Is it maybe providing a bogus NTP server or something? Maybe the automatic reboot feature can be moved to the Secure Enclave or something, and made to only rely on the hardware RTC in a way that can't be tampered with.
I'm wondering if you put the phone into a mode where it thinks it's dialing emergency services or contacting them via crash detection etc that it won't reboot. I could picture a scenario where the code is written to never disrupt an emergency services call.
Full disclosure I don't own an iPhone so this may not even be a thing. Just guessing based on liability risk from Apple of "what's more important than protecting the phone"
Here's a deeper dive on that question:
https://naehrdine.blogspot.com/2024/11/reverse-engineering-i...
Tl,dr: it's likely baked into the sep, no ntp
I'm wondering if you put the phone into a mode where it thinks it's dialing emergency services or contacting them via crash detection etc that it won't reboot. I could picture a scenario where the code is written to never disrupt an emergency services call.
Full disclosure I don't own an iPhone so this may not even be a thing. Just guessing based on liability risk from Apple of "what's more important than protecting the phone"