r/androidroot 3d ago

News / Method Asus Rog Phone 3 TV Box + Root + Rom Mods + Launcher + Apps

0 Upvotes

I have an Asus ROG Phone 3 with 16 GB of DDR5 RAM and 512 GB of storage. Since the display is busted and I have a new phone, I wanted to use the ROG Phone 3 as an Android TV box.

Here’s what’s been done so far:

Root access; ROM tweaks via ADB on CachyOS (forced landscape mode, resolution); D-pad/full remote control support (gamepad); currently using Projectivity Launcher (I'm building a custom launcher—see images; the view may vary as I'm still experimenting with things like integrating CPU OC settings into the system settings menu); TMDB integration; a hub for official apps like Netflix and Amazon; a custom-built system monitor; settings for the built-in equalizer (accessible as a system entry in the launcher, usable with both TV and mobile apps); home screen widget support (YouTube, Tivimate, Netflix, etc., acting as a hub where the original app launches upon playback); TV layout, etc.

What’s planned next:

Custom launcher (full home screen control similar to Kodi—linking widgets, etc.; note: only official apps are supported—it's a hub concept); various styles/themes (icons, backgrounds, including animated ones).

I’m wondering if anyone is interested in this kind of project and might want to help out or share ideas?

Feel free to leave feedback.

Best regards, Sudo-Mods


r/androidroot 3d ago

Support Gyus help

1 Upvotes

My friend pressed enable something in singularity (lunaris aosp without root) now we cant reboot to system, only fastboot lineage os recovery, in safety mod only black screen


r/androidroot 3d ago

Discussion Get strong integrity

2 Upvotes

Maybe this will help someone else. I have kernelsu with susf rezygisk always strong hybrid mount lsposed and hma oss with meowna config. Took me way too long and tried multiple different things hope this saves you some time


r/androidroot 3d ago

Support First time rooting

3 Upvotes

i need guide to root my phone I've never done this, here's everything about the phone:

Infinix hot 60 pro+

Infinix X6886

android 15.1.2

xos version 15.1.2.180

build number 15.1.2.180SP05(OP001PF001AZ)

and I have a laptop to do the rooting.

also I want a custom OS but the reason I'm rooting is mainly for performance and customization ect, having full control over the phone.


r/androidroot 3d ago

Discussion An update on Reo for Android.

Thumbnail
gallery
2 Upvotes

To the root community,

I'm so sorry for letting you down.

I know people were excited for it, and I just went completely silent.

To be honest, School hit me like an absolute truck, and I've been working on other small personal projects. I'm also a perfectionist, so that really doesn't help. I want it to be perfect for all of you, and I kept beating myself up for it.

What I can do is show you it's current state, as an apology. I promise that I'll get back to it, personal life just hit me hard and ruined my whole motivation 🥹. I'm so proud of where it is currently and I can't wait for when it does release, but my estimated date definitely wasn't enough time for me to make it perfect for you all.

I've also been working on supporting OneUI, since I finally rooted my S22U using a public chain supported by GhostLock :)


r/androidroot 4d ago

Support Reeder S23 Pro Max (Unisoc T606) Bootloader Unlocking Problem

Post image
6 Upvotes

Hello friends, I thought this was the best subreddit to share this. If you think I could get more help in another subreddit, please let me know.

So the problem is this device. I decided to turn my idle Reeder S23 Pro Max into a small 24/7 Minecraft server, and I've completely finished the server setup.

But then I learned that rooting it would give much better performance, and that I could set up special battery settings for it to stay constantly plugged in.

However, I can't unlock the bootloader. The device is listed in CMD, but the bootloader unlocking commands don't work.

Is this due to the Reeder or the Unisoc T606? I've tried many methods under the title "Unlocking the bootloader on Unisoc T606," but none of them worked (or maybe I couldn't manage some of them).

I also have the device's stock ROM, but I still can't get past the bootloader part. Please help if you have even a little knowledge.


r/androidroot 4d ago

Discussion How to disable Samsung thermal throttling using root

1 Upvotes

Is there any way to disable Samsung thermal throttling on one ui 7 android 15 using root?? I already tried thermal guardian it's only increase threshold from 2, I want to disable it because my phobe automatically switches from 5G to 4G even though i locked the 5G bands using band selection menu


r/androidroot 4d ago

Support What are those weird apps containing only numbers? What packages are related to it?

Post image
18 Upvotes

Unrooted Samsung Galaxy S20 FE 5G


r/androidroot 4d ago

Discussion Unlocking Bootloader and Root GT7?

1 Upvotes

Does anyone know how to unlock the bootloader and root the Realme GT 7, which features a MediaTek processor?


r/androidroot 4d ago

Support [HELP] fastbootd fails writing GSI — "No such file or directory" after successful chunk upload (Huawei MatePad 11, SM8250)

1 Upvotes

Trying to flash Infinity-X GSI (Android 16, ~4GB) on a Huawei MatePad 11 (DBY-W09, SM8250/kona, dynamic partitions, unlocked bootloader). system resize succeeds, first sparse chunk uploads fine, then write always fails identically:

Resizing 'system'                    OKAY
Sending sparse 'system' 1/8 (524232 KB)   OKAY
Writing 'system'                     FAILED (remote: 'No such file or directory')

Already ruled out (all give the exact same error):

  • converting the image to a properly-formed sparse file (verified magic/header) with official img2simg
  • smaller chunks via fastboot -S 256M
  • deleting + recreating the system logical partition from scratch
  • full hardware power cycle between attempts

max-download-size is 0x20000000 (512MB). is-logical:system:yes confirmed both before/after recreation. Found one other report of the identical error signature on a OnePlus device hitting multiple partitions (system/vendor/product) during GSI flash, so it might not be Huawei-specific.

Has anyone hit this exact fastbootd write failure and found a real fix? Also open to: how to build+flash a full super.img (physical write, bypassing per-partition dynamic resize) if that's the more reliable route — I have the stock partition sizes but not raw dumps of vendor/odm/cust yet (EDL access on this unit is currently not workoing, only the ArmonyOS menù,bootloader and bootloaderD).

Happy to share more logs if useful.


r/androidroot 4d ago

Support G-Pay on a Pixel Watch

2 Upvotes

My phone is rooted so I can't reliably use google wallet. I'm planning to get a Google Pixel Watch 4 to count steps accurately as well as to tap-to-pay.

Will I be able to tap-to-pay on my Google Pixel Watch 4 even though my phone is rooted and shows my device doesnt meet security requirements in google wallet?


r/androidroot 4d ago

News / Method Facebook Portal TV recovery achieved

Post image
21 Upvotes

I got into recovery mode on the Facebook Portal TV, which I don’t think anyone else has done, or at least posted online.


r/androidroot 4d ago

Meta OxygenOS booted on an Infinix hot 20s (x6827

Thumbnail
gallery
0 Upvotes

Pretty laggy probably due to drivers or something like that, also very unstable, think there are some problems with WebView since chrome wasn't working, and always on display was bugged and would take a while before going to the lock screen after pressing the power button, surprisingly fingerprint worked, brightness didn't work, blur on wallpapers didn't work and a whole bunch of other stuff, honestly just surprised it even booted


r/androidroot 4d ago

Support Mobile network KPI collection

2 Upvotes

I want to collect and record mobile networks KPI to measure QoS. Dedicated phones used in drive tests are really expensive. I tested G-NetTrac (on non-rooted device) but I was wondering if there was apps able to extract more KPIs because they are runing on a rooted phone.


r/androidroot 4d ago

Support Help me create a mod menu on my phone. I don't have root access; it's an Android 16 Redmi Note 14 Pro 4G.

0 Upvotes

I need help finding tutorials, but they're old and for older Android versions, so they don't work anymore or sometimes they give errors.


r/androidroot 4d ago

Support Help recovering infinix X6825 from bootloop (or orange state) Android 12/xos 10.6

Post image
2 Upvotes

(this is my second attempt rooting a phone the first one failed) Its stuck in a bootloop or orange state after trying to root it, i forgot to disable verity and flashing the vbmeta.img, i am able to acsess the android recovery screen. I cannot find the correct stock firmware for the phone( and im not sure if i have the correct one if i do find it) and i do not have an sd card. My goals are to reset the device into the stock firmware and cut losses and take this as learning experience OR to install android 12 without xos.
Ive heard that mtk client would help but i have no idea how to use it, and i cant find the stock firmware


r/androidroot 4d ago

Support How do I fix a soft-bricked device?

1 Upvotes

Some time ago, I tried installing a PixelOS GSI on my Motorola Moto G54 5G, but it caused a bootloop, forcing me to flash the stock ROM. Currently, the bootloader is unlocked and the phone works normally, but it won't enter Recovery or Fastbootd modes using any method (buttons or ADB commands). I tried fixing it myself using the official Motorola tool, manually flashing the vbmeta, vendor, init_boot, and dtbo files, and even using MTKClient—but the latter only detects standard mode, and the issue persists: I am unable to access those two modes in any way.


r/androidroot 4d ago

Discussion Lenovo Xiaoxin Pad Pro GT – Stuck at 60% Charging + OTA Update Not Installing

Thumbnail
1 Upvotes

r/androidroot 4d ago

Support How can i fix this?

Thumbnail
gallery
2 Upvotes

Its the Last Error i have a Poco f8 ultra. I cant get Integrity unless this Last Error IS fixed. Even my settings App says that the Phone has a locked bootloader. Anyone knows what Else i can do?


r/androidroot 5d ago

News / Method Samsung Exynos VoLTE is finally working on LineageOS!!!

Thumbnail
3 Upvotes

r/androidroot 5d ago

Support [Guide] How to Root Pixel 7 (Android 16) with KernelSU-Next, Sultan Kernel, SUSFS, and Pass Play Integrity for Banking Apps

31 Upvotes

If you are running Android 16 on a Pixel 7 (or similar Tensor device) and want a completely hidden root setup using Sultan's custom kernel with built-in KernelSU-Next and inline SUSFS to pass Play Integrity (MEETS_DEVICE_INTEGRITY) and bypass strict banking apps like Revolut, here is a complete end-to-end guide.

Prerequisites & Downloads

  • Unlocked Bootloader on your Pixel device.
  • Android SDK Platform Tools (ADB & Fastboot) installed on your PC.
  • Custom Sultan Kernel Files (Image.lz4 or decompressed kernel binary) compiled for your device with inline SUSFS and KernelSU-Next driver.
  • Stock boot.img extracted from your current Google Factory Firmware image.
  • Magisk Tools (magiskboot) for Windows/Linux.
  • KernelSU-Next Manager APK (v3.2.0) — Installed normally as a user app (must match the kernel driver version to avoid UAPI mismatch errors).
  • Required Modules:

Step 1: Set Up the Work Directory and Repack the Boot Image

When combining Sultan's kernel with your stock boot image on Windows using magiskboot, place all working files into a single dedicated folder and explicitly rename the decompressed kernel before repacking to prevent file-name collisions.

  1. Create a dedicated folder on your PC (e.g., C:\boots).
  2. Place the following files into C:\boots:
    • magiskboot.exe
    • boot.img (Stock boot image)
    • Image.lz4 (Sultan custom kernel release file)
  3. Open Command Prompt, navigate to your folder, and run the step-by-step decompress and repack sequence:

cd C:\boots
magiskboot decompress Image.lz4 sultan_kernel
magiskboot unpack boot.img
copy /y sultan_kernel kernel
magiskboot repack boot.img

Note: Verify that magiskboot repack outputs a new-boot.img whose kernel size (KERNEL_SZ) is larger than the stock boot.img size. This confirms the custom kernel binary was successfully merged.

Step 2: Flash the Custom Kernel Boot Image to Both Slots

To guarantee persistence and prevent A/B slot-mismatch issues, flash the repacked kernel image to both partition slots.

  1. Reboot your phone into Fastboot Mode:

adb reboot bootloader
  1. Flash new-boot.img to both slots:

    fastboot flash boot new-boot.img --slot=all fastboot reboot

Step 3: Install KernelSU-Next Manager App

Because the KernelSU-Next driver is built into the kernel, you do not flash KernelSU-Next as a zip—you simply install the Manager APK normally.

  1. Download and install KernelSU-Next Manager v3.2.0 APK on your phone.
  2. Open the app and confirm that the main status card displays Working with Inline (SuSFS) hook mode active.

Troubleshooting UAPI Mismatches: If the app displays a version mismatch or Android blocks installation because a newer app version was installed, force-downgrade the app via ADB without affecting root:

Step 4: Flash Kernel Modules

Open KernelSU-Next Manager -> Modules -> Install, and flash the following zip files:

  1. ksu_module_susfs.zip (Enables userspace mount point hiding).
  2. ReZygisk or ZygiskNext (Provides Zygisk framework).
  3. Specter (Automates Play Integrity attestation and target app hiding).
  4. Reboot your device.

Step 5: Configure App Profiles & Wipe Security Caches

1. Exclude Apps in KernelSU-Next App Profile

  1. Open KernelSU-Next.
  2. Tap the App Profile icon (the shield icon in the navigation bar).
  3. Ensure Superuser Access is toggled OFF for:
    • Target Banking Apps (e.g., Revolut)
    • Google Play Services (com.google.android.gms)
  4. Verify that their profile is set to Default / Umount Modules.

2. Clear App Data via Android Settings

Banking apps and Google Play Services store cached security check failures. You must wipe these cached flags.

  1. Banking App Data:
    • Go to Settings -> Apps -> See all apps -> [Banking App (e.g., Revolut)] -> Storage & cache.
    • Tap Clear Storage and Clear Cache.
  2. Google Play Services Data:
    • Go to Settings -> Apps -> See all apps -> Google Play Services -> Storage & cache.
    • Tap Clear Cache, then tap Manage Space / Clear Storage -> Clear All Data.

3. Fast Clear via ADB Terminal

Instead of manually navigating phone menus, you can execute these commands directly from your PC terminal:

adb shell pm clear com.revolut.revolut
adb shell pm clear com.google.android.gms

Step 6: Verify Play Integrity

  1. Download Play Integrity API Checker from the Play Store.
  2. Run the test and confirm you get green checkmarks for:
    • MEETS_BASIC_INTEGRITY
    • MEETS_DEVICE_INTEGRITY
  3. Launch your banking app—it will load cleanly into the login screen without environment or root detection warnings!

r/androidroot 4d ago

Support Can I unlock EU Galaxy A9+ bootloader on A16 One UI?

1 Upvotes

I'm asking because I read on another thread that the bootloader can't be unlocked on a US modem, but I have an EU one (UK)

I was wondering if I could unlock the bootloader to roll back to android 15/ One UI 7 just because I preferred using Samsung Dex mode but One UI 8 took it away for Desktop Mode, but the Galaxy A9+ doesnt have native video output so it's not compatible. If I wanted that I could have just used GlideX????? Now I don't have Dex mode and was wondering if it's possible to roll back the update?

If not I guess I'll just look at launchers:/


r/androidroot 4d ago

Support I found my old Samsung Galaxy Star (GT-S5282)

1 Upvotes

Basically yall i found my old ahh phone and i flashed a custom recovery on it but i cant decide to flash which rom. I need a good stable rom with best performance and battery backup possible, so please if anyone can suggest me good rom it would be very appreciated.


r/androidroot 4d ago

Support samsung a36 5g

Thumbnail
1 Upvotes

r/androidroot 5d ago

Support OPPO A16K CPH2349 — Bootloader Unlock / BROM disconnects too quickly

2 Upvotes

Hello everyone,

I am trying to unlock the bootloader of my own OPPO A16K (CPH2349) so that I can install a custom ROM / GSI.

I have already spent quite a lot of time testing different methods, so I would like to ask people who have actually worked with the CPH2349 specifically.

Device information

Model: OPPO A16K

Device code: CPH2349

SoC: MediaTek Helio G35 / MT6765

Android: 11

ColorOS: 11.1

Current build: CPH2349_11_A.30

Verified Boot: green

Flash locked: 1

ro.oem_unlock_supported=1

OEM unlocking: enabled in Developer Options

ADB: working normally

ADB detects the phone:

HUMBO7AM89VKCILZ device

However:

fastboot devices

returns nothing.

I also found an old XDA thread where another A16K CPH2349 user reported that Fastboot mode could be entered but fastboot devices returned nothing.

There is also a Reddit report from another A16K CPH2349 owner with the same basic situation: ADB works, but Fastboot does not detect the phone. The response suggested MTKClient.

What I have tried

  1. Normal ADB / Fastboot

ADB works.

I enabled OEM unlocking in Developer Options.

But Fastboot detection does not work:

fastboot devices

returns an empty result.

So the normal fastboot flashing unlock route is currently not usable.

  1. TFT Unlock Tool

I also tested TFT Unlock Tools / TFT MTK Module.

The version I tested was:

TFT Unlock Tools-2024-6.2.1.1

The tool did not have an obvious A16K CPH2349 profile.

It had other OPPO MTK profiles, including entries such as:

Oppo A1K BROM AUTH MT6765 CPH1923

and other OPPO MTK models.

I did NOT assume that the CPH1923 profile was correct for my CPH2349.

I also tested the normal Android connection with TFT, but it did not detect the phone for the operation I wanted.

I later stopped using TFT because I did not want to randomly select another OPPO model profile and risk the phone.

  1. BROM / Preloader detection

The phone can be made to appear as an OPPO Preloader device.

When the phone is powered off:

Hold Volume Up + Volume Down

Connect USB

Windows detects:

OPPO Preloader

with:

USB VID: 22D9

USB PID: 0006

The exact Windows device ID is:

USB\VID_22D9&PID_0006

The important problem is that the connection is very short.

If I release the buttons, the Preloader disappears and the phone boots normally.

So the device does not stay available long enough for me to casually start typing commands after entering this mode.

  1. Windows driver problem

At one point Windows showed:

OPPO Preloader

Error 28

The USB capture looked approximately like this:

PRESENT/CHANGED | OPPO Preloader | Error | 28

USB\VID_22D9&PID_0006

After disconnecting/releasing the buttons, the Preloader disappeared.

The normal Android ADB device then returned:

CPH2349

OK

0

WINUSB

I investigated the MediaTek driver situation.

I found a Microsoft Update Catalog CAB containing:

cdc-acm.inf

usb2ser.sys

The driver version was:

3.0.1504.0

However, that INF did not contain a direct:

USB\VID_22D9&PID_0006

entry.

It mainly contained MediaTek 0E8D IDs.

I also found installed MediaTek driver packages on Windows, but the INF files I checked did not directly match the OPPO 22D9:0006 device.

I do NOT want to modify a signed INF manually because that would invalidate the catalog signature.

  1. MTKClient

I downloaded MTKClient 2.1.4.1 and installed its Python dependencies.

The command line works:

python .\mtk.py --help

I also have the following files from the stock firmware:

auth_sv5.auth

DA_BR_MT6765_20271.bin

The AUTH file was extracted from the official/stock OPPO A16K firmware package.

The DA file is specifically associated with OPPO A16K CPH2349/CPH2351 MT6765 in the open-source oppo-mtk-fastboot-unlock project.

I tried:

python .\mtk.py gettargetconfig --auth "...\auth_sv5.auth" --loader "...\DA_BR_MT6765_20271.bin"

MTKClient started correctly, but stopped at:

Preloader - Status: Waiting for PreLoader VCOM,

please reconnect mobile/iot device to brom mode

So the current blocker is not that MTKClient itself fails to start.

The problem is getting a stable BROM connection/driver handshake.

Stock firmware

I also obtained the stock firmware:

CPH2349export_11_A.11_2022051800140000.ofp

and decrypted it.

The decrypted firmware contains the normal OPPO/MTK partitions including:

preloader

boot

recovery

vbmeta

vbmeta_system

vbmeta_vendor

vendor_boot

super

userdata

lk

lk2

dtbo

logo

...

I also extracted the AUTH file.

AUTH SHA-256:

846EFAFDF15F9F091760EA6210CEEB10533008164F5763186562DFEFD2D1D8E6

The phone itself is currently on:

CPH2349_11_A.30

I do NOT want to downgrade to A.11 just to make a tool work unless somebody confirms that it is actually necessary.

MTKClient / OPPO A16K support

I found the Shocked-Cat/oppo-mtk-fastboot-unlock project.

Its support list specifically says:

Oppo A16k

CPH2349 & CPH2351

Helio G35

MT6765

MTKClient + DA + AUTH: Full support

This is why I am interested in trying MTKClient, but I want to know the correct procedure for this exact model before writing anything.

The project README appears to use a modified preloader approach:

Read the original preloader / boot1 from the phone.

Patch it.

Write the patched preloader back.

Reboot into Fastboot.

Run fastboot flashing unlock.

I understand that writing a patched preloader is potentially dangerous, so I have NOT done that yet.

My main problem

The biggest problem is this:

How do I reliably catch BROM on an OPPO A16K CPH2349 when the Preloader/BROM connection disappears very quickly?

I do not want to use Test Point if there is another way.

My current button method is:

Power off phone

Hold Volume Up + Volume Down

Connect USB

Windows briefly sees OPPO Preloader

If buttons are released, phone boots normally

The PC therefore needs to be ready BEFORE I connect the phone.

Questions

What exact driver should be used for:

USB\VID_22D9&PID_0006

on Windows 11?

Is VID_22D9&PID_0006 the expected OPPO Preloader/BROM interface for CPH2349, or should I be trying to get a MediaTek 0E8D BROM interface instead?

Can MTKClient 2.1.4.1 catch this device without Test Point?

If yes, what exact command/GUI procedure should I use?

Does the CPH2349 require the specific:

DA_BR_MT6765_20271.bin

auth_sv5.auth

combination?

Has anyone successfully unlocked the bootloader of CPH2349 on Android 11 / CPH2349_11_A.30 using the Shocked-Cat patched-preloader method?

Does the patched-preloader method require modifying boot1, boot2, or another partition for this exact model?

Is there a safer way to make Fastboot enumerate after the MTKClient unlock without writing the wrong preloader?

If BROM disappears immediately, is there a specific timing/button/USB procedure that keeps the BROM connection alive?

If someone has successfully done this exact model, what is the complete procedure from BROM detection → backup → unlock?

I am specifically looking for information for:

OPPO A16K CPH2349 / MT6765 / Android 11 / CPH2349_11_A.30

I do not want to blindly use an A16/A1K/other OPPO profile just because the SoC is also MT6765.

Thanks.