While this is true, you can tune the work factor of PBKDF2 accordingly. On the positive side, it's easier to argue for PBKDF2 in face of regulations since it's a standard while scrypt is not.
That still does nothing for the fact that a GPU will be thousands of times faster than a mobile.
SQLCipher uses PBKDF2 as a standard mechanism to compute a key, however by default it uses a static iteration length, currently 64,000.
The problem is often that the device spread varies greatly and often a given application will target more than one device. You can watch our presentation covering the details here:
https://www.youtube.com/watch?v=b8TNHZ7fWzg&list=PLdIqs92nsI...