• News/
  • https://www.bleepingcomputer.com/news/security/serbian-police-used-cellebrite-zero-day-hack-to-unlock-android-phones/

Serbian police used Cellebrite zero-day hack to unlock Android phones

BleepingComputer
·
Bill Toulas
·
Published Feb 28, 2025
·
Updated

Serbian authorities have reportedly used an Android zero-day exploit chain developed by Cellebrite to unlock the device of a student activist in the country and attempt to install spyware. Cellebrite is an Israeli digital forensics company that develops tools used by law enforcement, intelligence agencies, and private companies to extract data from smartphones and other digital devices. Companies like Cellebrite commonly utilize zero-day exploits to access and extract data usually protected on locked phones. The use of this Android exploit was found by Amnesty International's Security Lab in mid-2024 during forensic research on the logs of the impacted device.

The organization previously reported on cases of privacy rights abuse in Serbia in December 2024. In response to the revelations, Cellebrite announced it blocked access to its tools for the country's security services (BIA) earlier this week. After Amnesty shared its findings with Google's Threat Analysis Group (TAG), Google's researchers were able to pinpoint three vulnerabilities in the Linux kernel USB drivers, also used in Android, that were exploited as zero-days. The three flaws are: The first flaw was patched in Google's February 2025 Android security updates, marked as "under limited, targeted exploitation." The other two flaws have not been announced as fixed in any Android security update bulletins yet, and depending on the device model and how often manufacturers update its kernel, it might take a while. He...

Read full article

Affected Software

2 affected components
Google Android
Google Android
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What was the main topic of the article?

The article discusses how Serbian police utilized a Cellebrite-developed zero-day exploit to unlock Android phones.

2

What security implications are raised in this article?

The article highlights concerns over the use of zero-day exploits by law enforcement and the potential for misuse of digital tools for surveillance.

3

Which products or software are specifically affected by the exploit?

The exploit specifically targets devices running Google Android.

4

What was the purpose of the Serbian police using the zero-day exploit?

The Serbian police used the exploit to unlock a student activist's phone and attempted to install spyware.

5

Who developed the zero-day exploit used by the Serbian police?

The zero-day exploit was developed by Cellebrite, an Israeli digital forensics company.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203