I should mention: Cellebrite's methods would tend to walk completely around whatever the phone thought was a normal, good idea.
When the usual manufacturer-prescribed method for reading contacts said to take some long-winded steps to put the phone into a special mode, Cellebrite's hardware just usually skipped that shit and read the data very directly without any fuss.
Plug it in, push the button, and the Cellebrite box just did the appropriate magic. It then interpreted the data and munged it into a useful form to shove into the next phone.
After that: The recovered personal data was pushed right up into the ass of the next phone with the same lack of consent. It was succinct and brutal in operation.
And: It worked. It was so dead-nuts simple that a cell phone salesperson could run it with ease. I stopped getting phone calls from the field about transfer problems when we started using Cellebrite kit.
Nothing else did this stuff with that measure of resolute nonchalance.
So at this point they've been uniquely hooning with cell phones for decades. It's kind of their schtick.
If we can speculate that something like the the USB-C charge rate negotiation on a given phone can open a pathway into the system, then it can be safe to say that Cellebrite is already using that method to get things done -- and that a person at the border can exploit it even if they're "not a tech person".
Simplifying these kinds of hacks is what they do.