Updated Cellebrite Google Pixel Matrix Leak February 2025

GrapheneOS is still not vulnerable to Cellebrite device exploitation as of the February 2025 support matrix which have leaked online in multiple places.

Pixels with GrapheneOS remain the only device explicitly mentioned by Cellebrite as being unaffected by their exploits, and remains the only third-party operating system in their documentation entirely

blog post that summarizes the big pages for Android devices A deep dive into Cellebrite: Android support as of February 2025 - Osservatorio Nessuno

Thanks to the leakers for keeping us updated :heart:.

8 Likes

This isn’t super surprising. The robust USB protections make attacking GrapheneOS extremely difficult and I don’t see this changing until they switch to an alternative attack vector.

2 Likes

Any iOS support matrix?

1 Like

Haven’t seen it shared, anyone is welcomed to share it here.

1 Like

What does the acronyms mean?

I get that BFU is before first unlock and AFU is after first unlock but what is FFS and BF? Also SPL?

Full File System Extraction (FFS): A technique used to obtain a complete copy of a device’s file system, after operating system decryption. Analysis could also allow the retrieval of deleted files.

Brute Force (BF): Brute forcing PINs and password varies a lot depending on software and hardware implementations. The worst case is the extraction of encrypted keys and offline bruteforcing. Other cases include bypassing throttling on the TEE or secure elements for online bruteforcing.

Security Patch Level (SPL): Indicates the date or version of the latest security updates applied to a device.

4 Likes

Amazing! So it basically says Graphene is pretty much untouchable if it is reasonably updated

1 Like

You also need to relock the bootloader after installing GOS (it’s part of their instructions but some may forget).

2 Likes

iirc there is a giant warning during first time setup if unlocked

1 Like

Super duper interesting.

I see that they added Android 15 support for only unlocked devices or AFU, what about Andorid 15 support for the BFU or locked state? Still not feasible?

Also i would like to know the capabilities on the newer Huawei devices with Harmony OS (i understand they stopped supporting after P40), are latest huawei comparable to pixel nowadays ?

Impressive that even the 6 series still holds up.

@Encounter5729
Why wouldn’t it?

Well its hardware is less secure than 8&9 series, so I imagine it could be subject to some hardware hacks. Edit: Cellebrite is software-based so maybe this doesn’t matter.

what
ever since the Tensor transition, They never have been more secure than before. Idk what you’re on about. (Tensor is also where it got the introduction of the better Titan M2, so again idk what you’re on about.)

The Pixels 8 and 9 are more secure in that it has hardware memory tagging support which is why it is recommended by GrapheneOS, on top of the 7 years of support. But hardware memory tagging seems to be for software and likely does nothing for physical attacks or brute forcing which is why the older Pixels still hold up, at least for now.

1 Like

Older Pixels (as far back as the Pixel 6 series) still hold up against brute forcing because they use the same Titan M2 secure element.

3 Likes

Got it. Didn’t know secure memory tagging didn’t matter to brute forcing.