Apple Refutes iPhone Passcode Bypass Claims by Hacker, Claims It's a Result of 'Incorrect Testing'

Advertisement
By Ankit Chawla | Updated: 25 June 2018 11:35 IST
Highlights
  • A hacker had claimed a passcode bypass last week
  • The hack appears to bypass lock out and erase data options
  • Apple has disputed the genuinity of the hack

Apple will soon bring the controversial USB Restricted Mode to iPhone and iPad devices with the rollout of iOS 12 later this year. This toggle in the settings will cut off communication through the USB port when the phone has not been unlocked in an hour. With the move, Apple was preventing the use of brute-force attacks to guess the passcode, a method commonly employed by law enforcement authorities and security agencies to crack a locked iPhone. The company had said it was aiming to protect all customers, especially in countries where phones are readily obtained by police or by criminals with extensive resources, and to head off further spread of the attack technique. Despite this upcoming fix to the brute force, an ethical hacker posted a demonstration of a brute-force passcode attack on devices running versions lower than iOS 12. He claimed to have bypassed current protections by sending passcodes combinations at once. Apple replied to the claim by refuting the method, calling it "incorrect testing".

Matthew Hickey, who goes by the pseudonym @hackerfantastic, took to Twitter on Saturday to show how the iPhone's passcode could be bypassed with a simple hack. In a Vimeo video, Hickey is seen connecting a Lightning cable to an iPhone running the latest stable version of iOS 11.3. He also shows, in Settings, that the Erase Data (on multiple wrong attempts) option has been switched on. He then runs his software which sends all passcode attempts ranging from 0000 to 9999 to the iPhone at once, instead of once at a time. The one-minute video shows that the iPhone gets unlocked within seconds of running the software.

He explained the brute-force attack to ZDNet, "If you send your brute-force attack in one long string of inputs, it'll process all of them, and bypass the erase data feature." As you know, passcode bypass protections will erase a phone's data after multiple wrong attempts.

Advertisement

After a day of posting about the brute-force attack, the hacker suggested in a correction to his original claim, that the iPhone's Secure Enclave Processor (SEP) appeared to register less PINs than previously thought, due to instances of pocket dialling and/ or overly fast inputs. "When I sent codes to the phone, it appears that 20 or more are entered but in reality its only ever sending four or five pins to be checked," he explained to ZDNet. Hickey said he reported his findings to Apple before tweeting about them.

Advertisement

In a statement to ZDNet, Apple spokesperson Michele Wyman responded to the Hickey's claim, "The recent report about a passcode bypass on iPhone was in error, and a result of incorrect testing." The company did not provide any details about precisely why it disputes the findings.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: iPhone, Apple
Advertisement

Related Stories

Popular Mobile Brands
  1. ACT Fibernet Launches New Broadband Plans With Free OTT Subscriptions
  2. OnePlus 15R Surfaces on Benchmarking Site Ahead of India Launch
  3. Motorola Edge 70 With Pantone's 2026 Colour, Swarovski Crystals Launched
  4. Flipkart Buy Buy 2025 Sale: Nothing Phone 3, Phone 3a Deals Revealed
  5. Flipkart Buy Buy 2025 Sale With Discounts on iPhone 16 Begins on This Date
  6. Samsung May Limit Exynos 2600 to South Korea's Galaxy S26 Units
  7. HMD 101, HMD 100 With Built-In Radio Launched in India at These Prices
  8. Apple Announces App Store Awards 2025 Winners: Check List
  9. Realme Watch 5 Launched in India With Up to 16-Day Battery Life: See Price
  1. NotebookLM App Gets an In-Built Camera, Lets Users Upload Images as a Source
  2. HMD 101 Launched in India With 1,000mAh Battery, Auto Call Recording Alongside HMD 100: Price, Features
  3. Crypto Traders Await US Fed Signals as Bitcoin Price Drops to $91,900
  4. Nothing Phone 3a Lite Goes on Sale in India: See Price, Offers, Availability
  5. Realme Narzo Phones Confirmed to Launch in India Soon via Amazon
  6. Samsung Galaxy Watch Ultra 2 Launch Timeline Leaked; Could Debut Alongside Samsung Galaxy Watch 9
  7. Samsung Galaxy S26 Series May Get Exynos 2600 Chipset Exclusively in South Korea: Report
  8. Apple’s FaceTime Reportedly Blocked in Russia Alongside Snapchat’s Video Calling Feature
  9. Anthropic Releases New Claude Tool That Interviews Users About Their AI Usage
  10. ACT Fibernet Launches Revamped Broadband Plans Starting at Rs. 499
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.