell time. The phone can look untouched and remain fully useful to the party holding it. Your firewall never sees that session. Your threat-protection catalog will not name the dongle as malware. Physical access just got a maintenance mode, and the maintenance is the point.
This is a bad look for any program that treated Apple’s timer as a substitute for revoke-and-wipe. The feature still has value against a thief who tosses a phone in a drawer. It has much less value against a party whose job is to keep the drawer from getting cold.
Other safety windows failed the same way
CrowdStrike this week walked through a pattern it labels Request, Aggregate, Bypass. Attackers split a disallowed goal across multiple LLM turns so safety classifiers that score one prompt at a time miss the assembled intent. Windowed inspection fails when the other side decides how the window closes. Apple’s reboot is a 72-hour window. The classifier is a one-request window. Both look decisive until someone preserves or fragments state inside them.
Retail got a noisier version of the same lesson. Malwarebytes reported that ASOS customers received push notifications about a company breach, messages that read like they came from inside the relationship. When the last-mile channel still delivers, you do not get to pick the moment the story starts.

Incident response starts when the device or the user is reachable, not when your timer says the risk expired.
Revoke before the clock does your cybersecurity job
Do not wait 72 hours to act on a missing phone, tablet, or token-bearing laptop. Immediate work is revoke-first. Kill SSO sessions, refresh long-lived tokens, rotate mailbox and VPN credentials tied to that user, and push a remote wipe from MDM while the device might still check in. If wipe confirmation never returns, assume After First Unlock until you have evidence of a reboot or a cryptographic reset. Disable the hardware credential in the identity provider. Pull the device certificate. Treat the passcode as burned.
Pair that with a stolen-device call tree that does not stall on forensics. Legal can argue about imaging later. Your job is to shrink the live identity attached to the metal. If the user had an authenticator on that handset, bounce them to a new factor before the next login window. If they used the phone as a jump into production Slack, mail, or a cloud console, hunt those sessions the way you would hunt a stolen laptop. Brute-force against a cold reboot is a lab problem. Session reuse from a warm phone is your production problem.
Ongoing, rewrite the control. Timeouts, inactivity reboots, and LLM safety classifiers are layers. They are not containment. Put stolen-device drills on the same cadence as a phishing tabletop: lost iPhone on a Friday, no MDM check-in, user still has chat on that device. Measure how many minutes until tokens die. Add detections for impossible travel and new device enrollments after a loss ticket. Keep USB restricted mode and Stolen Device Protection enabled, then document that those flags slow a kit; they do not cancel a Preserve-style hold. For AI tools, stop grading a single prompt. Log tool calls, concatenated user turns, and data egress as one incident object, the way CrowdStrike’s bypass write-up implies you must.
Security hardening here is boring on purpose. Inventory which apps store long-lived tokens on iOS. Cut those lifetimes. Require re-auth for payroll, identity admin, and production consoles from a managed browser, not from a personal Safari session a lab can keep warm. Defense in depth means the reboot can fail and you still win because the account is already dead.
Sources
- Possible Vulnerability in Apple’s Automatic Reboot
- Request, Aggregate, Bypass: How Attackers Can Evade LLM Safety Classifiers
- ASOS “hackers” send push notifications to customers
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
