# Updated Cellebrite iPhone Support Matrix Leak

**URL:** https://discuss.privacyguides.net/t/updated-cellebrite-iphone-support-matrix-leak/19578
**Category:** General
**Created:** 2024-07-20T18:19:20Z
**Posts:** 37

## Post 1 by @anon48875053 — 2024-07-20T18:19:20Z

![WpuUNGh](//forum-uploads.privacyguidesusercontent.com/original/2X/a/a0d7405ade7877e6a51ffec1ec8239332f61cacc.png)

Just as expected. It’s common for Cellebrite to fall a few months behind with the latest iOS releases.

---

## Post 2 by @fria — 2024-07-20T19:10:22Z

Wonder what available in CAS means :thinking:

---

## Post 3 by @jonah — 2024-07-20T19:21:29Z

It’s you FedEx-ing it to them.

> Located in 10 secure labs around the world, we help advance your most challenging cases wherever you may be.

[https://cellebrite.com/en/advanced-services/](https://cellebrite.com/en/advanced-services/)

[https://cellebrite.com/en/cas-supported-devices/](https://cellebrite.com/en/cas-supported-devices/)

[https://9to5mac.com/2022/02/10/cellebrite-kit-cant-unlock-iphones/](https://9to5mac.com/2022/02/10/cellebrite-kit-cant-unlock-iphones/)

---

## Post 4 by @anon36940904 — 2024-07-20T20:28:53Z

I need a ELI5 for this

What does AFU mean and how do I read/understand this table?

---

## Post 5 by @anon48875053 — 2024-07-20T20:29:43Z

If your phone has been unlocked even once after turning it on, then you’re fucked.

AFU stands for after first unlock.

BFU stands for before first unlock.

AFU in this table means that if your phone was unlocked even once after a reboot or after just turning it on, they can extract all the data from that device.

---

## Post 6 by @anon36940904 — 2024-07-20T20:42:08Z

Ah! I see.

But what if your data is within encrypted apps like encrypted cloud storage apps or things of that nature?

---

## Post 7 by @anon48875053 — 2024-07-20T20:43:19Z

If you’re logged in into those, you’re screwed.

---

## Post 8 by @anon36940904 — 2024-07-20T20:54:59Z

Got it! Thank you for clarifying.

---

## Post 9 by @pinkandwhite — 2024-07-20T23:40:19Z

Isn’t that the state in which Pixels are also most vulnerable, hence GOS’ auto-reboot being a thing? Bit misleading of Cellebrite to say “oh yeah we can do locked devices (as long as it’s AFU :blush:)”

---

## Post 10 by @fria — 2024-07-20T23:45:29Z

Yeah but they can’t unlock GOS in AFU, someone showed the screenshot but I gotta find it again.

 ![](//forum-uploads.privacyguidesusercontent.com/original/2X/a/a73f2fe075e79fa3de608b66156869a3dec22980.png)  
Love that they have a dedicated GOS section, they’re really feeling the pressure from it.

---

## Post 11 by @jonah — 2024-07-20T23:57:32Z

This chart shows they also can’t unlock stock Android in BFU or AFU, to be fair.

---

## Post 12 by @pinkandwhite — 2024-07-20T23:58:15Z

They really put in “uh but but we can on 2022 updates!!” on the Pixel 8 series that… wasn’t out until 2023 :sob:

---

## Post 13 by @fria — 2024-07-21T00:05:20Z

It says FFS for AOSP but for GOS it’s only up to 2022.

---

## Post 14 by @jonah — 2024-07-21T00:10:52Z

Yes, and FFS has nothing to do with unlocking the device. They can perform a filesystem extraction, but the encrypted data they extract remains encrypted unless they are able to obtain the decryption key, which they can not do without knowing your passcode beforehand regardless of your OS.

This is also the case in the iOS chart, where they are unable to brute force the passcode on anything newer than an iPhone 11, in case anyone is misinterpreting this data.

**Edit:** To be completely clear for readers, in the extraction they _would_ be able to see data _not_ protected by File-Based Encryption, so they’d gain limited insight in to things like what apps you have installed, some information about the OS, that sort of thing. For encrypted data it depends on the encryption class used by the developer, probably.

---

## Post 15 by @kobba89 — 2024-07-21T00:44:06Z

In regards to CAS does it mean that they can do a FFS on iphone 15 or can they actually get into it? I’m more referring to the iphone 15 being in BFU.

---

## Post 16 by @jonah — 2024-07-21T00:45:32Z

It doesn’t mean anything, we don’t know what their capabilities are from this document.

---

## Post 17 by @kobba89 — 2024-07-21T00:47:45Z

Ah right. Any iphone could technically fall under CAS then. Thank you for the very quick reponse, much appreciated.

---

## Post 18 by @anon48875053 — 2024-07-21T06:17:11Z

They can exploit all AFU devices, but not a Google Pixel 6 or later with GrapheneOS. This is the case even if auto-reboot didn’t exist.

---

## Post 19 by @anon48875053 — 2024-07-21T06:37:15Z

If you have a 6-digit PIN on your iPhone 12 or later, then you’re fine. At least when it comes to Cellebrite, XRY, etc.

But three later agencies, such as the NSA, etc., are a different thing, and their capabilities are unknown. That’s why GrapheneOS is still working very hard on features like biometric unlock + a PIN as a 2FA.

---

## Post 20 by @camp — 2024-07-21T18:02:41Z

They can extract the FFS (full file system) of Pixel devices, but this info will be mostly encrypted. That’s why under that section it says “BF: NO”.

AKA: They can’t brute force the password to decrypt the files.

Additionally these charts only apply to default settings.

---

## Post 21 by @anon48875053 — 2024-07-21T18:07:19Z

> [@camp](#):
>
> Additionally these charts only apply to default settings.

Source? It doesn’t make sense that it’s settings dependent.

---

## Post 22 by @jonah — 2024-07-21T18:12:13Z

It could conceivably be affected by Lockdown Mode on iOS for example. We don’t have the full slides here so I don’t know for sure, but from what I’ve heard at least some of the `(1)`, `(3)`, etc. footnote indicators in the chart refer to notes that the attack is time-sensitive.

This likely refers to iOS switching to USB Restricted Mode after 1 hour of being locked. I believe Lockdown Mode would decrease that timeout to 0.

---

## Post 23 by @anon48875053 — 2024-07-21T18:20:48Z

There are no footnotes for the iPhone 12 and later on the latest iOS versions. They would probably look like clowns if they claimed that they could extract the data and, after being asked for assistance, said that they couldn’t because of Lockdown Mode.

At this point, I’m just assuming that they’re working on different ways of exploiting these devices. Both GrapheneOS and iOS have strong USB protections, so these companies are forced to adapt.

---

## Post 24 by @anon48875053 — 2024-07-21T18:25:10Z

> [@jonah](#):
>
> **Edit:** To be completely clear for readers, in the extraction they _would_ be able to see data _not_ protected by File-Based Encryption, so they’d gain limited insight in to things like what apps you have installed, some information about the OS, that sort of thing. For encrypted data it depends on the encryption class used by the developer, probably.

They would get access to basically everything apart from the /data partition. But the thing is that GrapheneOS will have an optional toggle to use the Owner primary lock method as a boot passphrase, so Cellebrite is cooked on that front too.

---

## Post 25 by @anon48875053 — 2024-07-21T21:41:13Z

> **[Cellebrite Premium July 2024 documentation - GrapheneOS Discussion Forum](https://discuss.grapheneos.org/d/14344-cellebrite-premium-july-2024-documentation)**
>
> GrapheneOS discussion forum

Here’s the Cellebrite Premium 7.69.5 iOS Support Matrix from July 2024.

404media recently published an article based on the same April 2024 docs we received in April and published in May. Many tech news sites including 9to5Mac made incorrect assumptions treating that as current.

 ![image](//forum-uploads.privacyguidesusercontent.com/original/2X/f/f1e3c1aacb5f246d26ee5b9aa55e1e02751ad987.png)  
 ![image](//forum-uploads.privacyguidesusercontent.com/original/2X/d/d61c2710f005892bed81d021b113ec373abb7d80.png)  
 ![image](//forum-uploads.privacyguidesusercontent.com/original/2X/d/d8c0c7041ee456e7f76dd68057cd4a80cb4b3c4a.png)

Here’s the Cellebrite Premium 7.69.5 Android Support Matrix from July 2024 for Pixels. They’re still unable to exploit locked GrapheneOS devices unless they’re missing patches from 2022. A locked GrapheneOS device also automatically gets back to BFU from AFU after 18h by default.

 ![image](//forum-uploads.privacyguidesusercontent.com/original/2X/5/521fa6fdf155e0a881bb20759ccb29d2a6f734cd.png)  
 ![image](//forum-uploads.privacyguidesusercontent.com/original/2X/c/c27d36708b595df920117f1343650b7bbc6407b7.png)

GrapheneOS is defending against these tools with generic exploit protections rather than by patching specific vulnerabilities. Until recently, it’s likely that it was our generic memory corruption exploit mitigations including hardened\_malloc which was successfully stopping this.

In February 2024, we added a new feature for disabling the USB-C port at a hardware level. In March 2024, we set the default mode to “Charging-only when locked, except before first unlock”. In June 2024, we increased the default security level to “Charging-only when locked”.

Later in June 2024, we extended our software-level USB protection, merged it into the newer hardware-level protection feature and extended the hardware-level protection to pogo pins on the Pixel Tablet. There’s extremely strong protection against these USB-based attacks now.

Here’s the Cellebrite Premium 7.69.5 Android Support Matrix from July 2024 for overall Android devices. Other than the Titan M2 on the Pixel 6 and later not being successfully yet to bypass brute force protection, it’s largely just based on what they’ve had time to support.

 ![image](//forum-uploads.privacyguidesusercontent.com/original/2X/d/dd4f9093cb8152afcc8fdad5d1ac3eaad8605602.png)  
 ![image](//forum-uploads.privacyguidesusercontent.com/original/2X/e/e1ea6088bc3bced188d43bd61c78c41a19bf2f5e.png)  
 ![image](//forum-uploads.privacyguidesusercontent.com/original/2X/4/4e5f73d4ef0ddeda3b969c8efc591c87e5f0b45d.png)  
 ![image](//forum-uploads.privacyguidesusercontent.com/original/2X/e/e77a2ab0282e6cb696393b3811d933f6cd8c1dcd.png)

In January 2024, we reported several vulnerabilities being exploited by the XRY tool from MSAB to get data from Android devices including stock OS Pixels. In April 2024, Pixels shipped a reset attack mitigation we proposed preventing the whole attack vector. We plan to expand it.

Currently, non-Pixel devices are still vulnerable to these reset attacks. In June 2024, Android 14 QPR3 included another feature we proposed providing wipe-without-reboot support for the device admin wipe API. We shipped this early and use it in our duress PIN/password feature.

We also began triggering a full compacting garbage collection cycle in system\_server and SystemUI when the device is locked based on info about these attacks. This releases memory for no longer allocated objects to the OS, where our generic zero-on-free feature clears all of it.

In the near future, we plan to ship support for adding a PIN as a 2nd factor to fingerprint unlock to enable users to use a strong passphrase combined with PIN+fingerprint secondary unlock for convenience. We have an initial implementation, but it needs more work before shipping.

We’re going to continue advancing the state of the art for protection against exploitation. Hardware vendors are welcome to collaborate with us if they want to protect users. We’re regularly filing vulnerability reports and making suggestions to improve the security of Pixels.

---

## Post 26 by @anon48875053 — 2024-07-21T21:59:15Z

It’s interesting to see that they barely have any exploits for the iPads. Probably because they prioritize phones.

---

## Post 27 by @camp — 2024-07-22T03:25:02Z

Lockdown mode is a problem. Apparently access to control panel is also a requirement for AFU iOS acquisition.

> **[AFU x BFU na prática](https://www.youtube.com/watch?v=8iY9PIHfnFQ)**
>
> Você já conferiu a série de videos curtos com dicas da equipe de suporte no Brasil?Então acompanhe, compartilhe, interaja e nos envie seus comentários!Import...

---

## Post 28 by @camp — 2024-07-22T23:42:02Z

Full Cellebrite manuals, enjoy

> **[Cellebrite May 2021 Manuals for Touch2 UFED, 4PC UFED : Free Download,...](https://archive.org/details/performing-extractions-7.45-may-2021-1/PerformingExtractions_7.45_May_2021-1/)**
>
> This archive consists of three documents, including the manual for the UFED, a system designed to break into locked mobile devices, and a guide for preforming...

---

## Post 29 by @jerm — 2024-07-22T23:58:31Z

May 2021, and I think it is public info as I found 2023 manual by just searching online.

> **[Cellebrite_UFED4PC_OverviewGuide_v7.66_July_2023.pdf](https://cao-94612.s3.us-west-2.amazonaws.com/documents/Cellebrite_UFED4PC_OverviewGuide_v7.66_July_2023.pdf)**
>
> 21.97 MB

---

## Post 30 by @whoami5 — 2024-07-25T02:14:39Z

> [@jonah](#):
>
> They can perform a filesystem extraction, but the encrypted data they extract remains encrypted

GOS admin says AFU or FFS means they exploit the OS and extract all the data unencrypted without needing to know the device lock method.

> **[Cellebrite Premium July 2024 documentation: Page 2 - GrapheneOS Discussion Forum](https://discuss.grapheneos.org/d/14344-cellebrite-premium-july-2024-documentation/27)**
>
> GrapheneOS discussion forum

---

## Post 31 by @NatureNate — 2024-07-25T11:43:25Z

Got it! Thank you for clarifying this.

---

## Post 32 by @camp — 2024-07-25T18:34:34Z

Not quite. AFU and FFS are two different things. FFS refers to extraction of the files from an **unlocked device.**

BF refers to the ability to actually find the unlock password via brute force.

Source is the exact link you posted. Following section (notice keyword unlocked):

```
Glossary:

BFU: Before First Unlock exploitation of OS
BF: Brute Force password after BFU exploitation, which requires bypassing secure element brute force protection if implemented
AFU: After First Unlock exploitation of OS
FFS: Full Filesystem Extraction from an unlocked device
```

---

## Post 33 by @whoami5 — 2024-08-05T18:13:25Z

read the linked comment

> BFU refers to exploiting a device Before First Unlock. BF refers to whether they can brute force lock methods after BFU exploits., which they cannot for Pixel 6 or later / iPhone 12 or later due to the more hardened secure elements. AFU refers to exploiting a device After First Unlock, which obtains access to nearly all the data.

---

## Post 34 by @TheG — 2024-11-05T12:38:43Z

Does Samsung Autoblock feature protect from Cellebrite?

---

## Post 35 by @anon48875053 — 2024-11-05T15:16:52Z

No.

---

## Post 36 by @POOLNNOB — 2025-03-11T17:22:32Z

I see that non-samsung mtk are in yellow and not in green, does it mean now Mediatek are safer than Qualcomm against cellebrite?

---

## Post 37 by @bitosi — 2025-03-13T17:19:49Z

No. They just put less resources into MTK devices. Most phones that have Mediatek chips have lots of other flaws they can use.
