Someone Snuck Into a Cellebrite Microsoft Teams Call and Leaked Phone Unlocking Details

Interesting information here. So, Cellebrite can unlock GOS devices but only up to 2022 updates. Stock pixels are still quite vulnerable

rogueFed then posted two screenshots of the Microsoft Teams call. The first was a Cellebrite Support Matrix, which lays out whether the company’s tech can, or can’t, unlock certain phones and under what conditions. The second screenshot was of a Cellebrite employee.

According to another of rogueFed’s posts, the meeting took place in October. The meeting appears to have been a sales call. The employee is a “pre sales expert,” according to a profile available online.

The Support Matrix is focused on modern Google Pixel devices, including the Pixel 9 series. The screenshot does not include details on the Pixel 10, which is Google’s latest device. It discusses Cellebrite’s capabilities regarding ‘before first unlock’, or BFU, when a piece of phone unlocking tech tries to open a device before someone has typed in the phone’s passcode for the first time since being turned on. It also shows Cellebrite’s capabilities against after first unlock, or AFU, devices.

2 Likes

Is someone able to properly share what the highly blurry picture says?

Model / State Standard Android OS BFU Standard Android OS AFU Standard Android OS GrapheneOS BFU * GrapheneOS AFU * GrapheneOS Unlocked
Pixel 6 / Pixel 6 Pro / Pixel 6a BFU Yes, BF No FFS Yes, BF No FFS Yes BFU Yes, up to late 2022 SPL, BF No FFS Yes, up to late 2022 SPL, BF No FFS Yes, up to late 2024 SPL
Pixel 7 / Pixel 7 Pro / Pixel 7a / Pixel Tablet / Pixel Fold BFU Yes, BF No FFS Yes, BF No FFS Yes BFU Yes, up to late 2022 SPL, BF No FFS Yes, up to late 2022 SPL, BF No FFS Yes, up to late 2024 SPL
Pixel 8 / Pixel 8a / Pixel 8 Pro BFU Yes, BF No FFS Yes, BF No FFS Yes BFU Yes, up to late 2022 SPL, BF No FFS Yes, up to late 2022 SPL, BF No FFS Yes, up to late 2024 SPL
Pixel 9 / Pixel 9 Pro / Pixel 9 Pro XL / Pixel 9 Pro Fold / Pixel 9a BFU Yes, BF No FFS Yes, BF No FFS Yes BFU No, BF No FFS No, BF No FFS Yes, up to late 2024 SPL
3 Likes

Ah if only the leaker knew how screenshots work :sweat_smile:

Original (still blurry): https://files.catbox.moe/80kwmt.jpg

1 Like

Thank you!

As I understand this then, GOS users who have updated their software have nothing to worry about then, right? (atleast when the phone is locked in BFU or AFU modes)

I’d avoid making definitive statements like that. Cellebrite is just one of many companies developing these kinds of exploits. That being said, it’s clear that the approach GrapheneOS is taking with generic exploit protections and minimising attack surface (like by default disabling USB when locked) is effective.

3 Likes

Good to know. Thank you for the context and nuance.

We’ve reached out to Google to inquire about why a custom ROM created by volunteers is more resistant to industrial phone hacking than the official Pixel OS. We’ll update this article if Google has anything to say.

1 Like

Original leak thread: https://discuss.grapheneos.org/d/27698-new-cellebrite-capability-obtained-in-teams-meeting

1 Like

Am I right? : FYI, FFS is just consent-based extraction of files. So extraction of files if you unlock your phone.

In their defense, they may have been more concerned with accidentally having a screen capture event register with their software and ruining their reputation and trust with the vendor.

2 Likes