Then they can unlock the actual device.
Then they can unlock the actual device.
This is why phone cracking devices like Cellebrite rely on exploits in phones rather than just cloning the disk and trying the small number of possible passcodes.
If your device's encryption key is produced by a PBKDF then yes it's doable, but no actually secure system works like that. The way a secure system works is
1. You have an HSM ("Secure Enclave" in Apple speak, Trusted Computing Module in MS speak, and I can't recall the google/android name)
2. The HSM generates a random encryption key (or family of keys)
3. The HSM encrypts and decrypts the data with those keys (the keys themselves never leaving the HSM)
4. The HSM gates access to those keys based on an attempt limited use of your passcode/password
There were common flaws a few years ago that meant that you could glitch the HSMs into (essentially) not incrementing the attempt counters or similar but I haven't heard of such in a few years now (almost a decade now? essentially these kinds of flaws were discovered en mass once HSMs reached consumer hardware so more security researchers were able to investigate)
The important thing though is the encryption key is now fully random, rather than derived from your password, which is the difference between a 128+ bit key and a ~40-60 bit key.
I guess if they really wanted to they could attempt to decap the chip and do something with a hardware attack, but thats difficult and dangerous.