Mobile Forensics: What Can Be Recovered from an iPhone and Android
By Juan Jesús Merino Carretero, chartered computer engineer no. 89 (CPIIEX) mobile phone · iPhone · Android · computer forensics
Forensic analysis of a mobile phone is one of the most requested expert services: divorces with disputes over conversations, dismissals for misuse of a company phone, harassment cases, financial scams or internal investigations at a company. The recurring question is what can really be recovered and what the difference is between an iPhone and an Android in forensic terms. This guide gives a complete overview.
What mobile forensic analysis is
It is the extraction and analysis, using forensic methodology, of the information contained on a mobile device. The extraction is done with write blocking, certified tools and a documented chain of custody. The analysis is done on the copy, not on the original device. The result is set out in an expert report that can be defended in court.
The expert has four main questions to answer:
- What information is on the phone.
- What information has been deleted and can be recovered.
- When and from where the key data was generated.
- Who was operating the phone at each moment (when it can be deduced).
What can be extracted from a phone
Communications
- Instant messaging: WhatsApp, Telegram, iMessage, Signal, Messenger, Instagram DM, SMS, MMS. Includes deleted messages that are still in the SQLite database.
- Calls: log of incoming, outgoing and missed calls, duration, associated contacts. In some cases, call recordings if they are stored locally.
- Email: configured accounts, downloaded messages, attachments.
Activity and patterns
- Browsing history: URLs visited, searches, bookmarks, cookies.
- Installed and uninstalled apps: full list with dates.
- Notifications: recent records (limited in modern versions for privacy).
- Usage patterns: hours of activity, most-used app, screen time.
Multimedia
- Photos and videos: including those deleted from the gallery but still present in cache or local backups.
- Audio files: recordings, voice messages.
- Screenshots: with their EXIF metadata (date, time, geolocation if enabled).
Location and movement
- Geolocation: GPS history (on iPhone, “Significant Locations”; on Android, “Google Timeline”).
- Known WiFi networks: networks the phone has connected to, in chronological order.
- Bluetooth: paired devices.
Identity and accounts
- IMEI and serial number of the device.
- Configured accounts: Apple ID, Google, Facebook, etc.
- SIM cards inserted (history).
Files and documents
- Downloaded files: PDFs, Office documents, images.
- Downloads folder and cache.
- Cloud sync: iCloud Drive, Google Drive, Dropbox.
Differences between iPhone and Android
| Aspect | iPhone (iOS) | Android |
|---|---|---|
| Encryption by default | Yes (AES-256 with TEE) | Yes since Android 6+ |
| Access without a passcode | Almost impossible on modern models | Varies by brand/model |
| Depth of extraction | Limited by iOS security | Deeper with root or exploits |
| Useful backups | iCloud / iTunes backup | Google backup + Helium |
| Recovery of deleted data | Good up to a point | Better on Android without TRIM |
| Useful geolocation | Significant Locations, photo EXIF | Very detailed Google Timeline |
| Messaging apps | WhatsApp, iMessage, Signal | Same + manufacturer apps |
iPhone
iOS has a very high level of encryption and security. Without the unlock code, on recent models (iPhone X and later) a deep extraction is not feasible with legal and commercial methods. What the expert work does allow:
- Access with the holder’s passcode and a signed voluntary transfer record.
- Analysis of local iTunes backups (encrypted or not).
- Analysis of iCloud with the holder’s credentials.
- AFU (After First Unlock) extraction if the phone is on and has been unlocked at least once since the last restart.
Android
Extraction depends on the manufacturer, the Android version and whether the phone is rooted. In general:
- Logical extraction with ADB authorized by the holder.
- Physical extraction with exploits for some older models.
- Analysis of a full backup with tools such as Magnet AXIOM or Cellebrite UFED.
- On Android without TRIM, recovery of deleted files is notably better than on iPhone.
Typical cases and what can be recovered
Case 1: divorce with suspected infidelity
- WhatsApp messages and other messaging apps.
- Call history with duration and times.
- Geolocation (frequent locations and times).
- Photos and videos with EXIF metadata.
- Dating apps installed/uninstalled with dates.
Case 2: dismissal for misuse of the company phone
- Browsing history.
- Time spent in each app (especially non-work apps).
- Communications with competitors or third parties.
- Files sent from the phone.
- Geolocation during working hours.
Case 3: extortion or blackmail
- Conversations with the extortionist.
- Analysis of email headers.
- Audio recordings.
- Identification of accounts associated with the extortionist.
Case 4: identification after loss or theft
- Last known location.
- Access to the cloud with the holder’s credentials.
- Identification of new SIM cards.
What can NOT be recovered
It is important to be realistic. There are absolute technical limits:
- WhatsApp conversations that were deleted and then followed by a factory reset of the phone.
- Information on a locked iPhone whose passcode is unknown.
- Photos in iCloud purged by the owner more than 30 days ago.
- “Disappearing” messages on Telegram or Signal, once the period has expired and the device has been restarted.
- Information in apps that encrypt data locally with a key that is lost on restart (Signal, some WhatsApp configurations).
Chain of custody in mobile expert work
The protocol is the same as for any digital evidence, with two particularities:
- Airplane mode or a Faraday cage during extraction to prevent the device from receiving remote commands (remote wipe, corporate MDM).
- Documentation of battery and connectivity status when collecting the phone.
More detail in our guide to digital chain of custody.
Frequently asked questions
Can I hand you my partner’s phone for you to examine?
Only if they hand it over voluntarily and sign the transfer record. Accessing someone else’s phone without authorization is a crime (art. 197 of the Spanish Criminal Code).
How long does the expert work take?
From 5 days for WhatsApp validations to 3-4 weeks for complex engagements involving analysis of multiple apps and recovery of deleted data.
Will my phone be damaged during the extraction?
No. The extraction does not open or damage the device. It is done through the phone’s standard interfaces with write blocking.
What if the phone has parental controls or corporate MDM?
The work must be coordinated with the MDM owner (the company) to prevent the device from being wiped during the extraction.
Is an iCloud or Google backup valid without having the physical phone?
Yes, with less depth but valid. It is the option when the phone has been lost or destroyed.
Conclusion
Forensic analysis of a mobile phone can provide decisive evidence in civil, criminal, labor and family proceedings. The possibilities depend on the model, operating system, encryption status and physical condition of the device. At Forenlab we carry out iPhone and Android expert work with AFU extraction, recovery of deleted data, WhatsApp analysis and documented chain of custody. Contact us and we will assess your case in under 24 business hours.