To solve this, GrapheneOS for Android devices introduced an auto-reboot mechanism that restarted the system after 18 hours of inactivity, bringing the device back into the "Before First Unlock" (BFU) state. When an Android phone is first started, it enters a Before First Unlock (BFU) state, where most user data remains encrypted and inaccessible until the device is unlocked for the first time. Google is rolling out a new security mechanism on Android devices that will automatically reboot locked, unused devices after three consecutive days of inactivity, restoring memory to an encrypted state. Although the tech giant has not commented on the exact motives behind the addition of this feature, it is expected to make data extraction by advanced forensic tools harder by bringing devices into a non-exploitable state more often. Once the user unlocks it with their PIN or biometrics, the device enters the After First Unlock (AFU) state, which decrypts the user's data, making it accessible for data extraction or surveillance. Devices seized or stolen are typically already in the AFU state, so even if the screen is locked, forensic tools can extract at least some user data from them. Important security updates for Android devices are also made available through Settings > Security & privacy > System & updates > Google Play system update. In January 2024, the developers behind the privacy-centric GrapheneOS warned of firmware flaws in Android that digital forensic companies are leveraging to extract data without the user's authorization. Amnesty International uncovered earlier this year that Cellebrite tools leveraged USB kernel driver flaws in Android to unlock locked devices that had been confiscated. Bill Toulas Bill Toulas is a tech writer and infosec news reporter with over a decade of experience working on various online publications, covering open-source, Linux, malware, data breach incidents, and hacks. To further strengthen physical security, it is recommended to turn off USB data transfer when the device is locked.
This Cyber News was published on www.bleepingcomputer.com. Publication date: Tue, 15 Apr 2025 13:55:19 +0000