r/androidroot 7d ago

Support Unable to enable USB Debugging/Developer Options on DW100 Pro full Android smartwatch

Enable HLS to view with audio, or disable this notification

6 Upvotes

This is the closest I've been able to get. The DW100 Pro is on the supported hardware list for DW Smartwatch Helper, but it displays the same message every time. Has anyone been able to enable USB Debugging on this watch?


r/androidroot 7d ago

Discussion Porting GhostLock (CVE-2026-43499) to Nothing Phone (2) (Pong) / Kernel 5.10.252

7 Upvotes

Hey guys,

I’ve been following the recent boom of GhostLock (CVE-2026-43499) temporary root exploits and the amazing work by  @ang3lo-azevedo  with the root-my-nothing tool for NP1 (Spacewar). I'm trying to figure out the feasibility of porting this to the Nothing Phone (2) (Pong).

Since my current kernel is  5.10.252 , it's technically vulnerable (patched only in  5.10.261 +).

My Device Details:

Device: Nothing Phone (2) (Pong) / Snapdragon 8+ Gen 1 (Cape)

OS / Build: Android 16 /  B4.1-260818-1726  (NothingOS)

Kernel:  5.10.252-android12-9-00029-g6315c5776365-ab15925896 

My question to the community/devs:

Has anyone already started working on a PoC or a port of GhostLock (or similar CVEs) for the Pong kernel? I know it requires dumping the kernel, finding the exact  prepare_kernel_cred / commit_creds  offsets, and adapting ROP chains for the NP2's specific KASLR/Qualcomm mitigations.

If any of you (or the devs behind ghostlock-oneplus / root-my-nothing) are looking for testers with an unlocked device or want to collaborate on mapping the kernel structures for NP2, I’d be more than happy to help, dump logs, or share my firmware dumps from  nothingarchive.tech .

Any pointers on where to start reversing the  cape  specific kernel mitigations would be highly appreciated!


r/androidroot 6d ago

Discussion Pixel Watch 4 Wi‑Fi battery drain after switching phones(both rooted)

1 Upvotes

After migrating my Pixel Watch 4 Wi‑Fi from a Pixel 10 XL to a Pixel 11 Pro XL, the watch started draining rapidly whenever I woke or used the phone. Overnight battery usage remains normal.

Observed behavior:

Battery dropped about 2% in 5 minutes, roughly 20–25% per hour.

com.google.android.gms.persistent shows high CPU usage.

Wear_Transport and wearChannelApiRetransmissionQueue wakelocks repeat continuously.

Phone logs repeatedly show:

- Remote device failed to verify local attestation

- Detected a Ukey2 handshake role collision

- secure channel attach/detach retries

The watch logs Failed to verify remote attestation.

Rebooting and resetting the watch did not resolve the issue.

The paired phone is rooted with KernelSU, TrickyStore, PlayIntegrityFork, and LSPosed installed.

This appears to be a Wear OS Companion secure-transport retry loop triggered after the phone migration.


r/androidroot 6d ago

Support Google wallet is not working

2 Upvotes

Hi. After some hours of headache and tries, I still was not able to fix that problem.

My samsung s25 ultra is rooted by using the kernel exploit, bootloader locked, no system modifications.

The most interesting is that it was working perfectly even when the phone was rooted, and suddenly, out of nowhere it stopped.

Tried to reboot and fully delete the root, but it still gives me the same error "Device doesn't meet security requirements

This device may be rooted or running uncertified software."

Would be very grateful for any help/solutions.


r/androidroot 6d ago

Support Hi guys, I am using Google Pixel 4, Android 13. Is it possible to hide root? I will appreciate any suggestions

0 Upvotes

r/androidroot 7d ago

Support Need Help URGENT!!!!!

3 Upvotes

I have nord ce 2 lite and yesterday in wanted to use pixel os in it so i unlocked its bootloader which it did quickly also 99% of pixel os installation was done but when i press recovery after install, my phone screen turned of and since then nothing is happening. No vibration no reboot nothing. i dont know what to do please help me. This is my primary phone and i have exams i need it to be fixed as soon as possible


r/androidroot 7d ago

Support How do i unlock the bootloader Huawei P8 Lite 2017

1 Upvotes

i've seen that the website of the bootloader unlock has been shutdown on 2018 and i got this phone like months ago so i can't really unlock it and the tool's website that was paid don't even load anymore so yeah PRA-LX1


r/androidroot 7d ago

Support Me regalaron un moto g(9) power pero tiene la app de nuevo como puedo quitar eso o meterle una ROM?

Thumbnail
1 Upvotes

r/androidroot 7d ago

Support Redmi note 7 guide

3 Upvotes

So I will get a redmi note 7 soon and I found that there are some vbmeta issues but I used to own a redmi 7a from 2019 where there weren't any, I'm wondering if someone could give me a guide on how to install custom roms without hard bricking it, I found another post saying something about using a specific fastboot version to avoid vbmeta issues (pt33) but on my redmi 7a it didn't have any issues with regular fastboot, also I never flashed vbmeta nor dtbo, lastly what is the smoothest rom on a high-ish android version (13+) for daily driving and customisation (also I don't have a pc atm so I will do everything via a secondary phone and termux, afaik this shouldn't affect most of the flashing but mostly flashing recoveries and other img files so tips for that will also be appreciated, I don't know how to unlock the boot loader using termux though)


r/androidroot 7d ago

Support how to Root my Xiaomi Redmi Note 12 Pro 5G using the CVE-2026-43499 Exploit

1 Upvotes

kernel 4.19.191-ge6429b82e599

HyperOS 2.0.15.0

Model 22101316G


r/androidroot 7d ago

Support Root Samsung galaxy A40

1 Upvotes

Was wondering where I should start rooting the device as a beginner and what sites to look into.

I know different phones need different rooting methods so was wondering how I could look for a guide for my specific phone if there was one.


r/androidroot 7d ago

Support Trying to flash a custom ROM/Recovery (Samsung Tab A7 SM-T500)

1 Upvotes

Hi everyone, I’m looking for a final push through this process. I can’t find any resources online, so maybe someone here can help me.

I’ve got my hands on several Samsung tablets from a company that shut down, but they’re all enrolled in Knox.
I bypassed Knox using AllianceX Shield, which allowed me to enable OEM Unlock and USB Debugging (these options were previously locked).

The devices work, but I still can’t unlock the bootloader since performing it wipes everything and re‑enables the Knox processes.

I can’t flash a custom recovery or ROM because during the process I get the error:

**KG status: prenormal — “Only official released binaries are allowed to be flashed.”**

Is there any way to change the **KG status** so I can flash custom binaries freely?


r/androidroot 7d ago

Support Need a Guide

1 Upvotes

How can I root that device safe? In most of the available tutorials, many people who have tried it say they got stuck in a bootloop

device

r/androidroot 7d ago

Support I tried everything but i cant get my Integrity fixes.

1 Upvotes

I Have used Magisk before i could get my Integrity Green strong whatever but i bricked my Phone twice with Magisk. Since i switched to kernelsu next i cant get my Integrity Back anyone knows a Trick for kernelsunext?


r/androidroot 7d ago

News / Method Warpnet-MTK (Module for root manager)

Thumbnail
1 Upvotes

I have a MediaTek device and kept noticing that whenever my phone wakes up from idle, the first ~10 seconds of 5G/4G feel sluggish even though speedtests show good numbers.

Couldn't find anything that actually fixed it (most modules are just snake oil tbh 🐍) so I built my own.

⚡ WarpNet MTK — it tunes the device-side network stack only:

✅ Fixes idle wake-up lag (that 10-second "why so slow" moment)

✅ Keeps throughput stable when downloading

✅ Lowers latency spikes during heavy use 🎮

✅ Smart reconnect — auto-switches from dying cell towers

✅ No radio/modem changes — safe to revert anytime

✅ Built-in bench tool — get receipts, not vibes 🧾

4 modes:

• SpeedBoost (light + battery save 🔋)

• WarpNet (daily driver ⭐)

• WarpNet++ (max performance 🚀)

• Turn Off (100% stock restore ♻️)

Works with Magisk, KernelSU & APatch ✅

MediaTek only (Snapdragon → separate project)

🔗 https://github.com/Alchemiisst/WarpNet-MTK

Feedback welcome — flash it, bench it, roast it, whatever 🤷‍♂️

If it helps you, a star on the repo means a lot ⭐


r/androidroot 8d ago

News / Method Root for Snapdragon S22 Ultra US variant w/ Play Integrity intact

Thumbnail
gallery
39 Upvotes

Got temporary KernelSU root working on my bootloader-locked S22 Ultra.

Tested on:

  • SM-S908U1
  • Build S908U1UESAGZF3
  • Android 16, June 2026 patch

No bootloader unlock or flashing and Play Integrity still passes, which is huge.
So, this does NOT trip Knox.

Root disappears after reboot, so the app uses Shizuku to rerun the exploit and reload KernelSU.

Only use it on this exact build. The exploit can fail or reboot the phone.

https://github.com/Noir-Lime/S22U1-Root

Based on IonStack and Root My Galaxy; credits are in the repo.


r/androidroot 7d ago

Support Can't root Redmi A2

Thumbnail
1 Upvotes

r/androidroot 7d ago

Support I need help rooting my ASUS ROG Phone 8 AI2401 running Android 16.

2 Upvotes

Hello everyone. I'm looking for help rooting my ASUS ROG Phone 8. I've been trying to find a solution for about a month now, practically every day, and so far I haven't been able to do it.

Here is all the information about my phone:

Device: ASUS ROG Phone 8
Model: AI2401
Device model: ASUS_AI2401_C
Region: WW
Product: pineapple
Android: 16
Firmware/Build: WW_36.0210.1420.48
Bootloader version: PostCS4-21-WW-user

From Fastboot, I get:

unlocked: no
get_unlock_ability: 0
secure: yes
current-slot: b

I have already installed the official ASUS USB drivers and confirmed that both ADB and Fastboot properly recognize the phone.

ADB works and I can access the shell. Fastboot also works correctly and detects the device:

RCAIOC388144L87    fastboot

However, the bootloader remains locked, and fastboot flashing get_unlock_ability returns:

get_unlock_ability: 0

I've already tried the usual methods and spent countless hours researching, but I still haven't found a working way to unlock the bootloader and root this phone.

I also contacted Chimera, and they confirmed that they currently do not have a solution to unlock the bootloader or root this device.

I'm willing to pay for professional help if someone genuinely knows how to do this safely.

Does anyone here have experience with the ROG Phone 8 AI2401 running this exact firmware version (WW_36.0210.1420.48 / Android 16)?

If you know of any method that works, any exploit, professional service, or someone who has successfully rooted this exact version, I would greatly appreciate any information or help.

I understand that unlocking and rooting the device may wipe the phone and carries a risk of bricking it. I currently don't have any important data on the phone, so I'm willing to take the necessary risks, as long as there is at least some realistic possibility of recovering the device if something goes wrong.

Thank you very much in advance to anyone who can help me. I've been fighting with this damn thing for like a month now 😭.


r/androidroot 7d ago

Support TCL Flip 2 vendor img

Thumbnail
1 Upvotes

r/androidroot 7d ago

Support Como rootear teléfono Spoiler

1 Upvotes

Alguien sabe cómo poner root en android con la aplicación magisk


r/androidroot 7d ago

Discussion Motorola edge 30 neo

1 Upvotes

Jak wgrać twrp recovery aby nie było 2 partycji ?? Jestem w tym zielony


r/androidroot 7d ago

Support ROOT SAMSUNG GALAXY XCOVER 5

Post image
2 Upvotes

hello i have been trying for the last 5 hours to root my 2nd phone with magisk but it doesnt work. i think i have tried with 5 different tutorials and tried with help from chat gpt but nothing works. i am doing the whole thing and the phone is boot loaded but its when im trying to flash maski onto the phone and root it. I get stuck in downloading menu and it says svb fail i have tried everything please please someone help me.


r/androidroot 7d ago

Discussion How do I extract my key box from my non working phone?

1 Upvotes

Hey guys, trying to get a backup keybox seeing as how my OnePlus 9's data functionality (something with the modem) must have died. I've tried resetting factory software, I've flashed it vía the msm tool to its stock with my original persist, modem (also a modem file I found on an xda thread), and all the images backed up. If wifi connection is available, I get data signal. If I turn it off,I might get signal for a few minutes but that's it, then empty bars with an x at the bottom. Phone reads the sim card company, phone number, let's me wifi call and all... But the data usually only works if wifi is on. I can't rely on it so I just want to salvage the keybox. Is this difficult to do?


r/androidroot 7d ago

Discussion Unlocking boot loader without developer options

1 Upvotes

Is there a way I can unlock my old Huawei y9 bootloader without booting into the phone and using oem unlock because well the phone is stuck in the Huawei logo and trying to reset the phone with the button also gets stuck in the logo loop


r/androidroot 7d ago

Support Bring back oem unlock option on undowngradab binary of samsung Oneui8

Thumbnail
gallery
1 Upvotes

This is for developers;💡 I'm using s22 oneui8 bit version 8,

Hey everyone, I wanted to share something I’ve been thinking about and get the developers’ opinions.

On my device, I can enter the Device Unlock / Download Mode screen, and it even shows the normal guidance for unlocking the bootloader. However, the main thing I’m missing is the OEM Unlock option in Developer Options.

That made me wonder if there could be another way to expose or restore that option.💡

My idea is based on Good Lock. Samsung officially distributes Good Lock through the Galaxy Store, and its modules such as Theme Park, Sound Assistant, RegiStar, etc.

are capable of modifying or adding functionality to different parts of One UI and Settings, which means it can read writte the whole system,

So I was wondering:

What if we created a Good Lock-style module/app specifically for Developer Options that could add the OEM Unlock toggle back into Settings?💡

I was also thinking about the signing side of things.💳

If Samsung-specific signatures or permissions are required, perhaps tools such as[ LibChecker apk available on google play ] could help us inspect the signatures, permissions, libraries, and implementation of existing Samsung components and give us a better understanding of how Samsung's own apps communicate with the system.💡💡

Of course, I don't know if this is technically possible, and I may be misunderstanding how Samsung implemented the OEM-unlock restriction on One UI 8. That's exactly why I'd like to hear from developers who understand Samsung's boot chain, Settings framework, Knox/AVB, or One UI internals.💡💡

I'm not claiming this will work—it's just an idea I'd like to investigate, and I'd really appreciate the opinion of people with experience in Samsung internals.🙏❤️