German researchers have demonstrated the ability to reveal passwords stored in a locked iPhone in six minutes and without needing to crack the passcode. The attack targets Apple’s password management system known as keychain and is based on existing jailbreak exploits that gives the attacker wide access to the iPhone’s internal data.
Once jailbroken, the researchers installed an SSH server on the iPhone and install a keychain access script. This keychain access script utilizes functions that are built within the phone to access passwords and other data stored in keychain which is then outputted to the attacker. For a demo of the exploit, jump the break.








