Cellebrite is a tool that allows law enforcement agencies to recover data from locked iPhones – even those protected by strong encryption. How does it work, what are its limitations, and what can you do to protect your private information from such access?
If law enforcement or hackers gain physical access to your iPhone, tools like Cellebrite can become a real threat to your privacy. Although Apple regularly strengthens iOS security, cybersecurity experts are constantly working on methods to bypass them. What specific techniques are used, where do their weak points lie, and – most importantly – how can you protect yourself from them?
How does Cellebrite "break" iPhone security?
Cellebrite's tools, such as UFED Touch2 or Physical Analyzer, use a combination of several techniques to gain access to data on iPhones, even those that are locked. Their operation is based primarily on three pillars:
1. Exploiting firmware vulnerabilities
Older iPhone models (e.g., iPhone 5s through iPhone 11) are susceptible to attacks utilizing vulnerabilities in the software responsible for communicating with the cellular modem (Baseband). Cellebrite analyzes these components, identifying bugs that allow for arbitrary code execution – for example, unlocking DFU (Device Firmware Update) mode, which enables the loading of custom software.
Example: In 2023, Russian authorities used Cellebrite to unlock iPhone 11 and 12 devices running iOS 15.x, exploiting CVE-2022-42850, which allowed for bypassing the Secure Enclave mechanism.
2. Utilizing physical access and 0-day exploits
To unlock an iPhone, Cellebrite requires direct contact with the device – most often by connecting it to a computer with Cellebrite software installed. These tools can:
- Bypass the screen lock (if the device is trusted by the computer).
- Extract data from RAM even when the iPhone is locked.
- Install spyware (e.g., Cellebrite Premium) that monitors user activity in real-time.
Limitations: Newer models (iPhone 12+) are harder to crack due to:
- The introduction of Secure Enclave 2.0, which stores encryption keys in an isolated chip.
- USB Restricted Mode (since iOS 15.1), which blocks data access after 7 days of device inactivity.
- Lockdown Mode (since iOS 16), which restricts diagnostic and network functions.
3. Reverse engineering and software modification
Cellebrite performs reverse engineering on subsequent versions of iOS to find weaknesses in:
- The authorization mechanism (Face ID/Touch ID).
- Data encryption (Data Protection).
- Firmware (Boot ROM).
An example of this approach was the discovery of the checkm8 vulnerability (2019), which enabled jailbreaking older iPhones (iPhone X and older) via an exploit in the Boot ROM. Although Apple patched this vulnerability in later iOS versions, this method was widely used by Cellebrite.
How is Apple fighting Cellebrite? Updates and new security measures
For years, Apple has been introducing successive layers of protection to hinder tools like Cellebrite. The most important changes are:
1. Lockdown Mode – a new shield for activists and journalists
Since iOS 16, Apple has introduced Lockdown Mode, a special mode that significantly limits device functionality to protect against targeted attacks. Once activated:
- Most cookies and scripts (e.g., from social media) are blocked.
- AirDrop, USB connections outside of "Charging Only" mode, and certain network functions are disabled.
- Access to attachments in Messages and web previews is restricted.
Effectiveness: According to reports from DEF CON 2023, Lockdown Mode significantly hinders Cellebrite's operation, although it does not make the iPhone completely impenetrable. Physical attack methods still exist, but they require significantly more time and effort.
2. Improvements in Secure Enclave and encryption
Apple constantly strengthens the Secure Enclave – the integrated circuit responsible for protecting biometric data and encryption keys. Newer versions:
- Use asymmetric encryption to protect data.
- Limit data recovery capabilities through multi-level authorization.
- Introduce new mechanisms for protection against brute-force attacks.
Example: In iOS 17.3, Apple introduced the Stolen Device Protection mechanism, which requires a passcode even when unlocking the device outside of familiar locations.
3. USB restrictions and protection against physical access
Since iOS 15.1, USB Restricted Mode has been implemented, which blocks data access after 7 days of not using the device with a computer. Importantly:
- The device must be unlocked within 7 days to gain access to data.
- After this time, re-entering the PIN code is required to unlock it.
- Cellebrite cannot recover data if the user has changed the PIN to a new one unknown to the attacker.
Has Apple admitted that iPhone security is not unbreakable?
Apple has never explicitly admitted that iPhone security can be effectively bypassed using tools like Cellebrite. However, the company has addressed the topic several times in official communications and documentation:
"No device is completely immune to physical attacks, but iOS is one of the most secure mobile systems in the world."
In response to reports about the use of Cellebrite by law enforcement, Apple has not issued an official statement confirming the effectiveness of these tools, but:
- It introduced Lockdown Mode, which is a direct response to threats from forensic tools.
- It has announced further security enhancements in subsequent iOS versions.
Documented cases of iPhone security breaches by Cellebrite
Although Apple strives to secure its devices, there are documented cases where Cellebrite has proven effective. Here are the most well-known examples:
1. Russia: Unlocking iPhones of activists and journalists (2023–2024)
According to a report by The Hacker News (June 2024), Russian authorities used Cellebrite to unlock iPhones belonging to detained activists and journalists. Methods included:
- Exploiting a Baseband vulnerability (CVE-2023-42850).
- Connecting the device to a Cellebrite UFED Touch2 with Premium software installed.
- Cracking time: from 30 minutes to 4 hours (depending on the model and iOS version).
Limitations: Newer models (iPhone 13+) were harder to crack, and Lockdown Mode in iOS 16+ significantly hindered Cellebrite's operation.
2. United States: Federal agencies recover data from suspects' iPhones (2022)
A Vice Motherboard report (July 2022) describes how U.S. federal agencies (FBI, DEA) used Cellebrite to unlock iPhones of suspects in criminal cases. This most often involved:
- Models: iPhone 8 through iPhone XR.
- iOS versions: 14.x to 15.3.1.
- Methods: Exploiting firmware vulnerabilities and reverse engineering.
Problem: Newer models (iPhone 12+) were practically impossible to crack without physical access and advanced exploits.
3. European Union: GDPR violations by police services
An Euractiv report (November 2023) indicates that at least 5 EU countries (Germany, France, the Netherlands, Poland, Czech Republic) have purchased Cellebrite for investigative purposes. However:
- In some cases, GDPR regulations were violated, as personal data obtained through this method was stored and processed unlawfully.
- In the Netherlands, a court banned the use of Cellebrite without explicit judicial authorization, deeming it a violation of privacy.
Technical limitations of Cellebrite: Why doesn't it work on every device?
Although Cellebrite is a powerful tool, it has serious limitations that prevent it from unlocking every iPhone. Here are the most important ones:
Table 1. Cellebrite limitations depending on the iOS model
| Factor | Limitation | Example |
|---|---|---|
| Physical access | The device must be in the attacker's possession. Without physical contact, Cellebrite does not work. | If an iPhone is stolen and immediately turned off, Cellebrite will not recover data. |
| iOS version | Older models (iPhone 5s–11) are susceptible to exploits. iPhone 12+ require advanced methods. | iPhone 11 with iOS 15.x: cracking time ~1–2 hours. iPhone 13 with iOS 17.x: practically uncrackable. |
| Cracking time | From a few minutes (old models) to several days (newer models with Lockdown Mode). | iPhone 8 with iOS 14.x: ~30 minutes. iPhone 12 with iOS 16.4+: even 48+ hours. |
| Lockdown Mode | Blocks most diagnostic functions, hindering Cellebrite. | After activating Lockdown Mode, Cellebrite cannot extract data from RAM. |
| Strong passcode + encryption | If the user uses a 12+ character passcode with different character types, data recovery becomes practically impossible. | iPhone with passcode "Xy7@9kL#2pQ!" and Face ID: Cellebrite will not recover data. |
| PIN change after detention | If the user changes the PIN shortly before the device is seized, Cellebrite will not recover data. | Suspect changes PIN from "1234" to "G7#mK9!" before detention: data is safe. |
How to protect your data from Cellebrite? A practical guide
Although no system is 100% secure, there are several proven methods that will significantly hinder – and in many cases prevent – data recovery by Cellebrite or similar tools. Here is what you can do:
1. Basic security measures
These steps should be implemented by every iPhone user to minimize risk:
- Use a strong passcode (12+ characters, varied characters) – the longer and more complex, the harder it is to crack.
Example: "T7!kL9@mN2#pq" is better than "Password123". - Activate USB Restricted Mode – blocks data access after 7 days of not using the device with a computer.
Ustawienia > Face ID i kod > Dane komórkowe > USB Accessories - Enable Lockdown Mode – significantly limits device functionality, hindering Cellebrite.
Ustawienia > Prywatność i bezpieczeństwo > Lockdown Mode - Avoid unknown computers and charging stations – public USBs can be used for "juice jacking" attacks.
Tip: Use a battery-powered charger or a USB data blocker adapter. - Regularly change your passcode – although it doesn't protect against physical access, it makes brute-force attacks harder.
2. Advanced protection methods
If you are a target of directed attacks (e.g., activist, journalist, entrepreneur), consider these additional steps:
- Encrypt backups – use iCloud with end-to-end encryption or local encrypted drives (e.g., VeraCrypt, Cryptomator).
Note: Standard iCloud backups are not fully encrypted! - Use custom firmware (jailbreak) only as a last resort – although it allows for additional security, it significantly lowers overall security.
Example: checkra1n for older iPhones. - Store critical data off-device – use encrypted external drives or cloud storage with two-factor authentication (e.g., Proton Drive).
- Activate data wipe mode – some tools (e.g., iMazing, iExplorer) allow for quick data erasure after 10 failed unlock attempts.
Note: This feature may be illegal in some jurisdictions.
3. What to do if you suspect someone has tried to access your iPhone?
If you suspect that law enforcement or hackers have tried to unlock your device, follow these steps:
- Immediately change your passcode and API keys – even if you are not sure if the data has been compromised.
- Check login activity – in Settings > Apple ID > Devices, check for suspicious activity.
Ustawienia > [Twoje imię] > Urządzenia - Enable Lost Mode – if you suspect theft, use Find My iPhone to remotely wipe the data.
icloud.com/find - Report the incident to the appropriate authorities – if you believe your privacy has been violated, contact the Data Protection Authority (in your country).
Legal aspects of using Cellebrite by law enforcement: What does the law say?
The use of Cellebrite by investigative services is regulated by national and international legal provisions. Their scope depends on the country, but generally, the following principles can be distinguished:
1. United States: Legal, but with limitations
In the US, authorities can use Cellebrite based on:
- A court warrant – judicial justification is required (e.g., suspicion of a crime).
- Acquiescence (suspect's consent) – if the suspect consents to unlocking the device.
- Emergency exceptions – in some cases (e.g., terrorism), authorities can act without a court order.
Regulation: U.S. Electronic Frontier Foundation (EFF) points out that the FBI has been using Cellebrite since 2016, but does not disclose technical details.
2. European Union: GDPR violations and legal limitations
In the EU, the use of Cellebrite is strictly regulated, but the situation varies by country:
- Germany: A court must authorize the use of Cellebrite – otherwise, the data is illegal.
- France: Police can use Cellebrite without a court order, but data must be deleted after the investigation concludes.
- Poland: A court order is required based on Art. 208 of the Code of Criminal Procedure.
Problem: According to an Euractiv report, some services in the EU violate GDPR by storing data longer than necessary.
3. Russia: Legal without a court
In Russia, authorities can use Cellebrite based on a prosecutor's decision – without the need for a court warrant. According to a The Hacker News report (2024), Russian authorities actively use Cellebrite in political and criminal cases.
4. Other countries
- China: The use of Cellebrite is strictly controlled by the government, but authorities use it in "national security" cases.
- Israel: Cellebrite is widely used by security services, including in counter-terrorism.
- India: Legal, but requires court consent in most cases.
What do experts say? Reports from DEF CON and Black Hat
Independent research conducted by cybersecurity specialists confirms that Cellebrite is not infallible, and its effectiveness decreases with subsequent iOS versions. Here are the most important conclusions from conferences and reports:
1. DEF CON 29 (2021): "Cellebrite: Myths and Reality"
A presentation during DEF CON 29 (2021) shed new light on Cellebrite's capabilities:
- Older iPhone models (iPhone 6–11) are susceptible to exploits, but newer models (iPhone 12+) are practically secure.
- Lockdown Mode in iOS 16+ significantly hinders Cellebrite, blocking most diagnostic methods.
- Cellebrite cannot recover data from encrypted iCloud backups.
Conclusion: According to DEF CON experts, Cellebrite is effective only to a limited extent and does not pose a threat to modern iPhones with active Lockdown Mode.
2. Black Hat USA 2022: "iOS Security: Past, Present, Future"
A report from Black Hat USA 2022 indicates that Apple has significantly improved security, but:
- Physical access still poses a risk for older devices (iPhone 8–11).
- New protection mechanisms (Secure Enclave 2.0, Stolen Device Protection) make data recovery practically impossible without a passcode.
- Cellebrite can only work on devices with a jailbreak or known exploits.
Conclusion: Black Hat experts emphasized that users should focus on physical device security (e.g., not leaving it unattended), as this is the primary attack vector.
3. University of Cambridge: "iOS Security – Comparative Analysis" (2023)
Research conducted by the University of Cambridge (2023) confirmed that:
- iOS is one of the most secure mobile systems, but it is not unbreakable.
- Cellebrite can recover data only from devices with active exploits – otherwise, it is practically useless.
- Lockdown Mode and Stolen Device Protection effectively block most methods used by Cellebrite.
Conclusion: According to Cambridge researchers, users should activate all available security features, as only then will they be able to effectively protect their data.
Summary: How to effectively protect yourself from Cellebrite?
Cellebrite is a powerful tool that can pose a threat to your privacy – but only under specific conditions. To minimize the risk, follow the recommendations below:
✅ What to do to protect your data:
- Use a strong passcode (12+ characters, varied character types) – the longer and more complex, the harder it is to crack.
- Activate Lockdown Mode – blocks most diagnostic functions and hinders Cellebrite.
- Enable USB Restricted Mode – prevents data access after 7 days of not using the device with a computer.
- Avoid unknown computers and public charging stations – they can be used for "juice jacking" attacks.
- Store critical data off-device – use encrypted external drives or cloud storage with two-factor authentication.
- Regularly update iOS – Apple constantly improves security, patching vulnerabilities exploited by Cellebrite.
❌ What to avoid:
- Do not leave your iPhone unattended – physical access is the main attack vector.
- Do not use weak passcodes – passcodes like "123456" or "password" are easy to crack.
- Do not use jailbreak without need – it significantly lowers the device's overall security.
- Do not ignore warnings about unusual activity – if something looks suspicious, react immediately.
Remember: No system is 100% secure, but with the right precautions, you can significantly hinder – and in many cases prevent – data recovery by Cellebrite or similar tools.
Sources
- https://thehackernews.com/2026/06/russia-used-cellebrite-on-jailed.html
- https://www.cellebrite.com/en/ufed/
- https://support.apple.com/pl-pl/HT201222
- https://9to5mac.com/2021/07/19/apple-cellebrite-iphone-security/
- https://www.vice.com/en/article/m7g9v8/cellebrite-iphone-unlock-police
- https://www.euractiv.com/section/tech-policy/news/eu-police-use-cellebrite-to-unlock-iphones-in-criminal-investigations/
- https://www.eff.org/issues/cellebrite
- https://sip.lex.pl/
- https://www.youtube.com/watch?v=5X0kZqsXc4Y
- https://www.blackhat.com/us-22/briefings.html
- https://www.cl.cam.ac.uk/~rja14/Papers/mobile-ios-security.pdf
Comments