There have been 2 or 3 exploits for the pixel that are capable of unlocking these phones from an AFU state. However, these have been patched for about a few months now. Previously these exploits have been confirmed to be used to unlock Pixels.
There have never been BFU exploits to unlock Pixels since the Titan M2. In fact, one federal agent said “Pixels are heavily encrypted and shouldn’t be sold to normal people” (Paraphrased quote, will find the article).
The fix for these exploit resulted in a much smaller attack surface (increased USB restrict mode and other features that are essential to unlock phones).
I personally believe both Apple and Google will eventually defeat Cellebrite, since the attack surface is getting very small.
For example, on current M1 - M3 Macbooks, computer forensic technicians are unable to image these devices, or unlock them (even in AFU state). This is because of Apple’s SOC + SIP. The only potential attack would be to dump the ram by removing the sticks, however on Mac RAM is soldered in, preventing this as well. There is simply no attack surface anymore to unlock these devices.
On another forum there is a user who had 4 Pixels confiscated in a federal lab for months with an order to “unlock as soon as possible”. They were unable to get in. All phones were BFU and on very old OS versions. Alphanumeric passwords.
By the way, shout out to the Graphene OS team! They discovered many of these exploits, and Graphene OS was never vulnerable to them.
“Forensic companies are rebooting devices in After First Unlock state into fastboot mode on Pixels and other devices to exploit vulnerabilities there and then dump memory.”
“Google implemented a fix by zeroing the memory when booting fastboot mode, and only enabling USB connectivity after the zeroing process is completed, rendering the attacks impractical.”
https://www.spiceworks.com/it-security/vulnerability-management/news/forensic-companies-exploiting-android-zero-day-bugs-pixel-phones-warns-google/