Skip to main content

A hidden iOS 18.1 upgrade made it harder to extract data from iPhones

A person holding the Apple iPhone 16 Plus.
Andy Boxall / Digital Trends

Apple Intelligence was the most notable upgrade that arrived on iPhones with the iOS 18 series of updates. But it seems Apple reinforced the security protocols in the background that could prevent bad actors from gaining unauthorized access to iPhones that haven’t been unlocked in a while by their legitimate owner.

Earlier this month, 404Media reported that law enforcement officials are troubled by iPhones that are mysteriously rebooting. Citing a report courtesy of officials in Michigan, the outlet notes that the reboots are hampering the ability to access what’s stored on the phones through brute-force unlock methods.

Recommended Videos

Following the report, Dr.-Ing. Jiska Classen, a wireless and mobile security researcher at the Hasso Plattner Institute, shared on social media about a new iOS 18.1 feature called inactivity reboot. It kicks into action when an unlock action is attempted on an iPhone.

Please enable Javascript to view this content

“While most people won’t have their phone forensically analyzed, many more will have their devices stolen. It protects user data in both cases,” she explained. The whole system is tied to patterns of inactivity and how a phone taps into a secure state after being restarted.

Specifically, a phone enters a Before First Unlock (BFU) state following a restart. It only exits that stage after the phone has been unlocked. BFU is a critical security measure, as it encrypts files individually on the phone, which means they can be accessed only after the phone has been unlocked.

Cellebrite UFED device.
A Cellebrite device used to extract data from smartphones. Cellebrite

On iPhones, unlocking it after a restart (or the BFU phase) generates a decryption key, which subsequently decrypts the files and allows access to them. “Almost all the content of an iPhone is encrypted until the point when the user unlocks it to enable the phone to start up,” explains Celleberite, a company that makes devices used by law enforcement to extract data from phones.

The BFU state doesn’t seem to block access to all data, but it does impose some serious restrictions. “Remember, if you seize an iPhone and it is already powered on, try to keep it that way,” Cellebrite warns investigators in another blog post.

Apple’s new inactivity reboot system throws another obstacle in the way of accessing the data on an iPhone even if it hasn’t been unlocked in a while, thanks to the automatic reboot process that puts the phone in BFU mode.

Now, the BFU state itself is not impenetrable on its own. Cellebrite claims that its Premium package — which includes a UFED device and special software — can help extract data from devices in the BFU state.

However, as per a research paper by experts at the Department of Electrical Engineering (Faculty of Engineering, Universitas Indonesia), they could “see just around 40% of the media obtained in BFU locked device extraction” using the Cellbrite Premium system.

Apple hasn’t officially commented on the inactivity reboot system that it implemented with iOS 18.1 yet. However, the company still cooperates with law enforcement authorities to unlock iPhones with proper warrant or legal authorization.

Nadeem Sarwar
Nadeem is a tech journalist who started reading about cool smartphone tech out of curiosity and soon started writing…
Apple insider leaks future plans for a significant iPhone spec change
iPhone 16 Plus and iPhone 16 Pro Max close up of the cameras

Apple has long followed a strategy of consolidating the hardware supply chain within its own circle. Shifting away from Intel to in-house M-series processors was one of the biggest bets in recent memory. Now, the company is eyeing the same strategy for a critical part that allows iPhones to, well, act like phones.

According to Apple tipster Mark Gurman at Bloomberg, Apple will finally put its own cellular modem inside iPhones and iPads starting next year. The plans will be executed over three years, spanning three generations of modems, as part of a plan to end Apple’s reliance on Qualcomm for the part.

Read more
6 excellent iPhone apps that I wish were available on Android
Four iPhone exclusive apps and associated widgets on an iPhone 16 Pro homescreen

For the past 15 years, the way we think about and use technology has been completely reshaped. What was once a hardware-first industry quickly became a software-first one, and this radical evolution of technology can be traced back to one pivotal moment. In 2009, Apple debuted the iPhone 3G and the first App Store. This launch ushered in a new era: the smartphone, complete with apps. It also debuted one of the best commercials, complete with a catchphrase that is sometimes still used today: There’s an app for that.

For many years, the iPhone had a plethora of apps that were not available on Android. While most of these are now available cross-platform, not every developer has embraced the billions of potential customers who don’t have an iPhone. Even now, some apps launch first on iOS and can take months or years to launch on Android.

Read more
The iPhone 18 may get a big redesign you won’t be able to see
The back of the Apple iPhone 16 Plus.

The design of the iPhone can only be described as iconic. That rectangular shape has been a major influence on phone aesthetics and design since the first iPhone came onto the market back in 2007, and that isn't likely to change. The internal design of the iPhone might radically shift, however. Apple is supposedly planning to change how the iPhone hardware is designed to accommodate better AI performance.

Essentially, Apple wants to use discrete memory rather than integrated memory. Those are technical terms that basically mean separate and together. On the internal system on a chip (SoC), any memory that is stacked on top is considered integrated memory. Discrete memory would be RAM that is packaged separately from the SoC. If reports are correct, Apple will begin using discrete memory in 2026, and the shift would result in faster memory and better AI performance, according to The Elec.

Read more