Researcher finds method to bypass iOS passcode entry limit without losing data on devices with firmware as recent as iOS 11.3; requires connection to a computer
The attack allows any would-be-hacker to run as many passcodes as they want, without destroying the data.
Context & Ripple Effects
This is the latest entry in a long line of lock-screen defeats on iPhones: an iOS 9 flaw let attackers pull photos and contacts off locked phones via a passcode bypass back in 2015, and researchers demonstrated an Activation Lock bypass on current iPads and iPhones at the end of 2016. What distinguishes the new method is that it removes the one deterrent Apple built into the passcode screen — the wipe after repeated wrong entries — letting an attacker guess indefinitely while keeping the data intact.
The catch is that it needs a computer connection, which narrows who can realistically run it, and it stops working on firmware newer than iOS 11.3. The broader arc here runs from these targeted bypasses toward deeper compromises, culminating in the claimed unpatchable A5-to-A11 bootrom exploit released the following year.
First-order effects
- Owners of iPhones and iPads still running iOS 11.3 or older lose the erase-after-ten-attempts protection whenever the device is connected to a computer, so a thief or anyone with physical access can brute-force the passcode without destroying the data.
- Apple faces immediate pressure to ship a fix through an iOS update, since the attack works on firmware as recent as 11.3 and requires no exotic hardware.
Second-order effects
- The no-data-loss property makes the technique attractive to forensic buyers — law enforcement and private investigators — reducing demand for expensive third-party unlocking services for older devices.
- Each published bypass like this nudges users and enterprises toward faster patching cadences and stricter policies about leaving devices connected to untrusted computers.
Third-order effects
- If the pattern holds — passcode bypass in 2015, Activation Lock bypass in 2016, this method in 2018, then the bootrom exploit in 2019 — lock-screen and activation defenses become treated as speed bumps rather than barriers, shifting real security weight onto encryption keys and rapid OS updates.
- Repeated demonstrations that physical access defeats software locks strengthen the argument that device security ultimately rests on Apple's patch pipeline, making update adoption rates a structural security variable for the whole installed base.
The trend: iPhone lock-screen protections keep falling to researcher bypasses, turning Apple's update pipeline — not the passcode itself — into the last line of defense for devices within physical reach of an attacker.