Apple’s Biome framework is drawing fresh attention after researchers identified 84 data streams that can preserve detailed records of how an iPhone is used.
The findings do not describe malware or an active intrusion. Instead, they show how built-in iOS services can retain behavioural evidence, including app activity, locations, notifications, messages, connectivity, and device-state changes.
The research highlights a major change in iOS forensics. Information once concentrated in the KnowledgeC database has gradually moved into Biome, a framework designed to support predictions, recommendations, Siri intelligence, and personalised features.
This expanding data trail also adds context to the recently reported Apple notification privacy flaw involving retained deleted notifications.
Analysts at Zena Forensics identified the streams while reviewing full filesystem acquisitions from several iPhones running iOS 18 and iOS 26.
Zena Forensics said in a report shared with Cyber Security News (CSN). The investigation found that many current tools read only a small portion of the available Biome material.
The overall impact is important for investigators, privacy teams, and iPhone owners.
Data intended to improve the user experience may also help rebuild a detailed timeline of a person’s activity, particularly when it is compared with application records, network data, and other device artifacts.
Hidden Biome Data Streams
Biome first appeared in iOS 14, according to the analysis, and its scope expanded through iOS 15 and iOS 16.
Apple introduced the newer SEGBv2 storage format with iOS 17, while newer versions increasingly positioned Biome as a central store for contextual and behavioural information.
The researchers found 16 useful streams in the system-level Biome repository and 68 in the user-level repository.
Together, the 84 streams contained evidence linked to application usage, installations, Safari activity, location visits, Wallet transactions, CarPlay use, Screen Time, wireless connections, power events, Siri interactions, keyboard use, media playback, and Apple Intelligence activity.
This does not mean every stream contains the same level of detail on every device.
The data depends on iOS version, device activity, settings, and the type of acquisition available to an examiner.
Still, the scale of the framework gives investigators more places to look beyond traditional records, much like broader digital forensic investigation tools are designed to do.
Forensic Value and Privacy
A key finding is that Biome may retain some records longer than the commonly assumed 28-day period.
While many streams appeared to follow a roughly four-week retention cycle, others kept information for months, increasing their value when investigators need to reconstruct events from an older period.
Two streams stood out during the review: Siri.Remembers.MessageHistory and Location.Visit. The first may provide useful message-related context, while the second can offer details about visited locations.
Researchers cautioned that parsed results must always be validated against other evidence before drawing conclusions about user activity.
The report also notes that tool support remains incomplete. A standard iOS 26 device can contain more than 300 stream folders under the user-level Biome location, but many forensic tools currently interpret only 10 to 20 streams.
This gap makes manual validation and updated parsers especially important for defensible forensic work.
For users, the research reinforces the value of keeping iPhones current, particularly after privacy-related fixes.
Recent cases involving an iMessage zero click exploit and an iOS zero click vulnerability show why software updates remain essential, even though Biome itself is not an exploit or malware component.