From https://cellebrite.com/en/blog/the-access-gap-is-closed-what... :
Here’s what that looks like in practice in 2026:
iOS: Cellebrite supports access to the latest iPhone models and iOS versions, including both after-first-unlock (AFU) and before-first-unlock (BFU) states. Recent updates have introduced new AFU access methods for previously unsupported iOS device configurations, expanding the range of devices that can be accessed without requiring a prior unlock event.
Android: The latest releases restored and expanded full file system (FFS) extraction across a broad range of newer Android models, which is an area where the competitive landscape had seen fluctuation. Coverage now spans Samsung, Google Pixel and other major Android manufacturers at their current OS versions.
Actual hardware 0-days are highly coveted, extremely expensive, military classified tools that TSA does not have access too and never will.
Edit: CBP not TSA (thanks good callout)
The info extracted is the nuance your missing here. Cellebrite doesnt break encryption, it brute forces weak PINs and passwords and collects metadata thats outside of the protected volume.
Your online activity likely exposes much much more about you than the data extracted by Cellebrite. These distinctions matter as its really easy to misunderstand and sensitionalize their tools.