From Wikipedia, use of PBKDF2 leaves this vulnerable to GPU based fast dictionary attacks (versus eg: scrypt that is a deliberate RAM hog).
Other than that, this strikes me as a very nice way to get seamless, strong encryption for mobile or desktop apps (where data at rest needs to be protected) without writing a single line of crypto code.
That still does nothing for the fact that a GPU will be thousands of times faster than a mobile.
SQLCipher uses PBKDF2 as a standard mechanism to compute a key, however by default it uses a static iteration length, currently 64,000.
The problem is often that the device spread varies greatly and often a given application will target more than one device. You can watch our presentation covering the details here:
https://www.youtube.com/watch?v=b8TNHZ7fWzg&list=PLdIqs92nsI...