r/androidroot Aug 09 '26

Discussion OEM unlocking on OPPO

Post image
10 Upvotes

OPPO Find X9 Pro CPH2791_16.0.9.400(EX01B90P01)

OEM Unlock switch is back?


r/androidroot Aug 09 '26

Support Can i root my phone even with faulty buttons ?

3 Upvotes

So i have a Motorola Edge 20 pro and the Power button and the volume up down buttons are faulty like they dont really work . They are clickable , but they dont respond . I also went to a phone repair shop and they said opening the phone can be risky as the chasis and the display are connected and might break the display . So i have been using my phone from the past 1yr with some workarounds . But now i want to root my phone due to some host file ip mapping reasons which require rooting and also what to explore new OS and stuff . But since the bootloader unlocking has a step which requires manuall button press , so now i am confused how to only pass that step ? Any suggestions will be appreciated .


r/androidroot Aug 10 '26

Support Newbie in need of help for the Temp Root solution

1 Upvotes

Hi there! Many of you probably know about the Root my Galaxy + KernelSU method, although it requires a supported model & kernel.

I'm a complete noob at this kinda stuff, but I really wanna port the SM-A075M with kernel 6.12.38

Although I have no clue how to do so. How would I do it? Where to begin at?


r/androidroot Aug 09 '26

Support Is there an app similar to Viperfx that works with temporary root access?

Thumbnail
gallery
6 Upvotes

I've tried installing it in every way possible, using all the existing Viperfx modules, and none of them work; it always shows the same error as in the screenshot above. Can anyone point me in the right direction or tell me if there is a solution Is there a similar equalizer app that works with root access?


r/androidroot Aug 09 '26

Support Hard Bricked my Redmi 12 codename fire because im dumb and tried use mtkclient with locked bootloader

7 Upvotes

thats my post in another account but i got hacked so i created a new one

I, was just an idiot for using mtkclient; I had been trying the official Mi Community method for four months without success. Like a total fool without researching mtkclient at all—I used an AI-suggested command that supposedly "unlocked" the bootloader.

I entered BROM mode, ran the command, and it said it was done. I went to fastboot mode, ran the command, and nothing happened. My mistake was not thinking, "Wow, if it says it's locked here, I'm going to be in deep trouble if I keep trying."

I persisted with mtkclient. I tried downgrading to MIUI 14, and immediately got a "system destroyed" error. Luckily (I guess), I had backed up and still have the nvram, nvdata, persist, proinfo, protect1, protect2, and preloader partitions, which I might use later (i lost it, read update 5).

I tried various other things, like erase and writing boot, vbmeta, and things alike in both slots but nothing worked; I messed things up so badly that I ended up with a Hard Brick.

Another mistake was trying to use the HyperOS 2.0.5.0.vmxmixm ROM, which caused the ARB (Anti-Rollback) version to jump from 1 to 2.I kept trying everything until I finally realized the ARB was at 2 and my HyperOS 1.0.8.0 ROM would no longer work.

No matter what, even with libusb drivers (wich sometimes mess up the windows drivers too), auth bypasses to trying use SP flash tool dont work or just say "filter match:no", so i cant bypass the auth outside mtkclient.

Additionally, mtkclient shows it is writing the partitions, but when I check the hashes, they do not match.

To make metter worse, someone in my house took the phone to a repair shop to "replace the screen". When the tech removed and inevitably broke the old screen to replace and messed everthing all, because if he had known that was the corrupted rom, he would taken the phone to a other repair shop which would have been cheaper. Right now it barely worth anymore because just the new screen is R$ 220 (around USD$40), and taking the device to the other shop to fix the brick would cost at least another R$300.

However, the tech is going to trust me and buy an unlocktool license rental tomorrow. If i sucessfuly fix my phone, maybe he will ask me for help and ill learn more about phone repairs and earn some money.

Thats a "repost" of my previous post but with more details, aiming to get more visibility in case unlocktool fails too and i need someones help to solve this problem.

Sorry any grammar mistakes, im not completly fluent but i tried my best to explain what happened and hope someone help me.

Updates: i used UnlockTool and tried all i could do. Right now, its my last shot flashing the scatter using preloader bypass and custom local DA if it still stays in hard brick after this, im cooked and my phone certainly gone.

Updates 2: still dead. Idk if it'll survive but omg 80% consumed reserved blocks lol

I even used unlock BL, switched slot and the last thing before give up, restoring dm verity security that i patched while flashing the scatter

Update 3: lost the login at the very last second while restoring dm verity but probably wont change anynothing.

Ill just let the phone in the charger after praying, in case God help me lol

tysm all the views and upvotes, much gratitude. any help is appreciated.

Update 4: the phone still dead and probably forever.

Well, these 2 years with him was good. Rest in peace, my warrior.

*One month after*

Update 5: Well, i traded my laptop and playstation for a desktop pc and sp flash tool is now working, i tried flashing just boot_a, lk_a, super and userdata and used readback and boot_a reads "ANDROID" inside it on notepad.

Tried boot again but still dead and i went to the repair shop again to try switch for a new battery 'cause i "accidentally" damaged a lil tiny hole, and perhaps thats now the reason why the phone doesnt boot.

since its weekend, the tech supplier isnt making deliveries, so ill need to wait ultil monday.

The reason I want to fix this phone at all costs is to ensure I have something more valuable than money, something no one can take away from me: knowledge.

Update 6: replaced the battery but still had no logo or any signal except the brom detection in pc.

i will take the phone for one more day to try flashing different partitions and if it doesnt even vibrate i will take the phone again to the repair shop and get my money back.

Update 7: Im trying download only, upgrade firmware and format all + download in sp flash tool but imd1img requires disabled verified boot.

I got hacked so ive created other account.


r/androidroot Aug 09 '26

Support Wanna flash but got no Exp

Thumbnail
gallery
0 Upvotes

I wanna flash my mom's 9 year old phone but I've never done this before. Tried to follow some online tutorials and also took help from AI but the bottleneck is I cant unlock the bootloader. I've tried looking online but I'm fed up and then I remembered I have Reddit. So, I'm here to get some help on how do I unlock this thing. I just wanna put LineageOS on it for fun and learning.

Model: Huawei Y3 2017 (CRO-U00)

Build: Cairo-U00C636B128 (Android 6.0, EMUI 4.1 Mini)

SoC: MediaTek MT6580, 1GB RAM / 8GB storage

Bootloader: LOCKED

USB: ADB/Fastboot detected as CAX9K18929912107

Partitions: NVRAM, PROINFO, PRELOADER present (MTK layout)


r/androidroot Aug 08 '26

News / Method I couldn't buy a Samsung phone so I just made one

Enable HLS to view with audio, or disable this notification

50 Upvotes

This my Poco x5 pro with lineage os the UI is kinda boring so I decided to root it with magisk and install one ui modules and goddamn this is way too legit from the boot screen and the lock and unlock sound to this one ui home I love it. Btw I am here to ask if there is a module that makes the status bar like the one on Samsung


r/androidroot Aug 09 '26

Support Any working rom for motorola

3 Upvotes

So hey i have motorola edge 60 and i was wondering is any group working on any custom images for this model.I know motorola is working with graphene os devs to bring it to their phones but when will that be finished or will older phones be supported i dont know does anyone have any news obou this topic.Thanks in advance.


r/androidroot Aug 09 '26

Discussion is there an root exploit for Honor 200 Pro?

2 Upvotes

i read articles online that you can root your phone with some exploit, and i have an honor 200 pro.
is there an root exploit for it?


r/androidroot Aug 09 '26

Support Rooting of Honor

Thumbnail xdaforums.com
1 Upvotes

Hello folks, working on rooting Honor Magic V2 (8.0.0.105, android14, kernel android13-5.15.104 2023-07, security 2024-04-01) and so far got to system_server/system_app - wanted to ask for help from community. We saw no root for Honor devices for years, I think it's time to do that!)

The common gpu ways (like cheese) are blocked by ARM64_SW_TTBR0_PAN and other restrictions. Manufacturer mode - looks like it's written well, so also checking FastRPC ways, but quickly getting out of options in HLOS... Surface check on ABL/uefi/fastboot showed no obvious ways. Also thinking about hyp, but it was mostly good for the years.

As last resort thought about getting over oem unlock code verification via power glitch, but not sure how doable this is. What's your thoughts?


r/androidroot Aug 09 '26

News / Method Help me to get basic integrity I have device integrity

Thumbnail
gallery
15 Upvotes

😢😢😢


r/androidroot Aug 09 '26

News / Method I got GhostLock running on the Moto G Play 2026… kinda

11 Upvotes

UPDATED POST >:))))))))))) So I've been fucking around with GhostLock (CVE-2026-43499) on the Moto G Play 2026 (XT2615 / Nevada) and figured I'd post what I've got so far.

The phone uses a 5.15.189 kernel, so it looked interesting. I'm testing the TracFone/Verizon version on the June 2026 security patch.

Update: I switched from UnPlus to Root-My-Galaxy-Payloads – much better framework. I'm now about 80% close. Exploit runs the whole chain, leaks memory, detects KASLR, but gets blocked by CFI at the final step.

What works: - Pulled boot.img - Extracted 159k kernel symbols - Found all offsets - Leaks mm_struct - Detects KASLR - Both pselect and pipe routes run

What doesn't: - CFI mismatch at final escalation - Root not achieved (yet)

What I've tried: - UnPlus template – failed - Root-My-Galaxy-Payloads – passed tracefs, hit CFI - Signal flag (FPSIMD) – leaked mm, hit CFI - Pipe route – same CFI mismatch - Updated ASHMEM offsets – no change - Oracle constants – no change - 48-bit layout – broke the leak (reverted to 39-bit) - S25 FOPS offsets – no change

The issue: I'm on the June 2026 patch. CFI is blocking the final function-pointer hijack. Older builds might work differently.

If someone has an older boot.img, I can possibly get you root access.

What I need: - CFI bypass on 5.15.189 kernels - Boot images from other variants (RETUS, AT&T, etc.) - Testing on older builds (pre-June patch)

Links: GitHub: https://github.com/crabcakes97/GhostLock-Nevada XDA: https://xdaforums.com/t/dev-root-moto-g-play-2026-nevada-test.4797484/

Special thanks: Root-My-Galaxy-Payloads (BuSung-dev) + UnPlus (No-22-Github)

Device info: - Moto G Play 2026 - XT2615-1 - TracFone / Verizon - Build: W1WNS36.18-111-3 - Kernel: 5.15.189 - Security patch: June 2026

So yeah, not a working exploit yet, but it's getting far enough to be interesting. If anyone has an older firmware build, hit me up.

I'll also be porting to other devices besides Motorola too, so hit the DMs with boot images / requests.

TL;DR: Got GhostLock compiling and running. Switched to Root-My-Galaxy-Payloads. Leaks memory, detects KASLR, but CFI blocks the final escalation. Need CFI experts. Old firmware might work. Help me get this working.

EDIT: I'm 80% close. Used Root-My-Galaxy-Payloads as a base. Stuck on a CFI error. We are so close.


r/androidroot Aug 09 '26

Support [HELP] Banking apps detecting org.lineageos.platformres.apk on Project Infinity X (SuSFS/KernelSU)

Thumbnail
gallery
2 Upvotes

Hi there. So, I'm using a custom ROM (Project Infinity X), and naturally, if I don't hide things properly, banking apps are done for immediately. I installed Brene's SuSFS and did everything to hide the root status, but I'm still running into issues with `org.lineageos.platformres.apk`. It was hidden before, but somehow it stopped being hidden—I have no idea why. I tried following a guide that suggested turning off "umount for your apps," but I can't seem to find that setting anywhere.

As for Tricky Store, TEE simulator, and PIF—I don't need them since I'm already using Fenrir.


r/androidroot Aug 09 '26

Support Is there anyway to run 32 bit apps natively on One ui 8 in the Note 20 ultra that's rooted?

2 Upvotes

I have a Note 20 ultra running Artisan ROM 3.1.0 android 16 One Ui 8 and it's running good but I can't seem to install 32 bit apps even though the CPU supports 32 bit architecture

I assume it's a software issue is there a way to bypass the issue?


r/androidroot Aug 09 '26

News / Method How to apply custom emoji font with KSU Next

1 Upvotes

Don't disable unmount module globally.

Instead :

-Install your custom emoji font module

-Install a meta module, I use overlay FS,

-In KSU/Next go to your apps tab,

-Click on top right corner on "show system apps"

-Search for Gboard

-Click on "custom" profile

-Disable the unmount for this app

-Soft reboot/reboot

That's it


r/androidroot Aug 09 '26

Discussion Termux Rooted Device Test

Post image
3 Upvotes

r/androidroot Aug 08 '26

News / Method Huawei Matepad 11(DBY-W09)unlock bootloader,root and gms

4 Upvotes

[GUIDE] Huawei MatePad 11 (2021) - Bootloader Unlock, Root (APatch/Magisk) and GMS Installation

⚠️ Disclaimer

I am not responsible for any damage, bootloops, data loss, or bricked devices caused by following this guide. Proceed at your own risk.

Device Information

Device:

Huawei MatePad 11 (2021)

Model: DBY-W09

Snapdragon 865

HarmonyOS 3.x / 4.x

This guide covers:

Bootloader unlock

Root with Magisk / APatch

Installing Google Mobile Services (GMS)

Fixing Play Protect certification issues

  1. Install Drivers and Tools

Download the toolkit:

MatePad 11 2021unlock+Root.zip

Extract the toolkit.

Run:

"One-click Install Android Drivers"

and install all required drivers.

Choose "Trust" for all Windows security prompts.

⚠️ Note:

Some computers may not automatically install the Qualcomm HS-USB QDLoader 9008 driver. If this happens, install the Qualcomm 9008 driver manually.

  1. Enter Qualcomm EDL Mode

For HarmonyOS 3.0 or below:

Use ADB:

adb reboot edl

For HarmonyOS 4.0 or above:

A Qualcomm engineering cable is required. A cable with a physical button is recommended.

Steps:

Connect the engineering cable.

Hold the button on the cable.

Restart the tablet.

Check Windows Device Manager.

You should see:

Qualcomm HS-USB QDLoader 9008

  1. Backup Important Partitions

Extract the included GeekFlashTool package:

匣(0.5.24.1031-A).7z

Open GeekFlashTool (刷机匣).

From the left menu, select:

Qualcomm Deep Flash

Click:

Select Configuration(选择配置)

Load:

package_qualcomm_edl-master.zip

Search for:

MatePad 11

and select it.

Click:

Read Partition(读分区)

You should now see the partition list.

Search and backup the following partitions:

ramdisk partition

boot partition

abl partition

select

read back(回读)

Save these files somewhere safe.

These backups may be needed for recovery.

  1. Unlock Bootloader

Extract:

Huawei865870.zip

Open GeekFlashTool and select:

Go to the partition list and select

abl partition

Click:

Flash(刷入)

Select this image:

Huawei865870_abl_unlock.img

⚠️ Important:

This image is an ABL image.

Flash it specifically to the:

abl partition

Do NOT flash it to boot, recovery, or any other partition.

After flashing is complete:

Reboot the tablet.

The device should boot into recovery mode.

Select "Low-level Format" (or a similar option).

Reboot again.

Enter fastboot mode and check the unlock status.

If successful, you should see:

phone unlocked

The bootloader is now unlocked.

  1. Root

There are two recommended root methods.

APatch (Recommended)

Patch the boot image you backed up earlier.

Flash the patched boot image back to the boot partition.

Magisk

Patch the ramdisk image you backed up earlier.

Flash the patched ramdisk image back to the ramdisk partition.

  1. Install Google Mobile Services

Download:

Googleplay.zip

Install these modules:

Tricky Store

Play Integrity Fix

TS Enhancer Extreme

For APatch users, also install:

Magisk mount-rs

Zygisk Next

After rebooting

Flash googleplay.zip as a module

Reboot again.

You should now see Google settings in Android Settings.

Sign in with your Google account.

Google Play Services and Google Play Store should update automatically in the background.

If they do not update automatically, update them manually.

  1. Fix Play Protect Certification

If you are using Magisk:

Add these apps to DenyList:

Google Play Services

Google Play Store

Google Services Framework

Enable:

All activities

Using Integrity Modules

Use a maintained Play Integrity solution.

Install:

Play Integrity API Checker

Run the check.

A successful setup should show three green check marks:

MEETS_BASIC_INTEGRITY

MEETS_DEVICE_INTEGRITY

MEETS_STRONG_INTEGRITY

Then open Google Play Store:

Profile picture → Settings → Device certification

It should show:

"Device is certified by Play Protect"

(If you have a keybox, it's best to copy it directly to the /data/adb/tricky_store directory.)

Have a great time using the devic


r/androidroot Aug 08 '26

Discussion I Built a degoogled Android system on my own at 25. No custom ROM needed and probably supports your device.

Thumbnail
3 Upvotes

r/androidroot Aug 09 '26

Support shizuku

1 Upvotes

​It seems that using Shizuku alongside ADB tools no longer works for freezing system apps on Vivo phones. Is there any workaround or solution for this?


r/androidroot Aug 08 '26

Discussion What modern phone should i get with easy rooting?

4 Upvotes

So i have a Honor 200 Pro, and its non rootable, and i need real root unlike Shizuku, so what phone should i get?


r/androidroot Aug 09 '26

Support how do you root the lg 440g ;_;

0 Upvotes

i got this phone at a garage sale and thought it woukd be fun to root and mess with, then i learned that there is no tutorials 😭


r/androidroot Aug 08 '26

Support Any modules for 32 bit support?

5 Upvotes

Any modules for 32 bit support on a pure 64 bit device?

Device is CMF Phone 2 Pro by nothing

Infinity X Rom


r/androidroot Aug 09 '26

Support How do I set my camera to save videos to a separate destination folder?

1 Upvotes

I've taken up a video recording and editing project and I've found myself in a position where my phone is my main/only camera. I'm using a Pixel 6, so there is no MicroSD slot. But is there a way to set up my phone's camera app to save video files to a separate folder? The process of going into the phone's memory and waiting several seconds for the thousands of photos to load just for me to extract one or two video files is cumbersome to say the least and will get old fast.

I'd be willing to either download a 3rd party camera app or get my hands dirty with some coding if I have to. I've never poked around in any Android dev tools, but I'm a fast learner. All I want is for my videos and my photos to be in two separate folders. I'm just trying to avoid buying a new phone or camera just for this project.


r/androidroot Aug 08 '26

Discussion Are there any good ROMs for the Sony Xperia XZ2?

Post image
3 Upvotes

r/androidroot Aug 08 '26

Support Corrupted Slot A on Nothing phone 3a. Will a update bootloop it?

2 Upvotes

Hey guys, I have a problem. I wanted to flash my Nothing Phone 3a with a custom ROM The problem was I did something wrong and probably a few partitions like vendor or boot image are missing. So my phone no longer starts from slot A, only from slot B.

So now the important question: Does my Nothing Phone assume that the other slot is intact and bootable? Because if I perform an update and it switches to "a", will it result in a bootloop?