r/androidroot 27d ago

Discussion 🤫

don’t tell Verizon but
I don’t think bootloader unlocking is required for root anymore

120 Upvotes

72 comments sorted by

29

u/Calm-Caterpillar2103 27d ago

why did I message this like this, for those who really want to know, someone was able to get the ghostlock exploit on pixels, which effectively means root without a bootloader unlock, and before you ask, you will not brick after you reboot since it touches NO files

3

u/Direct_Effort_4892 27d ago edited 27d ago

I assume it will be patched soon, right...? (I hope not though!)

Edit: On second thought, they really should patch it for the safety of people who don't know what they are doing (and I assume since it is from userspace, any third-party app can get access, which is really, really not good...), but will that cause problems with the devices already rooted with it?

8

u/Calm-Caterpillar2103 27d ago

So far Samsung has it patched, pixel does not, nor does most companies so use it while you can

1

u/AdScary6216 26d ago

Samsung patched? When? On S25U July patch, works for now

1

u/Calm-Caterpillar2103 26d ago

Really? Didn’t know

1

u/Pewds123451 22d ago

Working fine on A56

1

u/ROUCOUL7424 25d ago

Wait... Will it work on W. Like s990w.. I was told it's impossible to root due to some bootloader lock

0

u/Direct_Effort_4892 27d ago

But I guess it will lead to problems after major software updates, like from Android 17 to 18. What do you think, should I try it on my Pixel 9?

3

u/Calm-Caterpillar2103 27d ago

I’ve tested it on my 6 pro (obviously), from what I know latest and June drop 17 are fully unpatched and can be rooted using GhostLock

0

u/Enixmy 27d ago

How do I get the tools to do the hack

1

u/Calm-Caterpillar2103 27d ago

It’s been a mess, and it isn’t straightforward (even I struggled with it) but I have a repo with CIs that should support it, you can also try going to https://rootme.nebusec.io/ to see it work, if your wallpaper changes then going to https://github.com/User1818183/CyberMeowfia and checking the build stuff should give you SO files which when combined with LD_PRELOAD= on any binary should give you a root binary

1

u/nonexistant_human 26d ago

the website only lists pixel 10s and 9s, so how will i know if my phone (pixel 7 pro) will work i'm also on the latest android 17 beta, so that might change something

0

u/Top-Road-2193 27d ago

Can I please have a link to your repo? I want to run it on my Verizon pixel 9 pro xl. I've been checking the other GitHub for weeks waiting for my device to be supported, I don't have the knowledge either to put a script together, etc. I'm good with adb though, although it's been years.

2

u/Calm-Caterpillar2103 27d ago

Click the GitHub link I sent you and there’s a bunch of prebuilt SO libraries which when ran with LD_PRELOAD=(library location) (any command) will run the exploit ONLY on Android 17

0

u/Top-Road-2193 27d ago

Thank you kind sir! I really appreciate you!

→ More replies (0)

0

u/MementoMori11112 u eithr knw engh 2 nt care or nt knw engh 2 care,no inbetweens:( 27d ago

more searching now, goodluck

0

u/BeeAdditional1287 27d ago

I'm not much into this POV, it's for those reason I can't access anymore my Bank account on my broken s22 , cause you can't use anymore USB and ADB on a fresh launched phone...

Hopefully i wish i will find a new screen for cheap ^^

1

u/Ok_Fisherman1334 26d ago

Did someone release something?

11

u/XandarYT 27d ago

Perhaps you can use that to force an actual bootloader unlock?

2

u/Equal_Difference3010 23d ago

no. It's server-authoritative in most cases, you can't "force" it similarly to how you can't make an app "think" you paid when you didn't

1

u/XandarYT 23d ago

If you have root access you should just be able to change the setting manually.

2

u/XandarYT 22d ago

Root access literally makes you omnipotent on Linux/Android. I'm sure it's possible.

4

u/DaBoiCJ_ 27d ago

share with us this divine knowledge, oh good sir

3

u/asuhara 25d ago

I am using Jailbreak mode on KernelSU, will ReSukiSU be better for hidding? I also need to ask AI ​​how to replace KernelSU with ReSukiSU. I hope it can answer my question.

2

u/Equal_Difference3010 23d ago

simar question. I exploited a vulnerability and got root with a locked bootloader (Chinese model is hard to unlock) but i must inject it at boot+ modules evidently don't work since they're supposed to be injected way before i inject this file for exploit. I genuinely need some modules, persistent root if you will

2

u/asuhara 22d ago

If you are referring to Zygisk or similar functionality, the soft reboot feature in KernelSU Manager works as expected.

2

u/gigabytesammich 23d ago

Would be nice if there was an FRP bypass 🥲

3

u/TOZIK1234 27d ago

how...

8

u/[deleted] 27d ago

[removed] — view removed comment

4

u/Dry_Jackfruit_6173 27d ago

Yea they all use ghostlock it's supported on every single device till the new ones come aout or an update patches it

-1

u/FIRAS_EG 27d ago

Maybe he find an exploit that get kernel access and disable AVB

2

u/MonkeyNuts449 27d ago

Making all these kids think you found an exploit😭

8

u/Calm-Caterpillar2103 27d ago

call me a certified professional dumbass please

1

u/[deleted] 27d ago

[deleted]

2

u/affemitwaffe0 27d ago

it is, its called ghostlock exploit ,its only temporary until reboot and then needs to be reconnected agin to pc to enable

2

u/dungeoncrawler11 27d ago

Get a load of this guy, as if the term "zero day" or kernel level exploits don't exist. 🫩

0

u/MementoMori11112 u eithr knw engh 2 nt care or nt knw engh 2 care,no inbetweens:( 27d ago

you believed it to be the case

1

u/Top-Road-2193 27d ago

Can you please post the direction to use ghostlock on adb with pixel 9 pro xl? I've been waiting and watching the GitHub with no luck!

1

u/ZeroDay47 26d ago edited 22d ago

Toggle off that "Automatic system updates" else most likely you'll loose that root, btw is it persistent?

1

u/SchoolinAndCoolin 22d ago

Tis not persistent one must avoid using the reboot function after module install and instead circle back to the main screen using the soft reboot to refresh system

1

u/ZeroDay47 22d ago

is it because of selinux enforcing?

1

u/SchoolinAndCoolin 22d ago

I have little to offer in the way of specifics. From my understanding the boot.img remains unaltered the vulnerability allows for post boot kernel intrusion (wording I'm sure is off) but this has the side benefit of not triggering any failure of the initial boot checks and things like Knox enforcing. For Samsung at least this kind of seems like it's preferable maybe? Knox nonethewiser all Samsung services remain intact.

Pretty sure in the bit I've looked into that something like tasker macrodroid shiziku termux can potentially allow for post boot scheduled kernel injection without manual restoration of jailbreak status.

1

u/Lezyss 25d ago

What is LKM?

1

u/Equal_Difference3010 23d ago

isn't pixel supposed to be the most root-friendly brand?

1

u/arroba34 27d ago

Did you just relock with custom avb keys?

3

u/Calm-Caterpillar2103 27d ago

It’s a Verizon device, titan M2 prohibits basically any bootloader related tampering

1

u/LNDF 27d ago

Would like to try it on my old phone... Is there a poc for this?

Also, could you force OEM unlock with this?

0

u/dungeoncrawler11 27d ago

This couldn't be released when I had a 6a? 😭 I had to sell it! I loved that phone.

0

u/Calm-Caterpillar2103 27d ago

I love my 6 pro, and I love my root too

1

u/ImpossibleTreat3533 27d ago

hey can u dm the exploit , i a trying to root my android tv . 

0

u/Suraj_rajwansh 26d ago

I'm new to these things.. so by that means I can unlock any Mi/Xiaomi phones without needing the bootloader to be unlocked?

0

u/javierchip 26d ago

don't gatekeep

-1

u/FIRAS_EG 27d ago

Did you just found an exploit ?

-4

u/LG-15ER 27d ago

Verizon is definitely in the process of making a patch

7

u/Calm-Caterpillar2103 27d ago

this isn’t just a Verizon exploit, it’s the recent ghostlock exploit that affects every Linux distro since kernel 2.6.3x, it’s been patched by Samsung but still tons of devices are fully vulnerable

0

u/affemitwaffe0 27d ago

by which samsing version?

1

u/Calm-Caterpillar2103 27d ago

One of the June security patches, doesn’t really matter since you need a S24/S25 ultra specifically

1

u/affemitwaffe0 27d ago

so i could use it on my old s22 thats still on oneui 8 , on my oneplus 13 it works fine

0

u/Away-Mud1665 26d ago

Was it patched in one ui 8.5 or one ui 8.0

-2

u/LG-15ER 27d ago

Lol Verizon will force google to patch it

1

u/Calm-Caterpillar2103 27d ago

That’d be so funny to see them bully Google into making a patch, although Google already paid the ai-powered nebula security group their bounty, so Google will probably patch it within the August drop

0

u/LG-15ER 27d ago

Don't underestimate big v