The disclosure arrives days after Cellebrite suspended Serbia as a customer, turning a country-specific abuse allegation into a broader test of how forensic-tool suppliers and Android respond when their capabilities are tied to device compromise.
First-order effects
Google’s fixes close the three reported Android zero-day paths, reducing the usefulness of those specific flaws for phone-unlocking operations on patched devices.
Serbia loses access to the reported technique, while Cellebrite faces more immediate scrutiny over tools Amnesty says were developed by the company.
Second-order effects
The combination of public reporting, a customer suspension, and platform patches raises the cost for forensic-tool vendors of relying on undisclosed mobile vulnerabilities in customer deployments.
Android’s response reinforces a feedback loop in which civil-society investigations can trigger both vendor-account actions and security remediation, rather than leaving alleged misuse solely to customer oversight.
Third-order effects
If this pattern persists, mobile-forensics providers may face stronger expectations to document safeguards, investigate customer use, and limit tools that depend on unpatched flaws.
The episode points to a durable contest between lawful-access tooling and mobile-platform security: disclosure can neutralize a technique, but it does not remove demand for device access or the incentive to find new weaknesses.
The trend: Dual-use mobile-forensics capabilities are drawing tighter scrutiny as researchers, platforms, and vendors increasingly respond to alleged state misuse in tandem.
🚨 UPDATE YOUR DEVICES 🚨: Amnesty International uncovers sophisticated zero-day exploit affecting billions of Android devices. Cellebrite's Linux USB exploit was used to unlock the phone of a Serbian youth activist, targeted in December 2024 **after** previous reports abuses [imag…
Our team at the Security Lab saw this Linux kernel USB exploit chain used against multiple people since mid-2024. We shared traces of exploit with Google's Threat Analysis Group allowing for the identification of at least three zero-day vulnerabilities https://securitylab.amnesty…
https://securitylab.amnesty.org/ ... Amnesty International's Security Lab has a post about 3 vulnerabilities exploited by Cellebrite to extract data from locked Android devices. GrapheneOS blocked exploiting these vulnerabilities in multiple different ways. We also patched them m…
Cases like this show how real-world attackers are exploiting the latest mobile devices. Android vendors should urgently implement security mitigations to limit the large attack exposed to malicious USB devices connected to a locked Android phone. https://grapheneos.org/...
Security nihilism grows from being in a reactive response-only mode for too long. Security optimism grows from focusing on applied security engineering. Be the house that didn't burn down because you invested in applying security engineering to prevent entire classes of attack.
Looks like we have a confirmation that Cellebrite uses memory corruptions in Linux kernel USB drivers to unlock Android phones. First 2 bugs seem easily discoverable by syzkaller/syzbot with a bit of extra descriptions. 3rd one is likely as well ⤵️
The USB exploit chain targets mainline Linux kernel drivers, potentially affecting devices across all Android vendors. At least five different USB device type types were used as part of the exploitation process. More exploit details are shared in our blog post [image]
Each of these is an upstream Linux kernel vulnerability: * CVE-2024-53104: heap overflow in a Linux kernel USB webcam driver * CVE-2024-53197: heap overflow in a Linux kernel USB sound card driver * CVE-2024-50302: uninitialized heap memory in a Linux kernel USB touchpad driver
Interesting - @AmnestyTech found some cases where confiscated Android phones were unlocked with Cellebrite's forensics tech, and shared traces with Google TAG, who identified three bugs in various Linux kernel USB device drivers https://securitylab.amnesty.org/ ...
@AmnestyTech Also, Android apparently doesn't have a USB restricted mode equivalent? You can just rawdog the entire set of Kernel drivers from the USB port by default?! Yikes.
GrapheneOS blocks reaching any of these vulnerabilities for locked devices through our USB-C port and pogo pins control feature disabling new connections at a hardware level and a software level after locking along with disabling USB data in hardware too: https://grapheneos.org/.…
NEW: Google fixed three zero-day vulnerabilities in Android that were used by authorities to unlock phones with Cellebrite forensic tools. The fixes come after Amnesty alerted Google, following the analysis of a Serbian student protester's phone. https://techcrunch.com/...