• News/
  • https://www.bleepingcomputer.com/news/security/google-adds-android-auto-reboot-to-block-forensic-data-extractions/

Google adds Android auto-reboot to block forensic data extractions

BleepingComputer
·
Bill Toulas
·
Published Apr 15, 2025
·
Updated

Google is rolling out a new security mechanism on Android devices that will automatically reboot locked, unused devices after three consecutive days of inactivity, restoring memory to an encrypted state. Although the tech giant has not commented on the exact motives behind the addition of this feature, it is expected to make data extraction by advanced forensic tools harder by bringing devices into a non-exploitable state more often. The new auto-reboot feature was listed in the latest Google Play services update (v25.14), under 'Security & Privacy.' "With this feature, your device automatically restarts if locked for 3 consecutive days," read the release notes. In January 2024, the developers behind the privacy-centric GrapheneOS warned of firmware flaws in Android that digital forensic companies are leveraging to extract data without the user's authorization. When an Android phone is first started, it enters a Before First Unlock (BFU) state, where most user data remains encrypted and inaccessible until the device is unlocked for the first time. Once the user unlocks it with their PIN or biometrics, the device enters the After First Unlock (AFU) state, which decrypts the user's data, making it accessible for data extraction or surveillance. Devices seized or stolen are typically already in the AFU state, so even if the screen is locked, forensic tools can extract at least some user data from them. To solve this, GrapheneOS for Android devices introduced an auto-reboot mech...

Read full article

Affected Software

5 affected components
Google Android
Google Google Play services=25.14
GrapheneOS GrapheneOS
Google Android
Google Google Play services=v25.14
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses Google's new security feature that automatically reboots locked Android devices after three days of inactivity to prevent data extraction.

2

What security implications are discussed in the article?

The new auto-reboot feature aims to enhance security by restoring the device's memory to an encrypted state, thereby preventing unauthorized forensic data access.

3

What devices or systems are impacted by this new feature?

The feature affects devices running Google Android and Google Play Services, specifically version 25.14 and above.

4

How does the auto-reboot feature work on Android devices?

It automatically reboots locked devices after three consecutive days of inactivity, ensuring that data remains secure.

5

Which specific version of Google Play Services is mentioned in the article?

The article mentions Google Play Services version 25.14.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203