“This is an absolute game changer for iOS forensics and a function that I wish we had years ago,” a Magnet employee says in a leaked video describing new capabilities aimed at bypassing an iPhone security behavior that locks the device into a higher-security state after 72 hours of inactivity.
Magnet Forensics’ new tools: GrayKey Preserve and Evidence Preservation Mode
According to reporting compiled by 404Media and summarized in the linked blog post, Magnet Forensics — the company identified as the maker of GrayKey — has developed a new hardware product called GrayKey Preserve and a software feature for existing GrayKey devices called Evidence Preservation Mode. The company is best known for GrayKey, described in the report as “a popular tool sold to law enforcement agencies that allows them to unlock and access data stored in iPhones and Android smartphones.”
The iPhone automatic reboot feature and the claimed bypass
The report centers on an iOS behavior that automatically reboots an iPhone into a more secure state if the device has not been used for 72 hours. 404Media’s reporting says a “cyber-weapons arms manufacturer” is exploiting a vulnerability in iOS to bypass that automatic reboot, and the Magnet products shown in the leaked video are explicitly positioned to defeat the inactivity-reboot protection so that data remains available to forensic tools.

The cyber insurance questionnaire just landed. Now what?
SOC 2, HIPAA, insurance renewals - someone has to own security strategy. Nubivance provides fractional CISO leadership without the full-time salary.
Get a security leadData types the tools aim to preserve
The leaked video, as quoted in the report, says GrayKey Preserve and Evidence Preservation Mode are also designed to counter another iPhone feature that “automatically deletes certain data — such as cached locations, and recently deleted photos and iMessages — after a certain number of days.” The vendor’s pitch in the footage includes the line, “We’re gonna be able to preserve that data for an infinite amount of time,” signaling an intent to stop those time-based deletions from removing evidence that would otherwise become unavailable to an examiner.
What the leaked video and vendor statements reveal
The primary source for these technical claims is a leaked video in which a Magnet employee demonstrates and praises the capability. The video is quoted directly in the reporting and presents the functionality as a targeted response to specific iOS protections — the 72-hour inactivity reboot and the automatic deletion of cached locations and recently deleted content. The report presents those vendor statements as the basis for the claim that the new GrayKey products can maintain access to data that iOS would otherwise render unavailable after set time windows.
What this means for law enforcement, Apple engineers, and device owners
- Law enforcement agencies: The report reiterates that GrayKey is sold to law enforcement agencies and frames the new features as forensic capabilities that would allow officers and examiners to access data that might otherwise be lost after inactivity reboots or time-limited deletions. Agencies that purchase GrayKey or GrayKey Preserve would be able to assert they can preserve data beyond the device’s built-in time-based protections, per the vendor presentation.
- Apple engineers: The coverage notes a presumption that Apple's engineers, once aware of the flaw, could find and fix it. That presumption appears in the source as a suggestion that disclosure to Apple could prompt a remediation of the vulnerability the vendor demonstrates.
- Device owners: The vendor statements in the leaked video indicate that cached locations, recently deleted photos and iMessages can be preserved indefinitely by these tools despite built-in iOS time-based protections. For owners expecting those protections to reduce the availability of such artifacts over time, the report implies those expectations could be affected if the vendor’s claims are accurate and the tools are used.
The account in 404Media, as summarized by the linked blog post, rests on a vendor demonstration in a leaked video and direct vendor quotes. It reports that Magnet Forensics has positioned a new product and a new mode for an existing product to counter two specific iOS behaviors: the 72-hour inactivity automatic reboot and time-based deletion of certain cached or “recently deleted” items. The report also signals a likely follow-up step — that the vulnerability could be addressed if the relevant Apple engineers receive the information and act on it — but stops short of documenting any patch, mitigation, or Apple response in the material provided.




