# Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer from an app's perspective

DevFeed: [Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer from an app's perspective](<https://devfeed.tech/articles/exploiting-vulnerabilities-in-cellebrite-ufed-and-physical-analyzer-from-an-app-s-perspective-1745.md>)

Original publisher: [Read original article](<https://signal.org/blog/cellebrite-vulnerabilities/>)

Published: 2021-04-21T00:00:00Z

Content type: article

Language: en

Sources: [Signal Blog](<https://devfeed.tech/sources/signal-blog.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Security](<https://devfeed.tech/topics/security.md>), [Mobile](<https://devfeed.tech/topics/mobile.md>), [Android](<https://devfeed.tech/topics/android.md>), [Windows](<https://devfeed.tech/topics/windows.md>), [iphone](<https://devfeed.tech/topics/iphone.md>), [Software](<https://devfeed.tech/topics/software.md>), [Parsing](<https://devfeed.tech/topics/parsing.md>)

Tags: [android](<https://devfeed.tech/tags/android.md>), [hardware](<https://devfeed.tech/tags/hardware.md>), [iphone](<https://devfeed.tech/tags/iphone.md>), [mobile](<https://devfeed.tech/tags/mobile.md>), [parsing](<https://devfeed.tech/tags/parsing.md>), [security](<https://devfeed.tech/tags/security.md>), [software](<https://devfeed.tech/tags/software.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [windows](<https://devfeed.tech/tags/windows.md>)

## AI overview

The article examines Cellebrite's UFED and Physical Analyzer software, explaining how the tools extract, index, parse, and display data from physically accessible mobile devices. It focuses on Cellebrite's support for Signal and the security implications of its products.

## Source excerpt

Cellebrite makes software to automate physically extracting and indexing data from mobile devices. They exist within the grey - where enterprise branding joins together with the larcenous to be called "digital intelligence." Their customer list has included authoritarian regimes in Belarus, Russia, Venezuela, and China; death squads in Bangladesh; military juntas in Myanmar; and those seeking to abuse and oppress in Turkey, UAE, and elsewhere. A few months ago, they announced that they added Signal support to their software. Their products have often been linked to the persecution of imprisoned journalists and activists around the world, but less has been written about what their software actually does or how it works. Let's take a closer look. In particular, their software is often associated with bypassing security, so let's take some time to examine the security of their own software. Read more...