
Sim, nos casos de zero-day usados pela Cellebrite para aparelhos bloqueados, são vulnerabilidades desconhecidas pelo Google (e fabricantes) até serem descobertas e reportadas. Exemplo recente: chain de exploits em drivers USB do kernel Android (como CVE-2024-53104), usada por autoridades na Sérvia, conforme relatório da Anistia Internacional de 2025. O Google só corrigiu após notificação — sem ação da vítima, só conexão física. Depende da versão do Android; em patches recentes, fica mais difícil.
Post summary
CVE‑2024‑53104, a zero‑day affecting Android USB driver kernels, has been actively exploited by authorities in Serbia, and Google later patched the flaw after notification. No proof of concept or exploit tool was cited, and the report does not debunk the vulnerability.
