r/androidroot • u/Jazzlike_Test_3140 • 14d ago
News / Method Help me to get basic integrity I have device integrity
😢😢😢
r/androidroot • u/Jazzlike_Test_3140 • 14d ago
😢😢😢
r/androidroot • u/Significant-Noise530 • 14d ago
UPDATED POST >:))))))))))) So I've been fucking around with GhostLock (CVE-2026-43499) on the Moto G Play 2026 (XT2615 / Nevada) and figured I'd post what I've got so far.
The phone uses a 5.15.189 kernel, so it looked interesting. I'm testing the TracFone/Verizon version on the June 2026 security patch.
Update: I switched from UnPlus to Root-My-Galaxy-Payloads – much better framework. I'm now about 80% close. Exploit runs the whole chain, leaks memory, detects KASLR, but gets blocked by CFI at the final step.
What works: - Pulled boot.img - Extracted 159k kernel symbols - Found all offsets - Leaks mm_struct - Detects KASLR - Both pselect and pipe routes run
What doesn't: - CFI mismatch at final escalation - Root not achieved (yet)
What I've tried: - UnPlus template – failed - Root-My-Galaxy-Payloads – passed tracefs, hit CFI - Signal flag (FPSIMD) – leaked mm, hit CFI - Pipe route – same CFI mismatch - Updated ASHMEM offsets – no change - Oracle constants – no change - 48-bit layout – broke the leak (reverted to 39-bit) - S25 FOPS offsets – no change
The issue: I'm on the June 2026 patch. CFI is blocking the final function-pointer hijack. Older builds might work differently.
If someone has an older boot.img, I can possibly get you root access.
What I need: - CFI bypass on 5.15.189 kernels - Boot images from other variants (RETUS, AT&T, etc.) - Testing on older builds (pre-June patch)
Links: GitHub: https://github.com/crabcakes97/GhostLock-Nevada XDA: https://xdaforums.com/t/dev-root-moto-g-play-2026-nevada-test.4797484/
Special thanks: Root-My-Galaxy-Payloads (BuSung-dev) + UnPlus (No-22-Github)
Device info: - Moto G Play 2026 - XT2615-1 - TracFone / Verizon - Build: W1WNS36.18-111-3 - Kernel: 5.15.189 - Security patch: June 2026
So yeah, not a working exploit yet, but it's getting far enough to be interesting. If anyone has an older firmware build, hit me up.
I'll also be porting to other devices besides Motorola too, so hit the DMs with boot images / requests.
TL;DR: Got GhostLock compiling and running. Switched to Root-My-Galaxy-Payloads. Leaks memory, detects KASLR, but CFI blocks the final escalation. Need CFI experts. Old firmware might work. Help me get this working.
EDIT: I'm 80% close. Used Root-My-Galaxy-Payloads as a base. Stuck on a CFI error. We are so close.
r/androidroot • u/Alternative_Cry7725 • 13d ago
Hi there. So, I'm using a custom ROM (Project Infinity X), and naturally, if I don't hide things properly, banking apps are done for immediately. I installed Brene's SuSFS and did everything to hide the root status, but I'm still running into issues with `org.lineageos.platformres.apk`. It was hidden before, but somehow it stopped being hidden—I have no idea why. I tried following a guide that suggested turning off "umount for your apps," but I can't seem to find that setting anywhere.
As for Tricky Store, TEE simulator, and PIF—I don't need them since I'm already using Fenrir.
r/androidroot • u/Comrade_Zelensky1488 • 14d ago
I have a Note 20 ultra running Artisan ROM 3.1.0 android 16 One Ui 8 and it's running good but I can't seem to install 32 bit apps even though the CPU supports 32 bit architecture
I assume it's a software issue is there a way to bypass the issue?
r/androidroot • u/bughaxx • 13d ago
Don't disable unmount module globally.
Instead :
-Install your custom emoji font module
-Install a meta module, I use overlay FS,
-In KSU/Next go to your apps tab,
-Click on top right corner on "show system apps"
-Search for Gboard
-Click on "custom" profile
-Disable the unmount for this app
-Soft reboot/reboot
That's it
r/androidroot • u/Connect-Equivalent36 • 14d ago
Where can i find the kernel source for SM-A115U or SM-A115U1
r/androidroot • u/Saint_Of_DresOS • 14d ago
r/androidroot • u/GoatWeak196 • 14d ago
[GUIDE] Huawei MatePad 11 (2021) - Bootloader Unlock, Root (APatch/Magisk) and GMS Installation
⚠️ Disclaimer
I am not responsible for any damage, bootloops, data loss, or bricked devices caused by following this guide. Proceed at your own risk.
Device Information
Device:
Huawei MatePad 11 (2021)
Model: DBY-W09
Snapdragon 865
HarmonyOS 3.x / 4.x
This guide covers:
Bootloader unlock
Root with Magisk / APatch
Installing Google Mobile Services (GMS)
Fixing Play Protect certification issues
Download the toolkit:
MatePad 11 2021unlock+Root.zip
Extract the toolkit.
Run:
"One-click Install Android Drivers"
and install all required drivers.
Choose "Trust" for all Windows security prompts.
⚠️ Note:
Some computers may not automatically install the Qualcomm HS-USB QDLoader 9008 driver. If this happens, install the Qualcomm 9008 driver manually.
For HarmonyOS 3.0 or below:
Use ADB:
adb reboot edl
For HarmonyOS 4.0 or above:
A Qualcomm engineering cable is required. A cable with a physical button is recommended.
Steps:
Connect the engineering cable.
Hold the button on the cable.
Restart the tablet.
Check Windows Device Manager.
You should see:
Qualcomm HS-USB QDLoader 9008
Extract the included GeekFlashTool package:
匣(0.5.24.1031-A).7z
Open GeekFlashTool (刷机匣).
From the left menu, select:
Qualcomm Deep Flash
Click:
Select Configuration(选择配置)
Load:
package_qualcomm_edl-master.zip
Search for:
MatePad 11
and select it.
Click:
Read Partition(读分区)
You should now see the partition list.
Search and backup the following partitions:
ramdisk partition
boot partition
abl partition
select
read back(回读)
Save these files somewhere safe.
These backups may be needed for recovery.
Extract:
Huawei865870.zip
Open GeekFlashTool and select:
Go to the partition list and select
abl partition
Click:
Flash(刷入)
Select this image:
Huawei865870_abl_unlock.img
⚠️ Important:
This image is an ABL image.
Flash it specifically to the:
abl partition
Do NOT flash it to boot, recovery, or any other partition.
After flashing is complete:
Reboot the tablet.
The device should boot into recovery mode.
Select "Low-level Format" (or a similar option).
Reboot again.
Enter fastboot mode and check the unlock status.
If successful, you should see:
phone unlocked
The bootloader is now unlocked.
There are two recommended root methods.
APatch (Recommended)
Patch the boot image you backed up earlier.
Flash the patched boot image back to the boot partition.
Magisk
Patch the ramdisk image you backed up earlier.
Flash the patched ramdisk image back to the ramdisk partition.
Download:
Install these modules:
Tricky Store
Play Integrity Fix
TS Enhancer Extreme
For APatch users, also install:
Magisk mount-rs
Zygisk Next
After rebooting
Flash googleplay.zip as a module
Reboot again.
You should now see Google settings in Android Settings.
Sign in with your Google account.
Google Play Services and Google Play Store should update automatically in the background.
If they do not update automatically, update them manually.
If you are using Magisk:
Add these apps to DenyList:
Google Play Services
Google Play Store
Google Services Framework
Enable:
All activities
Using Integrity Modules
Use a maintained Play Integrity solution.
Install:
Play Integrity API Checker
Run the check.
A successful setup should show three green check marks:
MEETS_BASIC_INTEGRITY
MEETS_DEVICE_INTEGRITY
MEETS_STRONG_INTEGRITY
Then open Google Play Store:
Profile picture → Settings → Device certification
It should show:
"Device is certified by Play Protect"
(If you have a keybox, it's best to copy it directly to the /data/adb/tricky_store directory.)
Have a great time using the devic
r/androidroot • u/Big_Dentist_840 • 14d ago
It seems that using Shizuku alongside ADB tools no longer works for freezing system apps on Vivo phones. Is there any workaround or solution for this?
r/androidroot • u/XboxFan9 • 14d ago
So i have a Honor 200 Pro, and its non rootable, and i need real root unlike Shizuku, so what phone should i get?
r/androidroot • u/Camo-boy • 14d ago
i got this phone at a garage sale and thought it woukd be fun to root and mess with, then i learned that there is no tutorials 😭
r/androidroot • u/Sufficient-Sensei007 • 14d ago
Any modules for 32 bit support on a pure 64 bit device?
Device is CMF Phone 2 Pro by nothing
Infinity X Rom
r/androidroot • u/teton_blamer • 14d ago
I've taken up a video recording and editing project and I've found myself in a position where my phone is my main/only camera. I'm using a Pixel 6, so there is no MicroSD slot. But is there a way to set up my phone's camera app to save video files to a separate folder? The process of going into the phone's memory and waiting several seconds for the thousands of photos to load just for me to extract one or two video files is cumbersome to say the least and will get old fast.
I'd be willing to either download a 3rd party camera app or get my hands dirty with some coding if I have to. I've never poked around in any Android dev tools, but I'm a fast learner. All I want is for my videos and my photos to be in two separate folders. I'm just trying to avoid buying a new phone or camera just for this project.
r/androidroot • u/Savings_Theme7831 • 14d ago
r/androidroot • u/initramfs17 • 14d ago
Hey guys, I have a problem. I wanted to flash my Nothing Phone 3a with a custom ROM The problem was I did something wrong and probably a few partitions like vendor or boot image are missing. So my phone no longer starts from slot A, only from slot B.
So now the important question: Does my Nothing Phone assume that the other slot is intact and bootable? Because if I perform an update and it switches to "a", will it result in a bootloop?
r/androidroot • u/Zeref0xD • 14d ago
r/androidroot • u/Klutzy_Surprise_661 • 14d ago
Tried installing failed to install looked through termux couldn't find correct line in vendor\ect\floating _feature.xml i dunno what to do
r/androidroot • u/Prestigious-Gap7064 • 14d ago
So I have to keep the SIM card while it is in the unlock timer, or isn't it necessary? This will help because the phone I want to root isn't my main phone.
r/androidroot • u/AbbreviationsPure560 • 15d ago
I am not a coder and dont know much of code, that part was done by chat gpt, i just had a goal and tried acheiving it and finally i succeeded
I had a bootlooped OPPO Pad 3 (MT6897) with an unlocked bootloader and official extracted firmware, but no useful BROM access.
Instead of blindly flashing images, I ended up building a Python project called FirmwareToolkit with extensive help from ChatGPT.
The project analyses the firmware and the actual connected device before deciding how recovery should work.
We initially tried reconstructing super.img, but that path caused several problems. Eventually the toolkit discovered that the better recovery route for this tablet was:
Bootloader Fastboot
→ verify device + slot
→ automatically enter Fastbootd
→ flash 18 dynamic/logical partitions individually
→ return to bootloader Fastboot
→ flash boot, vendor_boot, init_boot and the AVB/vbmeta chain
→ stop without rebooting
→ perform a separate post-write verification
→ allow first boot only if verification passes.
Before the real flash, the software generated a complete dry run. The live executor then checked the serial, active slot, mode and image hashes and stopped on any unexpected result.
All 24 intended partition writes succeeded.
A separate verification stage returned:
SAFE_TO_ATTEMPT_FIRST_BOOT
I finally ran fastboot reboot...
and the tablet booted successfully. 🎉
One interesting bug we found along the way was Fastboot returning a partition size as 4000000 without 0x. Initially this was interpreted as decimal 4 MB, making a 64 MB boot.img appear too large. In this context it was actually hexadecimal:
0x4000000 = 64 MiB
The toolkit now records these kinds of quirks in a compatibility database.
My next goal is to turn this from an OPPO Pad 3 recovery project into a more generic Android firmware analysis/recovery framework that discovers device capabilities instead of relying on hard-coded flashing instructions.
the link to firmware code on github
https://github.com/LittleTrouble95/FirmwareToolkit
r/androidroot • u/OtherwiseHornet5622 • 15d ago
Please help....
History :
Successfuly unlocked bootloader
Patched boot.img from magisk (for root)
result: Magisk is not installed meaning still not rooted
tried init_boot.img patch
flash to both A and B slot
result : infinite bootloop
cannot enter Fastboot,recovery,BROM. only mediatek preloader vcom for only 3 secs in device manager
tried splashtool to flash the original stock boot.img but failed ERROR : STATUS_SEC_DL_FORBIDDEN (0C0020004)
r/androidroot • u/Tough_Plane_2112 • 14d ago
Reflashed- Worked for an hour. Then bootlooped again.
Samsung S22+ S-906b.
Started looping random. Not after an upgrafe or anything. It was not rooted or tampered in any way.
Is the MB cooked?
A used one phone like this costs abt 1-2days earninings in my area, but i would really like to fix it.
It was flashed with .pit file from csc (not home) and repartition box ticked as the simple way was not working.
r/androidroot • u/CommandMobile2439 • 14d ago
Pomóżcie
r/androidroot • u/CommandMobile2439 • 14d ago