Researchers bypass Apple's Activation Lock on iPhone and iPad running the latest version of iOS
Researchers have found a bug that can be used to bypass Apple's Activation Lock feature and gain access to the homescreen of locked iPhones and iPads running the latest version of iOS.
Context & Ripple Effects
This closes out a rough 2016 for Apple's device-security story: after the Johns Hopkins iMessage decryption bug in March and the NSO-linked zero-day flaws patched in iOS 9.3.5 in August, researchers have now shown that Activation Lock — the anti-theft layer meant to make a stolen iPhone or iPad worthless without the owner's credentials — can be bypassed on the latest iOS release.
The finding matters because Activation Lock is the control that ties hardware to an Apple ID; a homescreen-level bypass means the lock fails at exactly the job it exists to do.
First-order effects
- Owners relying on Activation Lock as their recovery lever for lost or stolen devices lose assurance until Apple ships a fix, since the reported bypass reaches the homescreen of locked iPhones and iPads on current iOS.
Second-order effects
- Apple faces immediate patch pressure on its newest iOS build, continuing the rapid disclose-and-patch cadence set earlier in 2016 by the iMessage and NSO disclosures.
Third-order effects
- The pattern holds across the corpus — the 2016 Activation Lock bypass, the 2018 passcode entry-limit bypass, and the 2019 iOS 13 lockscreen exploit all target the same access-control layer — suggesting Apple's lock screens will keep being probed per release, making fast patch turnaround a permanent cost of the closed-device model rather than an anomaly.
The trend: iOS access-control layers — Activation Lock, passcode limits, lockscreens — are repeatedly bypassed by researchers with each major release, keeping Apple on a continuous harden-and-patch cycle for device locks.