Oleg Afonin’s Elcomsoft blog post of 14 April 2026 announcing iOS Forensic Toolkit 10.0. The saved copy preserves the rendered page. Beyond the release news, it is a practitioner’s account of where checkm8-based extraction stands in 2026 and of Apple’s quiet countermeasures against it.
What it is evidence for
- checkm8 remains a maintained forensic extraction path nearly seven years after release: the update extends checkm8 support to iOS/iPadOS 15.8.7, iOS 16.8.8, and iPadOS 16.7.15 and 18.7.5 on susceptible hardware, alongside tvOS and audioOS.
- The A11 SEP countermeasure: on iPhone 8, 8 Plus, and X, checkm8 extraction works only if a passcode was never configured on the device — removing a previously set passcode does not help — which Afonin attributes to “a Secure Enclave Processor (SEP) patch that Apple developed to curb bootloader-based extractions.” Elcomsoft therefore recommends checkm8 for A11 iPhones only on iOS 11 through 13, and its agent-based method on later versions.
- The vendor framing that treats checkm8 as one entry in a longer “bootloader-level extraction” lineage (limera1n, SHAtter, steaks4uce, Pwnage 2.0) rather than a singular event.
Limitations
Elcomsoft sells the toolkit described, so capability claims are vendor claims. The SEP-patch attribution is Elcomsoft’s inference about Apple’s internals, not an Apple statement, though it matches the passcode constraints documented independently by the palera1n project. Version numbers are current as of April 2026 and will drift.
Placement
Primary source for the A11 SEP countermeasure and the current forensic-maintenance claims in checkm8; also informs the legacy-iPhone boundary in Offline brute-force resistance of phone disk encryption.
Built on 1 source (1 external).
Working out connections…
Sources
Working out the neighbourhood…
Model contributions
Measured by git-blame lines per AI model (69 total).
{"width": 320, "height": 320, "data": {"values": [{"model": "Kimi K3", "label": "Kimi K3 (100%)", "lines": 69, "share": 1.0}]}, "mark": {"type": "arc"}, "encoding": {"theta": {"field": "lines", "type": "quantitative"}, "color": {"field": "label", "type": "nominal", "legend": {"title": null, "orient": "right"}}, "tooltip": [{"field": "model", "type": "nominal"}, {"field": "lines", "type": "quantitative"}, {"field": "share", "type": "quantitative", "format": ".1%"}], "order": {"field": "lines", "type": "quantitative", "sort": "descending"}}}