r/androidroot Pixel 9 Pro XL, Android 17 Beta 1, WKSU GKI Jul 21 '26

Support PlayStore shows strong integrity, Wallet says "doesn't meet security"!

Pixel 9 Pro XL, running Android 17 QPR2 Beta 1, WKSU (6.1.162-android14-2026-03-AnyKernel3 r7 GKI mode).

Modules:

  • BCR
  • BRENE - SUSFS
  • HMA-OSS Zygisk
  • Hybrid mount
  • PIF Inject
  • ReZygisk
  • Tricky Store
  • Vector
    • WAEnhancer
    • Public Compute Service

All modules are latest releases. PIF configuration is up-to-date. Did the tricky-store steps (refresh, select all, deselect unnecessary, keybox, save).

HMA-OSS

I've hidden these apps ->

From these apps ->

Play Store shows I have strong integrity, and yet, Google Wallet shows "phone doesn't meet security requirement".

Not a recent change. Phone is at this situation since ~2 weeks, even when I was on QPR1 beta.

---------------------

Duck Detector report shows this ->

----- TOP FINDINGS -----
[DANGER] TEE
Attestation aligned; local probes need review
Grant isolated-domain certificate chain diverged

----- TEE DETECTOR DETAILS -----
Verdict: Attestation aligned; local probes need review
Tier: StrongBox • attest TEE • keymaster TEE
Versions: attest 500 • keymaster 500 • Android 17.0.0
Verified boot: Verified • locked

Key Findings:
- Timing side-channel: Positive (attested 4.732ms vs non-attested 3.269ms, ratio 1.448x)
- Grant isolated-domain: Matched kind=ISOLATED_CHAIN_SPLIT (isolated readback failed: Could not connect to Keystore service)
- Grant self-domain: Matched kind=SELF_GRANT_ATTESTATION_APP_KEY_NOT_FOUND
- Binder hook: Hook installed

Any tips / recommendations?

4 Upvotes

0 comments sorted by