iOS 11.4.1's New Passcode Cracking Prevention Feature Can Be Bypassed: ElcomSoft

Advertisement
By Jagmeet Singh | Updated: 10 July 2018 13:12 IST
Highlights
  • Researchers have discovered a loophole in USB Restricted Mode
  • The new mode comes through a USB Accessories toggle on iOS 11.4.1
  • An untrusted USB accessory can reset the one-hour counter

While iOS 11.4.1 has just arrived with a USB Accessories toggle to restrict access to passcode cracking tools, researchers now claim that they have discovered a bug in the latest development. The bug is alleged to reset the one-hour counter available within the latest iOS update as long as a USB accessory is connected to the iOS device before the toggle triggers the lock. Interestingly, as per the researchers, authorities and private companies don't need any specific USB accessory to reset the counter. The researchers have spotted that it can be compromised using Apple's native Lightning to USB 3 Camera adapter that is available at $39 (roughly Rs. 2,700). The toggle was notably first seen as the 'USB Restricted Mode' in the developer preview betas of iOS 12 and iOS 11.4.1 last month.

The team of researchers at ElcomSoft have reiterated that once the USB Restricted Mode is enabled, it restricts all the data communications that occur over the Lightning port. This means if you haven't turned the USB Accessories toggle on, and it has been more than an hour since your Apple device was locked, a USB accessory won't be able to communicate with your device. However, as Oleg Afonin of ElcomSoft has highlighted, the feature is of no use if a USB accessory is already connected to your hardware. This prevents the USB Restricted Mode lock from turning after the one-hour timer. The resetting of the built-in feature works even with an untrusted USB accessory, one that has never been paired with the device before. "What we discovered is that iOS will reset the USB Restrictive Mode countdown timer even if one connects the iPhone to an untrusted USB accessory, one that has never been paired to the iPhone before (well, in fact, the accessories do not require pairing at all). In other words, once the police officer seizes an iPhone, he or she would need to immediately connect that iPhone to a compatible USB accessory to prevent USB Restricted Mode lock after one hour," Afonin writes in a blog post while explaining the loophole.

It has been seen that the lock doesn't get affected with Apple Lightning to 3.5mm jack adapter, though the one-hour countdown was reset through the official Lightning to USB 3 Camera Adapter. "According to our tests, this effectively disables USB Restricted Mode countdown timer, and allows safely transporting the seized device to the lab," claims Afonin. The researcher also underlined that with the release of iOS 11.4.1, the procedure of "properly seizing and transporting" an iPhone could include a compatible Lightning accessory. "Prior to iOS 11.4.1, isolating the iPhone inside a Faraday bag and connecting it to a battery pack would be enough to safely transport it to the lab," he concludes.

Advertisement

While Apple might fix the flaw in the next iOS 11.4 release or in the iOS 12, Afonin doesn't consider it as a severe vulnerability and calls it an "oversight." However, this doesn't mean that the USB connectivity with an Apple device is entirely safe. Law enforcement and private companies could leverage the loophole and design new hardware to continue to crack passcodes through the Lightning port.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Apple, iOS 11.4.1
Advertisement

Related Stories

Popular Mobile Brands
  1. Redmi Pad 2 Pro 5G Will Launch in India Soon: See Expected Features
  2. Xiaomi 17 Ultra With Leica-Tuned Cameras Confirmed to Launch Soon
  3. Nvidia's GeForce RTX 50 Series GPUs Are About to Be Scarce
  4. GTA 6 Map Guide: Here's All You Need to Know About Different Areas
  5. OnePlus 15s Visits BIS Certification Website; Could Launch in India Soon
  6. Eko OTT Release Reportedly Revealed: When and Where to Watch it Online?
  7. You Can Now Vibe Code AI Mini Apps Within Gemini With This Tool
  8. Samsung Will Unveil These New Bespoke AI Devices at CES 2026
  9. Best ANC TWS Earbuds Under Rs 8,000: Sony WF-C710N, OnePlus Buds 4, More
  10. OnePlus Watch Lite With Up to 10 Days Battery Life Launched: See Price
  1. Adobe Firefly Platform Updated With New AI Models and Tools, Offers Limited-Time Unlimited Generations
  2. Boat Valour Ring 1 Launched in India With Heart Rate Variability Tracking, Up to 15-Day Battery Life: Price, Features
  3. Call of Duty: Black Ops 7 Was the Best-Selling Game in the US in November, but Trails Battlefield 6 in 2025
  4. Truecaller Voicemail Feature Launched for Android Users in India With Transcription in 12 Regional Languages
  5. OpenAI Starts Reviewing Third-Party App Submissions for ChatGPT Integration
  6. Google Brings Opal, an AI-Powered Mini App Builder Tool to Gemini
  7. Redmi Pad 2 Pro 5G India Launch Teased Soon After Global Debut: Expected Specifications, Features
  8. CES 2026: Samsung to Unveil Bespoke AI Laundry Combo, Jet Bot Steam Ultra Robot Vacuum, and More
  9. Samsung Exynos 2600 Details Leak Ahead of Galaxy S26 Launch; Could Be Equipped With 10-Core CPU, AMD GPU
  10. Vivo Y50e 5G, Vivo Y50s 5G Appear on Google Play Console; Mysterious Vivo Phone Listed on Certification Site
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.