Dev.to
7/9/2026

Bypassing Activation Lock via Device-to-Device Migration: A Retrospective Analysis
Short summary
A security researcher documented a June 2026 iOS 18.6 vulnerability where Device-to-Device Migration could bypass Activation Lock on stolen iPhones by transferring from an older iOS 15.8.8 device, then performing a factory reset. The attack exploited version mismatch in Apple's activation server logic; Apple confirmed the behavior is patched in current builds.
- •iOS 18.6 Activation Lock could be bypassed via Device-to-Device Migration from older iOS devices
- •Attack allowed unprivileged users to replace attacker's Apple ID without credentials by exploiting version compatibility logic
- •Responsible disclosure completed; vulnerability confirmed patched in current iOS builds
Generated with AI, which can make mistakes.
Is this a good recommendation for you?



