Two of the United States’ top digital-defense agencies have converged on a strikingly low-tech recommendation for anyone carrying an iPhone or an Android phone: turn it off, then back on, once a week. The advice sits inside broader mobile-security guidance from the National Security Agency and the Cybersecurity and Infrastructure Security Agency, and it targets a specific category of threat known as a zero-click exploit — malicious code that can land on a phone without the owner ever tapping a link or opening a file. A weekly restart will not stop every attack, but security researchers say it forces many of the cheaper, more common exploit chains to start over from nothing.
How a Phone Gets Infected Without a Single Tap
Most phishing warnings assume a victim has to do something wrong: click a bad link, open an infected attachment, install a shady app. A zero-click attack skips that step entirely. It targets a flaw in software that automatically processes incoming data — a messaging app parsing an image, a calendar app reading an invitation, an operating system handling a malformed file — so the code executes the moment the message arrives, with no interaction required. Because there is no suspicious link to avoid or attachment to refuse, the usual advice about online caution offers little protection. Commercial spyware vendors have built entire businesses around these techniques, selling access to government agencies and, in some documented cases, to buyers who used the tools against journalists, lawyers, and dissidents.
Real-world cases have made the threat concrete rather than theoretical. Commercial spyware such as the tools built by Israel’s NSO Group have been documented exploiting zero-click flaws in mainstream messaging apps to install surveillance software on the phones of journalists, human-rights lawyers, and government officials in multiple countries, prompting lawsuits from Apple and Meta and export sanctions from the U.S. Commerce Department against the vendors involved. Those cases are why mobile-hygiene guidance aimed at ordinary phone owners now explicitly names zero-click exploits rather than only the run-of-the-mill phishing attempts most people are used to hearing about.
What the NSA’s Own Field Guide Recommends
The National Security Agency lays out its position in a public document called Mobile Device Best Practices, first issued in 2020 and periodically updated. Among more than a dozen device-hygiene habits, the guide lists a single instruction in plain type: power the device off and on weekly. The document specifically ties this step to defense against zero-click exploits, malicious apps, and spearphishing, alongside more familiar advice such as installing software updates promptly, downloading apps only from official stores, disabling Bluetooth when it is not in use, and avoiding public Wi-Fi networks and public USB charging stations. None of these steps is exotic. The agency’s point is that routine habits, applied consistently, close off a surprising amount of the attack surface that sophisticated intruders rely on.
CISA Gives High-Risk Users the Identical Instruction
The Cybersecurity and Infrastructure Security Agency reaches the same conclusion in its own guidance for people who may be targeted because of their profession or identity, such as journalists, elected officials, and human-rights workers. Its Project Upskill Checklist instructs at-risk individuals to reboot devices weekly as part of a broader defense against tracking technologies and spyware, alongside enabling Lockdown Mode on Apple hardware for anyone who suspects a sophisticated actor is targeting them. The checklist frames the weekly reboot as one layer in a stack of habits rather than a stand-alone fix, sitting next to strong multi-factor authentication, minimal app installation, and careful handling of unknown links and attachments.
Why the Reboot Works, and Where It Falls Short
The mechanism behind the advice is straightforward. Many zero-click exploit chains land their initial payload in a phone’s volatile memory rather than writing it permanently to storage, particularly on modern phones that use code-signing to block unauthorized software from being installed outright. A restart clears that memory, so an attacker who has not managed to establish a foothold able to survive a reboot has to start the entire exploit chain over from the beginning the next time the target phone is online. That is a meaningful obstacle, especially against exploits that are expensive to deploy and reserved for a small number of targets. It is not, however, a guarantee. Researchers who study commercial spyware have documented tools that achieve persistence able to survive a restart, typically by chaining several vulnerabilities together or by exploiting a device that has already been jailbroken or rooted. A weekly reboot raises the cost of an attack; it does not eliminate the most capable adversaries.
Platform differences also matter here. Apple’s Lockdown Mode, referenced in CISA’s own checklist, deliberately disables or restricts features zero-click exploits commonly abuse, such as message attachment previews and certain web technologies, at the cost of some everyday convenience; Android’s equivalent protections are split across manufacturer-specific security modes rather than a single unified switch, which is part of why federal guidance tends to phrase its advice in device-agnostic terms like the weekly reboot rather than pointing to one feature on one operating system.
The Other Habits the Agencies Pair With the Restart
Both agencies present the reboot as one item on a longer list, not a replacement for it. Keeping the operating system and apps updated closes the underlying vulnerabilities that exploit chains rely on in the first place. Installing software only from official app stores limits exposure to malicious apps disguised as legitimate ones. Turning off Bluetooth and Wi-Fi when they are not needed, avoiding public charging stations, and declining to open unexpected attachments round out a checklist that reads more like basic hygiene than advanced cybersecurity. The weekly reboot has drawn outsized attention mainly because it is so simple and so widely applicable — a habit anyone can adopt in a few seconds, without downloading anything or changing a single setting, that intelligence agencies say measurably raises the bar against some of the most sophisticated phone-hacking tools in existence.
This article was produced with the assistance of AI and reviewed by Morning Overview editors.
More from Morning Overview
- A handful of SUVs keep hitting 300,000 miles, and they share one engine trait
- Supplements now rank as the fifth-leading cause of death from liver disease.
- A study names the one SUV most likely to reach 250,000 miles
- More than 60,000 people flee the Spokane area as complex fires overrun 600 structures