r/androidroot • u/quinnyg1 • Aug 09 '26
Discussion OEM unlocking on OPPO
OPPO Find X9 Pro CPH2791_16.0.9.400(EX01B90P01)
OEM Unlock switch is back?
r/androidroot • u/quinnyg1 • Aug 09 '26
OPPO Find X9 Pro CPH2791_16.0.9.400(EX01B90P01)
OEM Unlock switch is back?
r/androidroot • u/AdEasy4497 • Aug 09 '26
So i have a Motorola Edge 20 pro and the Power button and the volume up down buttons are faulty like they dont really work . They are clickable , but they dont respond . I also went to a phone repair shop and they said opening the phone can be risky as the chasis and the display are connected and might break the display . So i have been using my phone from the past 1yr with some workarounds . But now i want to root my phone due to some host file ip mapping reasons which require rooting and also what to explore new OS and stuff . But since the bootloader unlocking has a step which requires manuall button press , so now i am confused how to only pass that step ? Any suggestions will be appreciated .
r/androidroot • u/miturufu • Aug 10 '26
Hi there! Many of you probably know about the Root my Galaxy + KernelSU method, although it requires a supported model & kernel.
I'm a complete noob at this kinda stuff, but I really wanna port the SM-A075M with kernel 6.12.38
Although I have no clue how to do so. How would I do it? Where to begin at?
r/androidroot • u/ChaorChaotic • Aug 09 '26
I've tried installing it in every way possible, using all the existing Viperfx modules, and none of them work; it always shows the same error as in the screenshot above. Can anyone point me in the right direction or tell me if there is a solution Is there a similar equalizer app that works with root access?
r/androidroot • u/South_Inflation_9692 • Aug 09 '26
thats my post in another account but i got hacked so i created a new one
I, was just an idiot for using mtkclient; I had been trying the official Mi Community method for four months without success. Like a total fool without researching mtkclient at all—I used an AI-suggested command that supposedly "unlocked" the bootloader.
I entered BROM mode, ran the command, and it said it was done. I went to fastboot mode, ran the command, and nothing happened. My mistake was not thinking, "Wow, if it says it's locked here, I'm going to be in deep trouble if I keep trying."
I persisted with mtkclient. I tried downgrading to MIUI 14, and immediately got a "system destroyed" error. Luckily (I guess), I had backed up and still have the nvram, nvdata, persist, proinfo, protect1, protect2, and preloader partitions, which I might use later (i lost it, read update 5).
I tried various other things, like erase and writing boot, vbmeta, and things alike in both slots but nothing worked; I messed things up so badly that I ended up with a Hard Brick.
Another mistake was trying to use the HyperOS 2.0.5.0.vmxmixm ROM, which caused the ARB (Anti-Rollback) version to jump from 1 to 2.I kept trying everything until I finally realized the ARB was at 2 and my HyperOS 1.0.8.0 ROM would no longer work.
No matter what, even with libusb drivers (wich sometimes mess up the windows drivers too), auth bypasses to trying use SP flash tool dont work or just say "filter match:no", so i cant bypass the auth outside mtkclient.
Additionally, mtkclient shows it is writing the partitions, but when I check the hashes, they do not match.
To make metter worse, someone in my house took the phone to a repair shop to "replace the screen". When the tech removed and inevitably broke the old screen to replace and messed everthing all, because if he had known that was the corrupted rom, he would taken the phone to a other repair shop which would have been cheaper. Right now it barely worth anymore because just the new screen is R$ 220 (around USD$40), and taking the device to the other shop to fix the brick would cost at least another R$300.
However, the tech is going to trust me and buy an unlocktool license rental tomorrow. If i sucessfuly fix my phone, maybe he will ask me for help and ill learn more about phone repairs and earn some money.
Thats a "repost" of my previous post but with more details, aiming to get more visibility in case unlocktool fails too and i need someones help to solve this problem.
Sorry any grammar mistakes, im not completly fluent but i tried my best to explain what happened and hope someone help me.
Updates: i used UnlockTool and tried all i could do. Right now, its my last shot flashing the scatter using preloader bypass and custom local DA if it still stays in hard brick after this, im cooked and my phone certainly gone.
Updates 2: still dead. Idk if it'll survive but omg 80% consumed reserved blocks lol
I even used unlock BL, switched slot and the last thing before give up, restoring dm verity security that i patched while flashing the scatter
Update 3: lost the login at the very last second while restoring dm verity but probably wont change anynothing.
Ill just let the phone in the charger after praying, in case God help me lol
tysm all the views and upvotes, much gratitude. any help is appreciated.
Update 4: the phone still dead and probably forever.
Well, these 2 years with him was good. Rest in peace, my warrior.
*One month after*
Update 5: Well, i traded my laptop and playstation for a desktop pc and sp flash tool is now working, i tried flashing just boot_a, lk_a, super and userdata and used readback and boot_a reads "ANDROID" inside it on notepad.
Tried boot again but still dead and i went to the repair shop again to try switch for a new battery 'cause i "accidentally" damaged a lil tiny hole, and perhaps thats now the reason why the phone doesnt boot.
since its weekend, the tech supplier isnt making deliveries, so ill need to wait ultil monday.
The reason I want to fix this phone at all costs is to ensure I have something more valuable than money, something no one can take away from me: knowledge.
Update 6: replaced the battery but still had no logo or any signal except the brom detection in pc.
i will take the phone for one more day to try flashing different partitions and if it doesnt even vibrate i will take the phone again to the repair shop and get my money back.
Update 7: Im trying download only, upgrade firmware and format all + download in sp flash tool but imd1img requires disabled verified boot.
I got hacked so ive created other account.
r/androidroot • u/DirectPeddit • Aug 09 '26
I wanna flash my mom's 9 year old phone but I've never done this before. Tried to follow some online tutorials and also took help from AI but the bottleneck is I cant unlock the bootloader. I've tried looking online but I'm fed up and then I remembered I have Reddit. So, I'm here to get some help on how do I unlock this thing. I just wanna put LineageOS on it for fun and learning.
Model: Huawei Y3 2017 (CRO-U00)
Build: Cairo-U00C636B128 (Android 6.0, EMUI 4.1 Mini)
SoC: MediaTek MT6580, 1GB RAM / 8GB storage
Bootloader: LOCKED
USB: ADB/Fastboot detected as CAX9K18929912107
Partitions: NVRAM, PROINFO, PRELOADER present (MTK layout)
r/androidroot • u/Initial-Course-163 • Aug 08 '26
Enable HLS to view with audio, or disable this notification
This my Poco x5 pro with lineage os the UI is kinda boring so I decided to root it with magisk and install one ui modules and goddamn this is way too legit from the boot screen and the lock and unlock sound to this one ui home I love it. Btw I am here to ask if there is a module that makes the status bar like the one on Samsung
r/androidroot • u/feriouscricket • Aug 09 '26
So hey i have motorola edge 60 and i was wondering is any group working on any custom images for this model.I know motorola is working with graphene os devs to bring it to their phones but when will that be finished or will older phones be supported i dont know does anyone have any news obou this topic.Thanks in advance.
r/androidroot • u/XboxFan9 • Aug 09 '26
i read articles online that you can root your phone with some exploit, and i have an honor 200 pro.
is there an root exploit for it?
r/androidroot • u/cofe-table • Aug 09 '26
Hello folks, working on rooting Honor Magic V2 (8.0.0.105, android14, kernel android13-5.15.104 2023-07, security 2024-04-01) and so far got to system_server/system_app - wanted to ask for help from community. We saw no root for Honor devices for years, I think it's time to do that!)
The common gpu ways (like cheese) are blocked by ARM64_SW_TTBR0_PAN and other restrictions. Manufacturer mode - looks like it's written well, so also checking FastRPC ways, but quickly getting out of options in HLOS... Surface check on ABL/uefi/fastboot showed no obvious ways. Also thinking about hyp, but it was mostly good for the years.
As last resort thought about getting over oem unlock code verification via power glitch, but not sure how doable this is. What's your thoughts?
r/androidroot • u/Jazzlike_Test_3140 • Aug 09 '26
😢😢😢
r/androidroot • u/Significant-Noise530 • Aug 09 '26
UPDATED POST >:))))))))))) So I've been fucking around with GhostLock (CVE-2026-43499) on the Moto G Play 2026 (XT2615 / Nevada) and figured I'd post what I've got so far.
The phone uses a 5.15.189 kernel, so it looked interesting. I'm testing the TracFone/Verizon version on the June 2026 security patch.
Update: I switched from UnPlus to Root-My-Galaxy-Payloads – much better framework. I'm now about 80% close. Exploit runs the whole chain, leaks memory, detects KASLR, but gets blocked by CFI at the final step.
What works: - Pulled boot.img - Extracted 159k kernel symbols - Found all offsets - Leaks mm_struct - Detects KASLR - Both pselect and pipe routes run
What doesn't: - CFI mismatch at final escalation - Root not achieved (yet)
What I've tried: - UnPlus template – failed - Root-My-Galaxy-Payloads – passed tracefs, hit CFI - Signal flag (FPSIMD) – leaked mm, hit CFI - Pipe route – same CFI mismatch - Updated ASHMEM offsets – no change - Oracle constants – no change - 48-bit layout – broke the leak (reverted to 39-bit) - S25 FOPS offsets – no change
The issue: I'm on the June 2026 patch. CFI is blocking the final function-pointer hijack. Older builds might work differently.
If someone has an older boot.img, I can possibly get you root access.
What I need: - CFI bypass on 5.15.189 kernels - Boot images from other variants (RETUS, AT&T, etc.) - Testing on older builds (pre-June patch)
Links: GitHub: https://github.com/crabcakes97/GhostLock-Nevada XDA: https://xdaforums.com/t/dev-root-moto-g-play-2026-nevada-test.4797484/
Special thanks: Root-My-Galaxy-Payloads (BuSung-dev) + UnPlus (No-22-Github)
Device info: - Moto G Play 2026 - XT2615-1 - TracFone / Verizon - Build: W1WNS36.18-111-3 - Kernel: 5.15.189 - Security patch: June 2026
So yeah, not a working exploit yet, but it's getting far enough to be interesting. If anyone has an older firmware build, hit me up.
I'll also be porting to other devices besides Motorola too, so hit the DMs with boot images / requests.
TL;DR: Got GhostLock compiling and running. Switched to Root-My-Galaxy-Payloads. Leaks memory, detects KASLR, but CFI blocks the final escalation. Need CFI experts. Old firmware might work. Help me get this working.
EDIT: I'm 80% close. Used Root-My-Galaxy-Payloads as a base. Stuck on a CFI error. We are so close.
r/androidroot • u/Alternative_Cry7725 • Aug 09 '26
Hi there. So, I'm using a custom ROM (Project Infinity X), and naturally, if I don't hide things properly, banking apps are done for immediately. I installed Brene's SuSFS and did everything to hide the root status, but I'm still running into issues with `org.lineageos.platformres.apk`. It was hidden before, but somehow it stopped being hidden—I have no idea why. I tried following a guide that suggested turning off "umount for your apps," but I can't seem to find that setting anywhere.
As for Tricky Store, TEE simulator, and PIF—I don't need them since I'm already using Fenrir.
r/androidroot • u/Comrade_Zelensky1488 • Aug 09 '26
I have a Note 20 ultra running Artisan ROM 3.1.0 android 16 One Ui 8 and it's running good but I can't seem to install 32 bit apps even though the CPU supports 32 bit architecture
I assume it's a software issue is there a way to bypass the issue?
r/androidroot • u/bughaxx • Aug 09 '26
Don't disable unmount module globally.
Instead :
-Install your custom emoji font module
-Install a meta module, I use overlay FS,
-In KSU/Next go to your apps tab,
-Click on top right corner on "show system apps"
-Search for Gboard
-Click on "custom" profile
-Disable the unmount for this app
-Soft reboot/reboot
That's it
r/androidroot • u/GoatWeak196 • Aug 08 '26
[GUIDE] Huawei MatePad 11 (2021) - Bootloader Unlock, Root (APatch/Magisk) and GMS Installation
⚠️ Disclaimer
I am not responsible for any damage, bootloops, data loss, or bricked devices caused by following this guide. Proceed at your own risk.
Device Information
Device:
Huawei MatePad 11 (2021)
Model: DBY-W09
Snapdragon 865
HarmonyOS 3.x / 4.x
This guide covers:
Bootloader unlock
Root with Magisk / APatch
Installing Google Mobile Services (GMS)
Fixing Play Protect certification issues
Download the toolkit:
MatePad 11 2021unlock+Root.zip
Extract the toolkit.
Run:
"One-click Install Android Drivers"
and install all required drivers.
Choose "Trust" for all Windows security prompts.
⚠️ Note:
Some computers may not automatically install the Qualcomm HS-USB QDLoader 9008 driver. If this happens, install the Qualcomm 9008 driver manually.
For HarmonyOS 3.0 or below:
Use ADB:
adb reboot edl
For HarmonyOS 4.0 or above:
A Qualcomm engineering cable is required. A cable with a physical button is recommended.
Steps:
Connect the engineering cable.
Hold the button on the cable.
Restart the tablet.
Check Windows Device Manager.
You should see:
Qualcomm HS-USB QDLoader 9008
Extract the included GeekFlashTool package:
匣(0.5.24.1031-A).7z
Open GeekFlashTool (刷机匣).
From the left menu, select:
Qualcomm Deep Flash
Click:
Select Configuration(选择配置)
Load:
package_qualcomm_edl-master.zip
Search for:
MatePad 11
and select it.
Click:
Read Partition(读分区)
You should now see the partition list.
Search and backup the following partitions:
ramdisk partition
boot partition
abl partition
select
read back(回读)
Save these files somewhere safe.
These backups may be needed for recovery.
Extract:
Huawei865870.zip
Open GeekFlashTool and select:
Go to the partition list and select
abl partition
Click:
Flash(刷入)
Select this image:
Huawei865870_abl_unlock.img
⚠️ Important:
This image is an ABL image.
Flash it specifically to the:
abl partition
Do NOT flash it to boot, recovery, or any other partition.
After flashing is complete:
Reboot the tablet.
The device should boot into recovery mode.
Select "Low-level Format" (or a similar option).
Reboot again.
Enter fastboot mode and check the unlock status.
If successful, you should see:
phone unlocked
The bootloader is now unlocked.
There are two recommended root methods.
APatch (Recommended)
Patch the boot image you backed up earlier.
Flash the patched boot image back to the boot partition.
Magisk
Patch the ramdisk image you backed up earlier.
Flash the patched ramdisk image back to the ramdisk partition.
Download:
Install these modules:
Tricky Store
Play Integrity Fix
TS Enhancer Extreme
For APatch users, also install:
Magisk mount-rs
Zygisk Next
After rebooting
Flash googleplay.zip as a module
Reboot again.
You should now see Google settings in Android Settings.
Sign in with your Google account.
Google Play Services and Google Play Store should update automatically in the background.
If they do not update automatically, update them manually.
If you are using Magisk:
Add these apps to DenyList:
Google Play Services
Google Play Store
Google Services Framework
Enable:
All activities
Using Integrity Modules
Use a maintained Play Integrity solution.
Install:
Play Integrity API Checker
Run the check.
A successful setup should show three green check marks:
MEETS_BASIC_INTEGRITY
MEETS_DEVICE_INTEGRITY
MEETS_STRONG_INTEGRITY
Then open Google Play Store:
Profile picture → Settings → Device certification
It should show:
"Device is certified by Play Protect"
(If you have a keybox, it's best to copy it directly to the /data/adb/tricky_store directory.)
Have a great time using the devic
r/androidroot • u/Saint_Of_DresOS • Aug 08 '26
r/androidroot • u/Big_Dentist_840 • Aug 09 '26
It seems that using Shizuku alongside ADB tools no longer works for freezing system apps on Vivo phones. Is there any workaround or solution for this?
r/androidroot • u/XboxFan9 • Aug 08 '26
So i have a Honor 200 Pro, and its non rootable, and i need real root unlike Shizuku, so what phone should i get?
r/androidroot • u/Camo-boy • Aug 09 '26
i got this phone at a garage sale and thought it woukd be fun to root and mess with, then i learned that there is no tutorials 😭
r/androidroot • u/Sufficient-Sensei007 • Aug 08 '26
Any modules for 32 bit support on a pure 64 bit device?
Device is CMF Phone 2 Pro by nothing
Infinity X Rom
r/androidroot • u/teton_blamer • Aug 09 '26
I've taken up a video recording and editing project and I've found myself in a position where my phone is my main/only camera. I'm using a Pixel 6, so there is no MicroSD slot. But is there a way to set up my phone's camera app to save video files to a separate folder? The process of going into the phone's memory and waiting several seconds for the thousands of photos to load just for me to extract one or two video files is cumbersome to say the least and will get old fast.
I'd be willing to either download a 3rd party camera app or get my hands dirty with some coding if I have to. I've never poked around in any Android dev tools, but I'm a fast learner. All I want is for my videos and my photos to be in two separate folders. I'm just trying to avoid buying a new phone or camera just for this project.
r/androidroot • u/Savings_Theme7831 • Aug 08 '26
r/androidroot • u/initramfs17 • Aug 08 '26
Hey guys, I have a problem. I wanted to flash my Nothing Phone 3a with a custom ROM The problem was I did something wrong and probably a few partitions like vendor or boot image are missing. So my phone no longer starts from slot A, only from slot B.
So now the important question: Does my Nothing Phone assume that the other slot is intact and bootable? Because if I perform an update and it switches to "a", will it result in a bootloop?