Cellebrite can unlock most Android phones but can't unlock most iPhones

t3chg33k

Skilled
Came up in the context of the Trump shooter's phone being unlocked in 40 minutes by Cellebrite. Basically any powered on Android phone can be hacked with Pixels being the exception when they are powered down.


All iPhones running iOS 17.4 and above cannot be unlocked at present which also brings to light the issue with most Android phones not getting the latest security updates. Also the fact that Samsung introduced vulnerability that otherwise didn't exist in Android.
 
Wonder whether he used Samsung's Knox / private folder policies.
 
Came up in the context of the Trump shooter's phone being unlocked in 40 minutes by Cellebrite. Basically any powered on Android phone can be hacked with Pixels being the exception when they are powered down.


All iPhones running iOS 17.4 and above cannot be unlocked at present which also brings to light the issue with most Android phones not getting the latest security updates. Also the fact that Samsung introduced vulnerability that otherwise didn't exist in Android.
It can open Iphone too. As previously we went on searches (Income tax raid) so I use to ask forensic guy. Can you guys take data from iphone too by using cellebrite. They said yes. But the cost for that was too high. And they didn't possess that. We didn't need it ever because assessee use to unlock his phone and give us without any hassles.
 

Apple takes security seriously, that's why an exploit of iOS is valued much higher than any android. I assume that cracking companies do have some exploits which are not known to the open world and can indeed open iPhones.
 
It can open Iphone too. As previously we went on searches (Income tax raid) so I use to ask forensic guy. Can you guys take data from iphone too by using cellebrite. They said yes. But the cost for that was too high. And they didn't possess that. We didn't need it ever because assessee use to unlock his phone and give us without any hassles.
Yeah, the current iPhone info is from their leaked documents and they have not managed to get into 17.4 yet while ones up to iPhone 11 are hackable due to hardware vulnerabilities. But then the loopholes are closed as they are found.

Wonder whether he used Samsung's Knox / private folder policies.
If it is a relative mid to high end phone then Knox is enabled by default. What I had read in the past is that they are still able to clone the complete filesystem from Android phones, which then gives them unlimited attempts to brute force the password.
 
Umm.. it is a little difficult to trust those leaks. Then there is Graykey
 
Last edited:
Umm.. it is a little difficult to trust those leaks. Then there is Graykey
That is a general list of devices and OS versions but then you wouldn't get these companies to acknowledge in general what they are capable of. In this case, Cellibrite at least acknowledged that the leaked documents are real.

Going by that, all iPhones on 17.4 cannot be unlocked presently. iPhone 12 onwards cannot be unlocked since iOS 17.1 whereas those up to iPhone 11 can be unlocked till 17.3.1. All 16.x and 17.0 iPhones can be unlocked.
 
Cellibrite at least acknowledged that the leaked documents are real.
And the reason they would do that is just hide the exploit they are using. It is a cat and mouse game after all. There is nothing which is unbreakable today. Interesting read -