iOS 11.4.1's New Passcode Cracking Prevention Feature Can Be Bypassed: ElcomSoft

Advertisement
By Jagmeet Singh | Updated: 10 July 2018 13:12 IST
Highlights
  • Researchers have discovered a loophole in USB Restricted Mode
  • The new mode comes through a USB Accessories toggle on iOS 11.4.1
  • An untrusted USB accessory can reset the one-hour counter

While iOS 11.4.1 has just arrived with a USB Accessories toggle to restrict access to passcode cracking tools, researchers now claim that they have discovered a bug in the latest development. The bug is alleged to reset the one-hour counter available within the latest iOS update as long as a USB accessory is connected to the iOS device before the toggle triggers the lock. Interestingly, as per the researchers, authorities and private companies don't need any specific USB accessory to reset the counter. The researchers have spotted that it can be compromised using Apple's native Lightning to USB 3 Camera adapter that is available at $39 (roughly Rs. 2,700). The toggle was notably first seen as the 'USB Restricted Mode' in the developer preview betas of iOS 12 and iOS 11.4.1 last month.

The team of researchers at ElcomSoft have reiterated that once the USB Restricted Mode is enabled, it restricts all the data communications that occur over the Lightning port. This means if you haven't turned the USB Accessories toggle on, and it has been more than an hour since your Apple device was locked, a USB accessory won't be able to communicate with your device. However, as Oleg Afonin of ElcomSoft has highlighted, the feature is of no use if a USB accessory is already connected to your hardware. This prevents the USB Restricted Mode lock from turning after the one-hour timer. The resetting of the built-in feature works even with an untrusted USB accessory, one that has never been paired with the device before. "What we discovered is that iOS will reset the USB Restrictive Mode countdown timer even if one connects the iPhone to an untrusted USB accessory, one that has never been paired to the iPhone before (well, in fact, the accessories do not require pairing at all). In other words, once the police officer seizes an iPhone, he or she would need to immediately connect that iPhone to a compatible USB accessory to prevent USB Restricted Mode lock after one hour," Afonin writes in a blog post while explaining the loophole.

Advertisement

It has been seen that the lock doesn't get affected with Apple Lightning to 3.5mm jack adapter, though the one-hour countdown was reset through the official Lightning to USB 3 Camera Adapter. "According to our tests, this effectively disables USB Restricted Mode countdown timer, and allows safely transporting the seized device to the lab," claims Afonin. The researcher also underlined that with the release of iOS 11.4.1, the procedure of "properly seizing and transporting" an iPhone could include a compatible Lightning accessory. "Prior to iOS 11.4.1, isolating the iPhone inside a Faraday bag and connecting it to a battery pack would be enough to safely transport it to the lab," he concludes.

While Apple might fix the flaw in the next iOS 11.4 release or in the iOS 12, Afonin doesn't consider it as a severe vulnerability and calls it an "oversight." However, this doesn't mean that the USB connectivity with an Apple device is entirely safe. Law enforcement and private companies could leverage the loophole and design new hardware to continue to crack passcodes through the Lightning port.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Apple, iOS 11.4.1
Advertisement

Related Stories

Popular Mobile Brands
  1. Xiaomi TV FX Mini LED Series With Up to 75-Inch Screen Launched in India
  2. Xiaomi 17T Launches in India With Leica-Tuned Triple Rear Cameras
  3. Motorola Edge 70 Pro+ With 6,500mAh Battery Debuts in India at This Price
  4. Xiaomi 17T vs Vivo X200T vs Samsung Galaxy A57: Price, Features Compared
  5. iPhone 18 Pro Max Leak Suggests It Has the Same Thickness as This iPhone
  6. Motorola Edge 70 Pro+ vs Vivo V70 vs Nothing Phone 4a Pro Compared
  7. Vi Unveils a Faster Verification Method for WhatsApp, Instagram and Instagram
  8. Infinix Smart 20 to Launch in India Next Week With These Features
  1. iPhone 18 Pro Max Leak Hints at No Significant Changes to Smartphone's Thickness Over Predecessor
  2. OnePlus 16 and iQOO 16 Development Progressing 'Rapidly', Could Launch Sooner Than Expected, Tipster Claims
  3. Nintendo Switch 2 Could Get a Removable Battery Variant Next Year to Comply With EU Regulations
  4. FIFA World Cup 2026: LASD Issues Warning Over Crypto Scams Days Ahead of World Cup
  5. Dridam OTT Release Date: When and Where to Watch Shane Nigam’s Crime Thriller Online
  6. Gram Chikitsalay Season 2 OTT Release Date: When and Where to Watch it Online?
  7. Samsung Reportedly Developing Carbon Standing Case for Galaxy Z Fold 8, Galaxy Z Fold 8 Ultra
  8. Vi Unveils Silent Mobile Verification for ‘Faster’ Verification on WhatsApp, Instagram and Facebook in India
  9. Amazon Expands Visual Search With AI-Generated Product Previews, Lens Live and Circle to Search Features
  10. US DoJ Targets Scam Networks in Southeast Asia, Freezes $3 Million in Joint Operation Involving Coinbase, Meta, Microsoft and Starlink
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.