THIS IS ABSOLUTELY CRAZY! I have personally tested this on my Non-pixel Android 12 device and it works.
My findings:
- The exploit works even on first pwd input screen on boot. however, the filesystem is still encrypted and cannot be accessed by any means (ADB/MTP). launcher does not load fully. but settings and other things accesible from notification panel can be launched (BT/Hotspot etc). you can get list of installed apps and many other sensitive informations that are not stored in /data/media/0/.
- adb can be connected. shell can be launched but data partition is not accesible.
- mtp initializes but does not load.
I guess although one cannot access the user data, the ability to access/control other parts of system potentially exposes a huge attack surface.