iOS 11 patches an exploit that could be used to crack an iPhone 7 or iPhone 7 Plus passcode using a $500 hardware hacking solution, Apple confirmed to TechCrunch this afternoon.

The exploit, demonstrated by YouTube user EverythingApplePro yesterday, was never really of any concern to iPhone users because of the extreme parameters required to make it work in a timely manner, according to TechCrunch. It uses a $500 piece of hardware, requires physical access to an iPhone 7 or 7 Plus, realistically only works with a 4 digit passcode, and slows down drastically more than 10 minutes after an iPhone's passcode was last changed.


The "box" shown off in the video is similar to tools used by law enforcement officials, and while passcode-guessing hardware like this does not normally work at this speed because iOS devices lock you out after several failed passcode entry attempts, there is a bug in iOS 10 that makes it possible to guess a passcode over and over for a short period directly after the passcode has been changed. TechCrunch explains:

On iOS 10, there is a "bug" for lack of a better term, that allows repeated, rapid guesses of the passcode if you've changed it within the last minute or so. This allows the box to work within that period. Once another threshold is crossed -- say 10 minutes after a passcode is changed -- you no longer have the freedom to guess rapidly.

Without the rapid guessing enabled by the iOS 10 bug, it takes much, much longer for a solution like box to get into an iPhone because it's slowed down by Apple's passcode timeout. A six digit passcode (now the default on iOS devices) that had not been changed recently would take approximately 9.5 years to crack, for example.

According to Apple, the behavior that allows the box to work has been patched as of iOS 11 beta 4.

Top Rated Comments

Tycho24 Avatar
76 months ago
So basically don't use your iPhone 7 until iOS 11 comes out lol.
Or don’t change your passcode then give your phone to some shady looking dude with a $500 password cracking tool in his hands, within 10 minutes... until iOS 11 comes out?
Score: 20 Votes (Like | Disagree)
dannys1 Avatar
76 months ago
He sneakly didn't mention in the video that the passcode needed to be changed in the last ten minutes.

I wonder what made them bring this useless tool to market.
Score: 14 Votes (Like | Disagree)
Mercifull Avatar
76 months ago
He sneakly didn't mention in the video that the passcode needed to be changed in the last ten minutes.

I wonder what made them bring this useless tool to market.
To flog to YouTubers hoping to make money from adverts.
Score: 10 Votes (Like | Disagree)
ArtOfWarfare Avatar
76 months ago
If not you get guys like these who think they're "hackers" by selling an overpriced iterative pin code guesser hahahaha
They don't think they're hackers - they know how simple the product is. The person buying it thinks they're a hacker because they have the product.
Score: 8 Votes (Like | Disagree)
luvbug Avatar
76 months ago
This "tool" seems to be about as effective as penis enlargement products, although I have no personal experience with this passcode generator :)
Score: 8 Votes (Like | Disagree)
Westside guy Avatar
76 months ago
I wonder if this was an intentional choice by the programming team? I could see someone arguing that "right after changing the passcode, people are going to be more prone to mistakes - so let's not penalize them for the first few minutes".
Score: 6 Votes (Like | Disagree)

Popular Stories

gradiente iphone white

Brazilian Electronics Company Revives Long-Running iPhone Trademark Dispute

Tuesday May 19, 2020 1:06 pm PDT by
Apple has been involved in a long-running iPhone trademark dispute in Brazil, which was revived today by IGB Electronica, a Brazilian consumer electronics company that originally registered the "iPhone" name in 2000. IGB Electronica fought a multi-year battle with Apple in an attempt to get exclusive rights to the "iPhone" trademark, but ultimately lost, and now the case has been brought to...