Skip to content
MDA-042 Mobile Devices & Apps

Could rooting or jailbreaking affect the reliability of the device?

Yes. Rooting or jailbreaking can affect how confidently investigators interpret a device.

What this means

These modifications remove or bypass some of the operating system’s normal restrictions.

That may allow system files to be changed, protected areas to be accessed and software to run with wider permissions than usual.

The danger is not that every modified device is unreliable.

The danger is assuming that standard behaviour, logs and security controls still apply without checking.

A rooted or jailbroken device may contain altered system files, modified timestamps, non-standard applications, disabled security features or tools capable of hiding, changing or exporting data.

It may also be more exposed to malware or unauthorised remote access.

Specialist examination may be needed to assess the operating-system state, installed packages, privilege changes, system integrity and relevant artefacts.

Corroboration becomes especially important.

Provider records, cloud data, network logs, witnesses and other devices may help confirm or challenge what appears on the handset.

What to check or do next

  • Investigators should distinguish possibility from proof.
  • Look for evidence of what was actually changed, when the change occurred and whether it affected the material relied upon.
  • Do not attempt to restore, update or reverse the modification during routine handling. That would alter the device further.

Evidential limits

But modification alone does not prove that evidence was fabricated, deleted or manipulated.

The operational takeaway is: rooting or jailbreaking increases the need for specialist interpretation and corroboration. It raises questions about system integrity, but it does not automatically invalidate all evidence on the device.

Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.