If I were an Apple security employee I would be checking the Cellebrite devices with my team and work on fixing any issue. Reverse engineering and debugging.
Yes, assuming you can get access to one. Do you think Cellebrite would knowingly sell one to Apple?
IIRC you don't even buy them they're all subscription based.
Perhaps I’m just naïve, but it seems unlikely that Apple couldn’t figure out some way or another to get ahold of them given the resources at their disposal. They could employ a full team whose only purpose is to reliably source Cellebrites by whatever means necessary and the cost wouldn’t even be a rounding error.
I would be mind-blown if Apple didnt have any and all of those devices (assuming that they're actually interested in security).
A company the size of Apple has ways of acquiring the devices.
If college campuses routinely have their own "police department" surely, Apple HQ Security could expand to have a law enforcement agency?
Cellebrite won't sell that thing to most police forces (they might sell the service to them, in a way where they don't get their hands on the actual exploits), so I'd assert that it is tricky for Apple to get this. This is also supported by the fact that Apple has systematically not been able to timely patch the vulnerabilities used by Cellebrite.
They could get lucky and find one that fell off of a truck.