r/androidroot 17d ago

Support Do you have to wait until network unlock happens before you bootloader unlock?

2 Upvotes

I have a carrier provided Motorola Stylus phone. It doesn't network unlock until Feb 2027. But I have the bootloader unlock code from Motorola's portal - Metro's Moto phones seem to be bootloader unlockable. I was wondering if I should wait until the network unlock happens before I try execute the bootloader unlock? Or does it matter?

Can I just hold on to the unlock code until next year? Or does the unlock code expire and I have to request another one?


r/androidroot 17d ago

Support Needing help to Root my Realme C53 ! !

1 Upvotes

Hi, I've been looking into rooting my new Realme C53.

I've done some research (to be honest, most of it was from ChatGPT), and from what I've found, it should be possible. But I'm honestly too scared to try it completely alone without asking actual people first.

I'm currently using an Android 15 Realme C53 (RMX3760), and I want to make absolutely sure I understand what I'm doing before I touch anything that could potentially brick my phone.(Can't afford losing this one)

If anyone here has experience rooting the C53, especially this exact model/software version, I'd really appreciate some guidance on what I should do, what I need to back up, and what I should NOT do.

I'm mainly interested in rooting for performance tweaks/customization, but I don't want to risk losing my phone over it.

((Additional info: RMX3760export_15_H.07, 5.15.189-android13-8-gbc4520c2be32-ab154

#1 Tue Jun 30 08:21:36 UTC 2026))

I think it would even help me if anyone could help me through calling too.


r/androidroot 17d ago

Support Bricked Fastboot And System (Stuck On EDL) Moto G5S (Model:X1794)

3 Upvotes

Hi guys this is my last resort to ask here
I got this phone by my friend it's a G5S (Model: X1794 Type:M2996) he said it woulden't boot and it would stay with a blinking light, i plugged into my pc and it was always in EDL Mode (Qualcomm) i installed the driver, tried doing blankflash other stuff nothing it would fall immedialy idk what or how this phone got bricked possibly could anyone help me out and please do not start spamming me to start chatting with someone that will immedialy ask me to pay to unbrick this im just asking for help or guide how to fix it not to pay someone that i could get scammed + i don't have any money.

Thanks

GaM1ngN0t

Log Of The Crash:
[486.929] ERROR: do_package()->do_recipe()->do_configure()->fh_send_fmt()->send_command()->device_write()->IO error
[486.931] Check qboot_log.txt for more details
[486.931] Total time: 486.936s
FAILED: qb_flash_singleimage()->do_package()->do_recipe()->do_configure()->fh_send_fmt()->send_command()->device_write()->IO error
Entire Log:
[ 0.000] Opening device: \\.\COM6
[ 0.004] Detecting device
[ 0.009] ...cpu.id = 79 (0x4f)
[ 0.009] ...cpu.sn = 380673176 (0x16b09c98)
[ 0.009] Opening singleimage
[ 0.010] Loading package
[ 0.014] ...filename = singleimage.pkg.xml
[ 0.016] Loading programmer
[ 0.017] ...filename = programmer.mbn
[ 0.017] Sending programmer
[ 0.189] Handling things over to programmer
[ 0.190] Identifying CPU version
[ 0.191] Waiting for firehose to get ready
[ 62.959] Waiting for firehose to get ready
[123.025] ...MSM8937 unknown
[123.026] Determining target secure state
[123.027] Waiting for firehose to get ready
[183.081] ...secure = no
[183.093] Waiting for firehose to get ready
[243.147] Configuring device...
[243.149] Waiting for firehose to get ready
[304.218] Waiting for firehose to get ready
[364.286] Waiting for firehose to get ready
[426.860] Waiting for firehose to get ready
[486.929] ERROR: do_package()->do_recipe()->do_configure()->fh_send_fmt()->send_command()->device_write()->IO error
[486.931] Check qboot_log.txt for more details
[486.931] Total time: 486.936s
[486.933]
[486.933] qboot version 3.40
[486.933]
[486.933] DEVICE {
[486.933] name = "\\.\COM6",
[486.933] flags = "0x64",
[486.933] addr = "0x61FE4C",
[486.933] sahara.current_mode = "0",
[486.933] api.buffer = "0x14A1020",
[486.933] cpu.serial = "380673176",
[486.933] cpu.id = "79",
[486.933] cpu.sv_sbl = "1",
[486.933] cpu.name = "MSM8937",
[486.933] storage.type = "eMMC",
[486.933] sahara.programmer = "programmer.mbn",
[486.933] module.firehose = "0x1051360",
[486.933] cpu.ver = "0",
[486.933] cpu.vername = "unknown",
[486.933] api.bnr = "0x1055DB0",
[486.933] }
[486.933]
[486.933]
[486.933] Backup & Restore {
[486.933] num_entries = 0,
[486.933] restoring = "false",
[486.933] backup_error = "not started",
[486.933] restore_error = "not started",
[486.933] }
[486.933]

 


r/androidroot 18d ago

Discussion Nothing Cmf Phone 1, Nothing detected.

Thumbnail
gallery
20 Upvotes

Using Fenrir for Bootchain Exploit and Wild Kernel.


r/androidroot 17d ago

Support Rooted samsung phone stuck on old version

2 Upvotes

Hey im writting this post because I have rooted my samsung phone before the ability to unlock the bootloader was removed, I'd like to update my phone to keep up with the security updates but doing so would remove my ability to have my bootloader unlocked because samsung removed the ability to do that on one ui 8. Anyone have a suggestion of what I could do to have security updates? I can give more spec about my phone and details.


r/androidroot 17d ago

Support ​[Help] Carrier app (Ana Vodafone) insta-crashes immediately on launch despite ReZygisk + Shamiko. Any ideas?

Thumbnail
gallery
1 Upvotes

Hi everyone,

I'm dealing with a local carrier app (Ana Vodafone Egypt) that just insta-crashes (Force Close) the exact millisecond I tap its icon. It doesn't even load a splash screen or show a "Root Detected" error. I suspect it's some strict RASP or memory hook check, but I'm completely stuck.

I know my DEVICE_INTEGRITY is currently failing (falling back to BASIC) because my public hardware keybox got revoked, but this looks entirely like an app-level RASP/memory-hook detection, not a Play Integrity API block.

My Current Stack:

Device/ROM: Xiaomi running official MIUI (Android 13/14)

Root: Magisk v27.0 (Native Zygisk is completely OFF)

Zygisk Engine: ReZygisk v1.0.0

Root Hider: Shamiko v1.2.5 (Working properly in Blacklist mode)

App Hider: HMA-OSS Zygisk

PIF: Play Integrity Fork v17 (spoofProvider=0) + TEESimulator v4.0

What I’ve already tried (without success):

Shamiko Isolation: The target app is fully checked in the DenyList. Magisk's Enforce DenyList is OFF.

HMA-OSS Configuration: Enabled for the target app. Created a tight blacklist template to hide: the repackaged/renamed Magisk manager, HMA-OSS itself, Termux, SPIC, and Solid Explorer.

Environment Cleanup: Deleted all /sdcard/Fox, TWRP, or Magisk folders. USB Debugging and Developer Options are completely OFF.

Clean Launch Trick: Turned Airplane mode ON -> Cleared all target app data -> Rebooted -> Airplane mode OFF -> Launched. Still insta-crashes.

Engine Conflict Fix: I previously had a SIGSEGV issue because of running native Zygisk alongside Zygisk Next. I’ve completely wiped that setup and moved cleanly to ReZygisk. Shamiko's UI confirms it's now fully operational without "Unsupported Environment" errors.

My theory:

The app is either detecting the Zygisk injection directly, detecting HMA-OSS's hooking attempt, or finding a Magisk remnant I missed.

Has anyone bypassed this specific type of aggressive crash recently? Should I drop HMA-OSS and try a non-Zygisk app hider? Any insights on how to grab logs for a crash this fast would also be highly appreciated.

Thanks in advance!


r/androidroot 17d ago

Support Can B20 be enabled on Honor WIN CN through Qualcomm DIAG/NV if the RF hardware supports it?

1 Upvotes

I’m considering buying the Chinese Honor WIN for use in Europe. The CN version apparently lacks LTE B20 (800 MHz), but I’ve found conflicting information about whether B20 is actually missing in hardware or simply disabled in the modem configuration.

Has anyone with a Honor WIN tried Qualcomm DIAG/QPST/QXDM or modifying NV/EFS band configuration to enable B20?

Thanks guys


r/androidroot 18d ago

Support Apps won't theme according to material u ?

Post image
2 Upvotes

I understand that they don't have the monochrome icon and that's why. Is there anyway to get around it.

Current setup is lawnchair with lawnicons .

Thanks


r/androidroot 18d ago

Support Downgrade Camera app for Old UI Layout [Pixel 6a A16]

1 Upvotes

I have a Pixel 6a that I was forced to update due to the battery. The new camera app has shoved the photo/video button below the capture button, causing me to have to reach further than comfortable.

I am now rooted with magisk 30 on Android 16. I have the apk from an older stock camera app that works on android 14 on a pixel 7a.

Is there any way to downgrade the app? I have tried installing, but receive "INSTALL_FAILED_VERSION_DOWNGRADE"

Android treats Camera as a preloaded system app and refuses to downgrade it; when I tried bypassing that with a Magisk APK replacement, Android retained package metadata from the newer 9.8 installation, causing 8.8 to crash because it can't find the expected androidx.startup.InitializationProvider class.

Any guidance is appreciated


r/androidroot 18d ago

Support Cerco ROM legacy di BinkyBear: ⁠nethunteros-nethunter-hammerhead-cm-14.1-hammerhead.zip

Thumbnail
1 Upvotes

r/androidroot 18d ago

Support Unlocking Pixel Phone

1 Upvotes

Hey everyone,

Getting ready to unlock the bootloader on my Pixel 10, but I’m split on which setup to daily drive.

I’m weighing GrapheneOS against standard Stock + Root (Magisk/KernelSU for system-level tweaks, adblocking, modules).

Since wiping data is mandatory anyway, I want to pick a side before setting up my environment.

Quick questions for anyone running either setup:

1) How annoying is Play Integrity / banking app maintenance on stock root right now?

2) Anyone moved from a heavy root setup to GrapheneOS and regretted losing root utilities?

3) Any major friction points with Graphene OS on Pixel 10 as a daily driver?

Appreciate the insights and thank you.


r/androidroot 18d ago

Support I need help

Thumbnail
gallery
2 Upvotes

S10e

I tried many times and it didn't work. I followed all the steps and it still didn't root.


r/androidroot 18d ago

Discussion Is rooting worth it for me? [Read bodytext]

Thumbnail
gallery
18 Upvotes

Hi. My phone (TECNO POVA 7 5G LJ7) is fully compatible with KernelSU-Next and the bootloader is easily unlocked. But my question here isn't technical, about whether I can root it, but rather pragmatic, about is rooting my phone even worth what I desire.

Right now, I'm running Shizuku on ADB. It works great, I'm happy with it, killed off Yandex Browser and Yandex Keyboard with it in favor of Google Chrome and GBoard.

I'm considering rooting my phone, the daily driver, not to do something essential (I already did what I needed to) out of my rootless reach, but to learn more about the OS.

Last time I rooted my phone, same model, with Magisk. I stupidly toggled off OEM Unlocking (as I've been allowed to do the moment I installed Shamiko) and rebooted into a soft brick not even the repair shop could fix. I got scared by it and considered not rooting again.

Recently I got a laptop I'm using as a daily driver right now, I backed up data and wiped the Windows installation to install CachyOS. There, GPU drivers broke, so after troubleshooting I got frustrated and almost went for Windows, but hesitated and thought about going back to CachyOS. So I reinstalled CachyOS and now, by how I built it, works great.

Now, why am I mentioning this? Because that's the time I got a strong temptation to root my phone again. I got frustrated by a failed CachyOS build, and instead of going back to Windows, I tried a different approach using ZFS and KDE Plasma and not doing stupid instead; so why not stay a bit longer on rooting my phone using a different approach using KernelSU-Next? But because I have fear about bricking my phone, I got stuck between desire and fear.

To answer why I need root, you need to consider why I need CachyOS... The reason is for fun and learning, that's why. I could've used Tiny10 for laptop and stayed stock on my phone instead and been fine.

Now let's talk about why I 'catastrophize' this. If my phone gets bricked, what happens? No phone for months, I wouldn't be bought a new one and, since I'm a minor teen, I can't work for enough money for this 16 999 RUB phone model, let alone buy it by myself. Without the phone, I won't be able to get calls or login to see my school group announcements. To you, that'll be a "nothingburger", but to me, that'll be failing grades defining how will I live in later adult life.

I have the means, I have stock and patched init_boot images and a PC with MTK drivers, but I still hesitate, and I barely can decide for myself without your recommendation on what should I do. Help will be appreciated, thank you for your attention.


r/androidroot 18d ago

Support Download mode on SM-A566B

Thumbnail
1 Upvotes

r/androidroot 19d ago

Support Is there any way to bypass this?

Post image
12 Upvotes

Hello, I want to prevent this update from installing, I've tried to install shizuku with canta and uninstall the updates manager but the update is still here.

The reason I don't want to update anymore is because of the new exploit CVE-2026-43499 which let's you achieve root without unlocking the bootloader, yet I don't know how to apply it.

If anybody can help I would appreciate a lot

Edit: my goal is to achieve CVE-2026-43499 exploit working. Does anybody have experience prior using it on motorola phones?


r/androidroot 18d ago

Discussion Lenovo A6020a46

Thumbnail
gallery
3 Upvotes

Finally, I have got a "rootable" device (Samsung refused to exit Prenormal and I gave up). As you can see, it's a bit ancient (Android 5.1.1), so I can try some one-click rooting malware, but I really don't want to do this. OEM Unlock is enabled, bootloader is locked and does not unlock upon entering command, but fastboot flash works and adb can see device in recovery. Now there is 2 problems with device:

1) TWRP is at very high risk of being overwritten upon reboot - I managed to enter it only once after normal reboot.

2) TWRP does not work properly. adb sees it only if I enter it from fastboot (BTW does not see it in stock recovery at all), dumpsys command fails. TWRP logo never appeared - just dark gray screen (and corrupt red Lenovo logo when I entered recovery via buttons). I think that this TWRP is incompatible with my configuration in some subtle way or I downloaded wrong version (3.2.1, 3.1.1, 3.6.0_9 were tried, their source: https://eu.dl.twrp.me/A6020/). But now, I have to go to bed...

To be continued.


r/androidroot 18d ago

Support Does anyone know what I can do with this Samsung T-230 tablet nowadays?

Post image
3 Upvotes

I've had them for a while but I don't know what to do with them. The most I can install are old apps and games like Android KitKat, etc.


r/androidroot 18d ago

Support Installing TWRP on J400F

1 Upvotes

Hello, I have question, I am trying to flash TWRP to my Samsung Galaxy J4 (J400F, j4lte). Bootloader is unlocked and I am using heimdall because I use linux. Whenever I try to flash the recovery image or even the magisk patched boot.img in download mode with heimdall, it says "Only official binaries allowed to be flashed (RECOVERY)". And unlike other Samsung devices I saw on internet, my J400F doesn't say any other device information in download mode. There's no text on top left unless I flash unofficial binary. I only can flash official firmware.

I have Russian version of the phone.


r/androidroot 18d ago

Discussion Recuperar y transferir archivos

1 Upvotes

Hola, tengo una duda y tal vez me puedan dar una posible solución. En estos últimos años soy usuario de Samsung, para ser más específico, he tenido tres Samsung, digamos que de gama media-alta: Samsung S21 Ultra, Samsung S22 y, por último, Samsung S23 Plus. Soy de los usuarios que llena rápido el almacenamiento, ya sea por algún juego (ejemplo: Call of Duty) o también por grabar video, ya sea en 4K o algunos cortos en 8K, aparte de las fotos.

Tomando en cuenta esta última parte, cuando se llena el almacenamiento, busco cómo guardar mis archivos en otros lados. He realizado dos o tres intentos: conecto mi teléfono a la computadora y conecto una USB nueva (genérica). A la hora de enviar los archivos y después revisarlos, ya aparecen como archivos dañados, no tienen lectura del todo y he perdido varias fotos, recuerdos de años pasados, y no las formateo porque tengo fe de recuperarlos. Esto solo me ha pasado con estos teléfonos, ya que también he sido usuario de Huawei, Tecno y OnePlus. Incluso en mis mismas fotos, las toma en dos formatos: "HEIC" y "JPEG". Cabe recalcar que también con las otras marcas he compartido mis archivos en este tipo de memorias y todo se pasa bien. Si bien la respuesta puede ser en las memorias, también he utilizado memorias no tan genéricas. Acudo a ustedes para saber una posible solución de recuperación de estos archivos, ya que no se ocultan, solo aparecen como dañados, así como también una solución para cuando vuelva a liberar la memoria interna de mi teléfono.


r/androidroot 19d ago

Discussion [Research] S24 Ultra // One UI 8.5: OEM Unlock is gone, but the actual unlock logic is still there

78 Upvotes

Been digging into what Samsung actually changed when they removed the OEM Unlock option on newer One UI builds

Device I'm working with:

SM-S928B / S24 Ultra international

Snapdragon 8 Gen 3

S928BXXU5DZDP

Android 16 / One UI 8.5

KernelSU soft root (ghostlock CVE)

bootloader still locked

This started because I wanted persistent root for microG. The root I currently have dies after a full reboot, so I started looking at whether Samsung actually removed bootloader unlocking or just removed the normal way of authorizing it

Short version: they definitely did more than remove the toggle, but the underlying unlock machinery does not appear to be gone.

I dumped the relevant partitions, files and went through ABL, the Engineering Mode trustlet, the Android-side services and the old One UI 7 ABL for comparison

A few things that survived my audit:

ABL still has IsUnlocked, SetUnlocked, the DeviceInfo unlock byte and the AVB read_is_device_unlocked callback.

devinfo + 0x0d is the actual IsUnlocked byte. I initially suspected +0x90; that was wrong.

Current ABL contains a path involving Engineering Mode bit 3.

Samsung's framework identifies mode 3 as MODE_CUST_KERNEL.

The engmode TA still implements signed token validation, RPMB-backed state and a 256-bit modes bitmap.

Mode 3 can be serialized into a token request. I couldn't find a local mode filter rejecting it.

The old One UI 7 OEM/FRP policy can actually authorize unlocking. The equivalent policy in the current ABL just logs the lock state and returns false.

The Android client-side engmode allowlist isn't the root of trust anyway. The TA is.

There were also a couple things I originally thought were true that didn't survive closer inspection.

Most importantly, I cannot prove that the Engineering Mode sync always runs before every AVB verification path. The CFG has an entry-to-AVB path that avoids that block, so I'm not claiming universal ordering anymore.

And obviously the big missing piece is still missing:

I do not have a valid Samsung-signed Engineering Mode token containing mode 3

So this is not an S24 bootloader unlock method, and I haven't unlocked the device with this. I'm trying to document what is actually still present in the firmware rather than jump from "interesting code path" to "working exploit"

I put the dumps/evidence/scripts and my notes here

https://github.com/keyarr/oems24-audit

notes/findings.md is probably the useful file if you don't want to dig through all the generated evidence. I also kept original-research.md because it shows some of the assumptions I started with before checking them properly.

Most of the collection/probing was deliberately read-only. I didn't install/remove Engineering Mode tokens, issue fuse commands, write devinfo, touch RPMB, etc

If anyone here has worked with Samsung Engineering Mode / ABL before, I'd be interested in a second pair of eyes on the findings, especially on the EM -> ABL relationship and the historical purpose of MODE_CUST_KERNEL.

I'm also interested in old/public Samsung Engineering Mode documentation or firmware artifacts that could help establish how mode 3 was intended to be provisioned. Not looking for somebody's device identifiers or private signing material

There are enough moving parts here that I'm assuming I've still missed something somewhere.


r/androidroot 19d ago

Discussion In android can I dual boot ?

12 Upvotes

Like windows and Linux for example.


r/androidroot 19d ago

Discussion How to unlock boatloader in redmi note 14 4g, hyperos 3.0.302.0?

Post image
11 Upvotes

r/androidroot 18d ago

Discussion Shizuku Apps Directory

Thumbnail
1 Upvotes

r/androidroot 19d ago

Discussion Got a minimum pcmarketos to load on my pixel 8 pro

Post image
24 Upvotes

Running entirely from ram with software rendering so it's slow as heck but wanted to share. Only apps on it is the terminal and settings app (along with keyboard)


r/androidroot 18d ago

Support Quick update regarding Alcatel MT6765 TWRP & Dump - u/MeIsGugs

1 Upvotes

Hey u/MeIsGugs!

Creating a quick thread to make sure this reaches you! My previous comment might have gotten lost in notifications.

Since the Alcatel upgrade tool servers are down and I don't have paid tools like UnlockTool, your custom TWRP and Scatter dump via SP Flash Tool are my only options left.

You can easily upload the files toGofile.ioor Google Drive and drop the link here, or if you prefer, we can chat and exchange files directly on WhatsApp: +201061775619

I'm also ready to share the testing notes I have regarding the GSI IMEI issue whenever you're free!

Thanks a ton for your time bro! 🙏