Apple Refutes iPhone Passcode Bypass Claims by Hacker, Claims It's a Result of 'Incorrect Testing'

Advertisement
By Ankit Chawla | Updated: 25 June 2018 11:35 IST
Highlights
  • A hacker had claimed a passcode bypass last week
  • The hack appears to bypass lock out and erase data options
  • Apple has disputed the genuinity of the hack

Apple will soon bring the controversial USB Restricted Mode to iPhone and iPad devices with the rollout of iOS 12 later this year. This toggle in the settings will cut off communication through the USB port when the phone has not been unlocked in an hour. With the move, Apple was preventing the use of brute-force attacks to guess the passcode, a method commonly employed by law enforcement authorities and security agencies to crack a locked iPhone. The company had said it was aiming to protect all customers, especially in countries where phones are readily obtained by police or by criminals with extensive resources, and to head off further spread of the attack technique. Despite this upcoming fix to the brute force, an ethical hacker posted a demonstration of a brute-force passcode attack on devices running versions lower than iOS 12. He claimed to have bypassed current protections by sending passcodes combinations at once. Apple replied to the claim by refuting the method, calling it "incorrect testing".

Matthew Hickey, who goes by the pseudonym @hackerfantastic, took to Twitter on Saturday to show how the iPhone's passcode could be bypassed with a simple hack. In a Vimeo video, Hickey is seen connecting a Lightning cable to an iPhone running the latest stable version of iOS 11.3. He also shows, in Settings, that the Erase Data (on multiple wrong attempts) option has been switched on. He then runs his software which sends all passcode attempts ranging from 0000 to 9999 to the iPhone at once, instead of once at a time. The one-minute video shows that the iPhone gets unlocked within seconds of running the software.

Advertisement

He explained the brute-force attack to ZDNet, "If you send your brute-force attack in one long string of inputs, it'll process all of them, and bypass the erase data feature." As you know, passcode bypass protections will erase a phone's data after multiple wrong attempts.

After a day of posting about the brute-force attack, the hacker suggested in a correction to his original claim, that the iPhone's Secure Enclave Processor (SEP) appeared to register less PINs than previously thought, due to instances of pocket dialling and/ or overly fast inputs. "When I sent codes to the phone, it appears that 20 or more are entered but in reality its only ever sending four or five pins to be checked," he explained to ZDNet. Hickey said he reported his findings to Apple before tweeting about them.

Advertisement

In a statement to ZDNet, Apple spokesperson Michele Wyman responded to the Hickey's claim, "The recent report about a passcode bypass on iPhone was in error, and a result of incorrect testing." The company did not provide any details about precisely why it disputes the findings.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: iPhone, Apple
Advertisement

Related Stories

Popular Mobile Brands
  1. Samsung Finally Rolls Out Its Health App Update With These Features
  2. Android 17 Will Let You Migrate iMessages, Passkeys and Even Alarms
  3. Tim Cook Says Apple Can No Longer Absorb Soaring Memory Costs Alone
  4. Google Wear OS 7 Update Brings Live Updates, Better Battery Life
  5. Google Home Speaker Finally Makes Its Global Debut, Available to Pre-Order
  6. OnePlus N6 Confirmed to Launch in India With an 8,000mAh Battery
  7. This Upcoming OnePlus N6 Could Arrive With This MediaTek Chip in India
  8. Telecos Reportedly Oppose TRAI Proposal on Cheaper Voice and SMS Packs
  9. You Can Now Download Android 17 on These Devices
  1. Bitcoin Slips Below $64,000 as Hawkish US Fed Outlook Dampens Market Sentiment
  2. Epic Games Confirms Unreal Engine 6 Comes With Claude, Gemini Integration; Releases UE 5.8 Update
  3. OnePlus N6 Runs Geekbench With a MediaTek Dimensity 6 Series Chip, 6GB RAM
  4. JBL Live 780NC, JBL Live 680NC Launched in India With Up to 80-Hour Battery Life: Price, Features
  5. Samsung Health Update Starts Rolling Out With Vitals, Heart Health Score and More Improvements
  6. Nothing Founder Carl Pei Says He’s Coming for Apple’s Customers, One iPhone User at a Time
  7. Android 17 Offers Upgraded Android Switch Tool With Support for Transferring iMessages, Passkeys, Passwords and Alarms
  8. Google Home Speaker Finally Makes Its Global Debut, Available to Pre-Order in Select Markets: Price, Features
  9. Honor Teases MagicOS 11 Update With Liquid Glass-Inspired Design as Early Access Programme Kicks Off
  10. Samsung Galaxy Z Fold 8 Series Tipped to Launch at Higher Price Than Last Year’s Galaxy Z Fold 7
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.