Cellebrite DI Ltd. (Nasdaq: CLBT) is an Israeli digital forensics company headquartered in Petah Tikva. Founded in 1999 as a consumer phone-to-phone data-transfer business, it entered mobile forensics in 2007 with its Universal Forensic Extraction Device (UFED) and now serves roughly 7,000 law enforcement, intelligence, military, and enterprise customers across 150 countries.1
Cellebrite’s tools unlock, decrypt, and extract data from mobile devices. Its capabilities rest on a combination of manufacturer relationships, internal reverse engineering, zero-day vulnerability acquisition, and code adapted from the public jailbreaking community.2 The company went public via a SPAC merger in August 2021 at a ~$2.4 billion implied equity value and acquired Corellium in 2025 for approximately $200 million, adding mobile device virtualization for vulnerability research.1
Products and capabilities
UFED and extraction levels
The UFED family performs three tiers of extraction:
| Extraction type | Data recovered | Method |
|---|---|---|
| Logical | User data (SMS, call logs, contacts, media, app data) | Standard backup interfaces (adb backup, iTunes backup) |
| File system | Full directory tree, hidden files, databases, encrypted containers | Exploit-assisted access to live filesystem |
| Physical | Bit-for-bit flash memory image, including deleted and unallocated data | Bootloader exploits, chip-off, decrypting bootloaders |
UFED supports iOS, Android, BlackBerry, feature phones, drones, SIM cards, SD cards, and GPS devices.3
Premium and Inseyets
Cellebrite Premium (introduced 2019) and its successor Inseyets are the high-end unlocking and full-file-system extraction tiers. They deploy exploits against locked and encrypted devices, including current iOS and high-end Android models. Cellebrite claims Premium can unlock iOS 16+ and iPhone 14+ devices and perform full file system extractions that include encrypted app data and the iOS keychain.4
Premium Enterprise (ES) extends these capabilities over a network to every UFED endpoint in an agency, with centralized fleet management and audit logging.5
Cellebrite also operates ten Advanced Services labs in nine countries that perform in-house unlocking for customer devices.6
checkm8 and the legacy-iPhone path
For iPhones through the X (A7–A11), Cellebrite’s extraction rests on checkm8, the free, unpatchable bootrom exploit axi0mX released publicly in September 2019. Cellebrite integrated it in UFED 7.28 (January 2020) — marketed as a “first-to market solution” performing “a forensically sound temporary jailbreak” — offering full file system and keychain extraction where the passcode is known or unset, and a partial BFU dump where it is not.7 8 The method is still maintained: UFED 7.65 (May 2023) extended checkm8 full-file-system extraction to iOS 15.7.3 on iPhone 7, 8, and X.9
The path has a hard hardware boundary. The A12 generation (iPhone XS and XR, 2018) closed the exploit in silicon a year before it was public, so against XR-class devices and later Cellebrite relies on Premium’s software exploits instead. On the newest vulnerable phones the path is narrower still: an Apple SEP countermeasure limits checkm8 extraction on iPhone 8 and X running recent iOS versions to devices that never had a passcode set.10
Known capability boundaries
Cellebrite leaked support matrices (July 2024, February 2025, October 2025) reveal a graded landscape:11 12
- Stock Android on Pixel 6–9: BFU metadata extraction possible; AFU full file system extraction possible; brute force against the Titan M2 secure element not supported.
- GrapheneOS on Pixel 6a+: BFU and AFU extraction resisted. As of late 2024, even unlocked GrapheneOS devices resist extraction of private user data beyond what the active session exposes.
- GrapheneOS pre-late-2022 builds: Extraction possible.
- MediaTek-based devices: Effectively no mitigation against BFU attacks due to unpatchable Boot ROM vulnerabilities.
- Most non-Pixel, non-Samsung Android devices: Unlockable due to delayed security updates, weak TEE implementations, and absent secure elements.
These matrices also indicate that Cellebrite’s AFU extraction on stock Pixel devices relies on USB-based exploitation, consistent with the tool’s behaviour as a local-access forensic device.
Cloud, analytics, and platform
Beyond extraction, Cellebrite sells: Pathfinder for AI-assisted lead prioritisation and timeline construction; Cellebrite Cloud for remote collection from backups and social media; and the Genesis case-management platform. Subscription revenue comprised 89% of total revenue in Q1 2025, growing 21% year-over-year.13
Does Cellebrite buy zero-days from shady sellers?
Cellebrite actively acquires and deploys zero-day vulnerabilities, but the full shape of its acquisition pipeline is obscured by trade secrecy.
What is known
Cellebrite derives its capabilities from three sources:2
- Early access to phone designs through manufacturer relationships, giving Cellebrite advance knowledge of hardware and software before devices reach market.
- Internal reverse engineering by a skilled research team.
- Code and techniques adapted from the public iOS jailbreaking community (e.g. limera1n, QuickPwn).
The 2017 Cellebrite hack exposed that large portions of its iOS extraction code closely resembled publicly available jailbreak tools, with modifications for forensic use such as PIN brute forcing.14 15 Jonathan Zdziarski, a forensic scientist who examined the leaked files, concluded that Cellebrite had “ripped off software verbatim from the jailbreak community” and used it in products marketed as scientifically validated.15 The pattern repeated in the open three years later: when axi0mX published the checkm8 bootrom exploit in September 2019, Cellebrite integrated it into UFED within four months and marketed the integration as a first-to-market feature (see § checkm8 and the legacy-iPhone path).
At the same time, Cellebrite Premium’s ability to unlock current-generation locked iPhones and Android devices cannot be explained by repackaged jailbreak code alone. The Premium and Advanced Services tiers either develop exploits in-house or acquire them from external researchers. Cellebrite treats these capabilities as trade secrets and trains customers to avoid disclosing techniques in court or testimony.6
The Corellium acquisition (June 2025, ~$200M) was explicitly described as expanding “mobile vulnerability research” through “cutting-edge virtualization technologies that accelerate research.”16 A mobile device emulation platform is infrastructure for finding and validating exploits, and Corellium’s co-founder became Cellebrite’s CTO.
The exploit broker market
The broader zero-day market is opaque, secretive, and operates through non-disclosure agreements and classified information controls.17 Exploits are priced from thousands to seven figures depending on platform prevalence, exclusivity, and whether the exploit is remote zero-click or requires local access.2 Research published in 2022 found a 44% annualised inflation rate in exploit pricing paid by a single broker.17
Cellebrite is a buyer in this market. Whether it purchases directly from individual researchers, through intermediaries, or from dedicated exploit brokers like Zerodium is not publicly documented. The distinction between “exploit broker” and “forensic vendor” is partly a matter of marketing: both acquire vulnerabilities, weaponise them, and sell the resulting capability to government customers. Cellebrite’s model requires physical possession of the device, distinguishing it from remote-access spyware vendors like NSO Group, but the upstream exploit supply chain overlaps.
The difference from NSO Group
Cellebrite tools require physical possession. They do not perform remote interception or surveillance. This is a meaningful operational distinction, but it does not eliminate the human-rights exposure: a device seized during detention or at a border can be extracted with the same tools used in legitimate criminal investigations. Serbia provides the closest documented case: Amnesty International found that Serbian authorities used Cellebrite forensic tools alongside bespoke spyware to target journalists and activists, including a zero-day exploit deployed against a student activist’s Android phone in 2025.18
The damage from hoarding exploits
The RAND findings and their limits
The 2017 RAND Corporation study Zero Days, Thousands of Nights is the most-cited empirical work on the stockpile-versus-disclose question.19 Based on a dataset of over 200 zero-day vulnerabilities (2002–2016), it found:
- average exploit life expectancy of 6.9 years;
- a 5.7% annual collision rate (independent rediscovery and disclosure);
- median exploit development time of 22 days after finding a vulnerability;
- no identifiable vulnerability characteristics that predict a long or short life.
RAND concluded that stockpiling “could be a more viable strategy” than commonly believed, because the collision rate is low and the protection from disclosure may be modest.19
The study has important limitations. It measured only publicly disclosed collisions, not secret discovery by another government or criminal group. The dataset came from a single commercial vulnerability research group and may over-represent one type of vulnerability or discovery method. A later study found collision rates as high as 10.8% to 21.9% per year, though methodology and populations differed.17 Most importantly, the RAND study characterised zero-day life expectancy from the perspective of a government deciding whether to retain an exploit, not from the perspective of the billions of device users left vulnerable.
How hoarding causes harm
The harm from exploit hoarding is not hypothetical. It operates through several distinct mechanisms:
Every user of the vulnerable software remains exposed. When Cellebrite retains an iOS or Android exploit for Premium, every device running the vulnerable version remains open to any other actor who independently discovers the same vulnerability. A 5.7% annual collision rate means, over the 6.9-year average life, roughly one-third of stockpiled vulnerabilities will be independently found by someone else. Those someone-elses may include criminal ransomware operators, state-sponsored espionage groups, or stalkerware vendors.
Stockpiles leak. Cellebrite has been breached repeatedly:
- January 2017: 900 GB stolen from Cellebrite servers, including customer databases, technical data, and exploit files for iOS, Android, and BlackBerry.20
- February 2017: The hacker published decrypted exploit code, demonstrating that Cellebrite’s internal protections were trivially bypassed.21
- August 2022: 4 TB of proprietary data leaked anonymously, including Mobilogy and Team Foundation Server data.22
- January 2023: 1.7 TB of Cellebrite software and documentation published via DDoSecrets by a whistleblower concerned about human-rights abuses.23
- October 2025: A Cellebrite capability matrix leaked when an outsider joined a Microsoft Teams briefing.24
Each breach demonstrates that an exploit stockpile is only as secure as the organisation that holds it. Cellebrite’s own software bundled FFmpeg DLLs from 2012 with over 100 unpatched security vulnerabilities, and its installer redistributed Apple-signed DLLs in apparent copyright violation.25
Stockpiled exploits enable repression. Cellebrite sold to the Rapid Action Battalion in Bangladesh (linked to extrajudicial killings), to Belarus and Russia (used against political opposition), and to China, Venezuela, Myanmar, Turkey, and the UAE.1 A leaked training video instructs law enforcement customers to keep techniques “hush hush” and classify them as “law enforcement sensitive,” potentially undermining criminal defendants’ ability to challenge the evidence against them.6
The tools undermine their own evidence. Moxie Marlinspike demonstrated in 2021 that specially formatted files placed in any app on a scanned device could execute arbitrary code on the Cellebrite machine, modifying not only the current report but all previous and future reports from all scanned devices, with no detectable checksum or timestamp changes.25 This is not a theoretical concern about hoarding: it is a direct consequence of building a forensic tool that parses untrusted input without adequate exploit mitigations, while simultaneously hoarding the vulnerabilities that make the tool’s own exploitation possible.
The counterargument
The RAND study and its defenders argue that disclosure is not costless. A government that discloses all vulnerabilities loses offensive capability, and some vulnerabilities against obsolete or niche systems cause negligible user harm while retaining intelligence value. The U.S. Vulnerabilities Equities Process attempts to balance these factors through interagency review, though reports of CIA stockpiling suggest the balance has not yet been found.2
For Cellebrite specifically, the company argues that its tools “protect and save lives” and that lawful access to encrypted devices is essential for investigating child exploitation, homicide, terrorism, and organised crime. These are genuine investigative needs. The question is whether the current model — private companies hoarding vulnerabilities and selling access to any government that can pay — is the least-bad way to meet them, or whether mandatory vulnerability disclosure combined with lawful-access frameworks would produce better outcomes.
Public opinion research by Leal and Musgrave (2023) found that US respondents overwhelmingly support disclosure over stockpiling, a preference only weakly affected by the collision-rate argument that RAND emphasised.26
Defences against Cellebrite
Because Cellebrite requires physical possession, defences centre on making extraction infeasible even when a device is seized.
Strongest available protection
GrapheneOS on a recent Pixel device (6a or newer) provides the strongest documented resistance. Per Cellebrite’s own support matrices, GrapheneOS resists both BFU and AFU extraction, and as of late 2024, even an unlocked GrapheneOS device resists extraction of private user data beyond the active session.11 12
GrapheneOS achieves this through:11
- a hardened memory allocator (
hardened_malloc) that zeroes freed memory, preventing RAM-dump-based credential extraction; - hardware-level USB-C port disabling when locked;
- configurable auto-reboot to return the device to BFU state;
- generic exploit mitigations rather than per-vulnerability patching.
Practical measures for all platforms
| Measure | Platform | Effect |
|---|---|---|
| Auto-reboot after inactivity | GrapheneOS, iOS 18+, Android 15 (72h) | Returns device to BFU; forensic tools lose memory-resident keys |
| USB restricted mode | iOS (Lockdown Mode), Android 15+, GrapheneOS | Blocks data over USB when locked, closing the AFU extraction path |
| Lockdown Mode | iOS | Reduces attack surface across Messages, Safari, wired connections; documented to stop FBI extraction on an iPhone 13 |
| GrapheneOS Lockdown | GrapheneOS (power menu) | Disables biometrics, hides notifications, requires PIN |
| Strong alphanumeric passphrase | All | Renders brute force infeasible, especially with Secure Element rate limiting |
| Disable USB debugging | Android | Closes the adb extraction path |
| Secure Startup | Android FDE devices | Requires passcode at boot; encrypts with hardware-backed key + user credential |
| Physical power-off | All | Forces BFU state immediately |
| Disable biometrics | All | Prevents compelled unlock; requires passcode knowledge |
| eSIM PIN | All | Prevents SIM swap or network-based attacks |
| File-Based Encryption (FBE) | Modern Android, iOS | Derives encryption keys from user credential rather than default_password |
iOS Lockdown Mode. Introduced in 2022, Lockdown Mode blocks most message attachment types, disables just-in-time JavaScript compilation, prevents wired data connections when locked, and blocks new configuration profiles and MDM enrolment.27 An FBI CART court filing stated that an iPhone 13 in Lockdown Mode could not be extracted.11 Some forensic practitioners claim that special cables with payloads can bypass Lockdown Mode’s USB restriction.28 The mechanism is not independently verified, and Apple’s inactivity reboot (iOS 18.1+) adds a separate layer of BFU return that forensic vendors are actively developing countermeasures against (Cellebrite “Safeguard Mode”, Magnet “GrayKey Preserve”).11
Auto-reboot. GrapheneOS allows the reboot timeout to be configured as low as 1–2 hours. Apple’s iOS inactivity reboot uses an undisclosed timeout. Android 15’s implementation defaults to 72 hours, which GrapheneOS developers describe as a likely compromise with law enforcement expectations.11
USB restrictions. Android 15 introduced USB restriction options. iOS has had USB Restricted Mode since iOS 11.4.1, which limits the port to charging only after the device has been locked for more than one hour. GrapheneOS provides hardware-level USB-C port disabling. These restrictions directly block the USB-based AFU attacks that Cellebrite’s matrices show working against stock Pixel devices.11
Apple’s Memory Integrity Enforcement (iPhone 17, September 2025) also targets the local memory-corruption chains that physical extraction tools use in the AFU state; exploit developers expect it to raise the cost of Cellebrite- and GrayKey-class attacks, though the leaked matrices predate it and no independent measurement exists yet.29
The asymmetry: hardware matters
The effectiveness of every software defence depends on the device’s hardware security architecture:
- Google Pixel with Titan M2 secure element: Brute force against the passcode is infeasible. Extraction requires an OS-level vulnerability.
- Samsung flagships with Knox Vault: Despite secure-element hardware comparable in class to Titan M2, Cellebrite’s Inseyets 10.0 (January 2024) added BFU, AFU, and full-file-system extraction for the Galaxy S24 series on both Qualcomm and Exynos variants, and the February 2025 matrices list Galaxy S7 through S24 as BFU-extractable. See Samsung Knox § The forensic record: worse than the architecture suggests.
- MediaTek-based devices: Unpatchable Boot ROM vulnerabilities make BFU extraction possible.
- Most other Android devices: Delayed or absent security updates, weak TEE implementations, and missing secure elements leave them unlockable.11
What does not help much
- Short PIN alone: Cellebrite’s matrix states brute force is not supported against Pixel Titan M2, but a 4-digit PIN on a device without a secure element can be brute forced.
- “Security through obscurity”: Cellebrite’s capabilities cover the most popular device models. Assuming an obscure device is safe because it is not explicitly listed is unwarranted.
- OEM skin modifications: Custom Android skins do not generally harden against forensic extraction; they often introduce additional attack surface.
- Routine software updates alone: Necessary but insufficient. A fully patched stock Pixel in AFU state is vulnerable to Cellebrite extraction according to Cellebrite’s own documentation.
Related notes
- Mobile-device extraction and evidentiary selection
- Reliability of mobile forensic extraction as evidence
- Mobile operating system security comparison
- Titan M secure element
- Case for privacy and security
- Rättssäkerhet in Swedish criminal cases
- Cognitive and human factors in digital forensics
-
Cellebrite, Wikipedia. Accessed 2026-07-23. ↩↩↩
-
Susan Landau, Listening In: Cybersecurity in an Insecure Age, Yale University Press, 2017, pp. 142–147. See Listening In; the citation was verified against the imported text. ↩↩↩↩
-
Cellebrite UFED 4PC Overview Guide v7.66, July 2023. ↩
-
The Solution That Changed Modern Digital Investigations Forever, Cellebrite blog, August 2021. ↩
-
Cellebrite asks cops to keep its phone hacking tech ‘hush hush’, TechCrunch, August 2023. ↩↩↩
-
Cellebrite on checkm8 full file system extraction (Cellebrite product announcement for UFED 7.28, January 2020); saved copy, captured from the Wayback Machine after the live page stopped serving. ↩
-
Cellebrite’s Checkm8, CDFS, 11 March 2020. Reseller walkthrough with the UFED 7.28 device-and-iOS support table (iPhone 5s through X). ↩
-
Cellebrite UFED & Responder v7.65 Now Available, Cellebrite, May 2023. ↩
-
Elcomsoft on low-level iOS extraction (Oleg Afonin, Elcomsoft blog, 14 April 2026); saved copy. ↩
-
Demystifying phone unlocking tools (Osservatorio Nessuno, May 2026); original. ↩↩↩↩↩↩↩↩
-
Leaked Cellebrite Briefing: GrapheneOS Significantly Hardens Google Pixel Against Mobile Forensics, CyberSecureFox, November 2025. ↩↩
-
Cellebrite (CLBT): history, ownership, mission, how it works & makes money, DCF Model, December 2024. ↩
-
Hacker Dumps iOS Cracking Tools Allegedly Stolen from Cellebrite, Motherboard (Vice), February 2017. ↩
-
Hacker Leaks Cellebrite’s Phone-Hacking Tools, Schneier on Security, February 2017. ↩↩
-
About Cellebrite, Cellebrite, accessed 2026-07-23. ↩
-
Zero-day vulnerability, Wikipedia. Accessed 2026-07-23. ↩↩↩
-
Amnesty Finds Cellebrite’s Zero-Day Used to Unlock Serbian Activist’s Android Phone, The Hacker News, February 2025. ↩
-
Lillian Ablon and Andy Bogart, Zero Days, Thousands of Nights: The Life and Times of Zero-Day Vulnerabilities and Their Exploits, RAND Corporation, 2017. ↩↩
-
Hacker Steals 900 GB of Cellebrite Data, Motherboard (Vice), January 2017. ↩
-
TamirAl/cellebrite, GitHub, February 2017. ↩
-
Anonymous Source Leaks 4TB of Cellebrite Data After Cyberattack, Hackread, August 2022. ↩
-
Release: Cellebrite (1.7 TB) and MSAB (103 GB), Distributed Denial of Secrets, January 2023. ↩
-
Someone Snuck Into a Cellebrite Microsoft Teams Call and Leaked Phone Unlocking Details, 404 Media, October 2025. ↩
-
Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer from an app’s perspective, Signal Blog, April 2021. ↩↩
-
Marcelo M. Leal and Paul Musgrave, “Backwards from zero: How the U.S. public evaluates the use of zero-day vulnerabilities in cybersecurity,” Contemporary Security Policy 44, no. 3 (2023): 437–461. ↩
-
How does Lockdown Mode protect iPhone security?, AppleInsider, February 2026. ↩
-
REVEALED: Here’s the Cellebrite Premium Device Support Matrix for July 2024, Stacker News, July 2024. ↩
-
Apple’s latest iPhone security feature just made life more difficult for spyware makers, TechCrunch, September 2025. ↩
Built on 14 sources (14 external).
Working out connections…
Sources
Working out the neighbourhood…
Model contributions
Measured by git-blame lines per AI model (631 total).
{"width": 320, "height": 320, "data": {"values": [{"model": "DeepSeek V4 Pro", "label": "DeepSeek V4 Pro (86%)", "lines": 544, "share": 0.8621236133122029}, {"model": "Kimi K3", "label": "Kimi K3 (13%)", "lines": 85, "share": 0.1347068145800317}, {"model": "Claude Opus 5", "label": "Claude Opus 5 (<1%)", "lines": 2, "share": 0.003169572107765452}]}, "mark": {"type": "arc"}, "encoding": {"theta": {"field": "lines", "type": "quantitative"}, "color": {"field": "label", "type": "nominal", "legend": {"title": null, "orient": "right"}}, "tooltip": [{"field": "model", "type": "nominal"}, {"field": "lines", "type": "quantitative"}, {"field": "share", "type": "quantitative", "format": ".1%"}], "order": {"field": "lines", "type": "quantitative", "sort": "descending"}}}