PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
March 26, 2026Forensic Science International Digital Investigation0 citationsOpen Access

The investigator's friend and foe: A forensic analysis of GrapheneOS

View Full Paper
KRKatharina De RentiisJGJulian GeusFFFelix Freiling

Key Points

  • This analysis aims to evaluate GrapheneOS in terms of security, privacy features, and its impact on forensic investigations.
  • Conducted a forensic analysis specifically on GrapheneOS.
  • Reviewed security and privacy features of GrapheneOS compared to standard Android.
  • Performed a data acquisition analysis involving tool support for GrapheneOS.
  • Executed a network traffic analysis to assess data interaction.
  • GrapheneOS shows enhanced security features compared to standard Android.
  • Privacy features of GrapheneOS significantly hinder remote data acquisition efforts.
  • Findings support that privacy-focused OSs complicate forensic investigations.

Abstract

Due to differing hardware and software security mechanisms, the forensic analysis of smartphones is strongly device-dependent. Given their prevalence in forensic investigations, the research community and tool manufacturers have focused primarily on devices with standard Operating Systems (OSs) from major manufacturers. Consequently, privacy advocates promote devices based on highly configurable OSs, such as the Android Open Source Project (AOSP), or custom ROMs like GrapheneOS, which prioritize privacy and security. These OSs benefit investigators in both private use and covert investigations. However, they present a significant challenge when used by the opposing side. To properly assess the situation, we conduct the first forensic analysis of GrapheneOS: We give an overview of AOSP and the custom ROM ecosystem. We also explain security and privacy features of GrapheneOS and how they compare to Android's. Finally, we perform a data acquisition analysis, including tool support for GrapheneOS, and a network traffic analysis. Our results demonstrate that GrapheneOS improves upon Android security, and that its privacy features considerably complicate the remote acquisition of user data.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Rentiis et al. (2026) studied this question.

synapsesocial.com/papers/69c4cd5afdc3bde448919896https://doi.org/10.1016/j.fsidi.2026.302048
Ask AI
Helpful
Bookmark
Share
View Full Paper

Also Consider

Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context:

  1. 1You Can't Always Get What You Want: Towards User-Controlled Privacy on Android2022 · 10 citations
  2. 2Android permission system and user privacy — A review of concept and approaches2017 · 24 citations
  3. 3Data acquisition techniques in mobile forensics2018 · 42 citations
  4. 4Mobile Forensics Data Acquisition2022 · 4 citations
  5. 5Survey on Mobile Forensics2015 · 18 citations