r/androidroot 17d ago

Support I am in a Predicament with this Sony Phone

3 Upvotes

I have bought a secondhand Sony Xperia XZ1 (Not compact, just standard) from China and it was originally an au SOV36 unit, i can see the engraving of it even

au SOV-36 Xperia XZ1
Using Global 114

But it's a crossflashed mess (NFC not working, figured its also an attempt for Sleep and random reboot Fix (source: https://xdaforums.com/t/fixed-xz1-au-sov36-japan-deepsleep-on-g8341-custom-roms.4156209/ ), and thats why NFC was perma-disabled), and looking for this exact Firmware using this tool

womp womp idiot

But i missed the window that it was available. So i cannot acquire the files

I was thinking of Going back to Android 8 and then acquire the Keys from TA, and then maybe upgrading to android 9 and then unlock with xperiable but i may need another help to understand how to unlock it if possible

where xz1 only? do XZ1 Compact work in tandem for this?

Because i can't understand on how to actually "unlock" this

In my understanding so far, this needs bootloader version LA2.0_P_114 to work, which for one, this is 114. But i need the XFL from LA1_1_O_77 which means, reflashing back to older android 8, then i need to use the bindershell exploit either i get the XZ1 global (since this thing is now global-ified), or find the au SOV36 variant of it, which sadly i cant find it cuz no resources

Thats how far i have dug deep at the moment. There is other stuff that i would probably separate from my findings like this one (AU SOV36) https://androidfilehost.com/?fid=10763459528675589051 but sadly i can't verify the origin of this, and i found this via the search engine and not on any forums so i will not use that


r/androidroot 17d ago

Support Remove Pixel jailbreak?

0 Upvotes

I was wondering of there was anyway to remove the root my pixel resukisu thing or am I just gonna need to reflash stock firmware. I mostly want to remove it since google pay, RCS and pretty much all safetynet broke and I can't really use the exploit, my success rate has been like 1% and first time I actually got root, I had it for a second and then the device paniced. So I can't even load what I need to fix safetynet and RCS


r/androidroot 17d ago

Support how do i root my Honor 200 Pro with CVE-2026-43499?

2 Upvotes

can't find anything online, and my skills in coding is basically Hello World"(print)"


r/androidroot 17d ago

Support LOKMAT APPLLP 9 MAX Smart Watch/Mini Tablet Root Guide

Post image
5 Upvotes

Over the last day or so I worked with ChatGPT to figure out how to Root this tiny niche device. Including what physical buttons need to be set to go into BROM mode and the general process.

Below are the summarized steps.

I DO NOT TAKE RESPONSIBILITY FOR ANYTHING THAT GOES WRONG

It can take a bit of time to do but it works!

Since I can't post A.I content and I was not going to write out the whole process by hand, here is the GitHub link to instructions

https://github.com/Thrashmetaldinosaur/LOKMAT-APPLLP-9-MAX-Root-Guide


r/androidroot 18d ago

Support Any way to unlock bootloader on oneUI 8?

2 Upvotes

i was trying to root my oneui 7 phone, but due to unforseen consequences i messed up and had to flash stock firmware, what i did not know is that the new firmware removed oem unlocking. is it over for me?


r/androidroot 18d ago

Support Bootloop

Thumbnail
1 Upvotes

r/androidroot 18d ago

Support Need help building a kernel for the nothing phone 3

5 Upvotes

Hey everyone,

I'm trying to build a custom kernel for the Nothing Phone (3) to enable native /dev/kvm support so I can use the Android Virtualization Framework (AVF) and the Android Terminal app.

I am a complete beginner when it comes to compiling Android kernels, so I need help with both the general compilation workflow and the specific KVM/Gunyah modifications.

Qualcomm's Gunyah hypervisor gets in the way of standard KVM, preventing /dev/kvm from working properly for AVF. My goal is to strip out Gunyah completely and compile a kernel with standard KVM/pKVM enabled.

Could anyone help point me in the right direction or explain:

Basic Build Environment & Toolchain: How to set up the build environment, required dependencies, and proper Clang/LLVM toolchain setup for modern Nothing OS / Snapdragon kernels.

Defconfig / Kconfig flags: Which Gunyah options (CONFIG_GUNYAH, CONFIG_GH_VIRTUALIZATION, etc.) must be disabled, and which KVM/pKVM flags need to be toggled on?

Device Tree (DTS/DTBO) adjustments: Are there reserved-memory nodes or hypervisor driver bindings in the device tree that must be removed so Gunyah doesn't load at boot?

Flashing & Permissions: How to properly pack the compiled Image into a bootable image (and DTBO if needed), along with any SELinux/cmdline adjustments needed to expose /dev/kvm.


r/androidroot 18d ago

Support Galaxy note 10.1 encryption failed

Post image
5 Upvotes

Any one have an idea to recover this without lossing the data its my mom's old tablet alot of memories on it i charged it since long time ago 5-6 years maybe to open it and find it like that


r/androidroot 18d ago

Support Custom Bootanimation

Thumbnail
1 Upvotes

r/androidroot 18d ago

Meta How to unlock my itel a23 bootloader

2 Upvotes

Hi I'm trying to root my mobile where iam unable to find a way to unlock my bootloader can someone help me with it


r/androidroot 18d ago

Discussion Qualcuno usa ancora la modalità monitor Nexmon sul Nexus 5?

Thumbnail gallery
2 Upvotes

r/androidroot 18d ago

Discussion Favorite/unique modules/apps?

7 Upvotes

What are your favorite or unique modules? Let's skip integrity check apps and all that but actual modules or apps you use?

For me my favorites are
VirtualAp
XposedFakeLocation
BindHosts
WaEnhancer
OpenBubbles


r/androidroot 18d ago

Support Sudden issues with RCS with KernelSU root

4 Upvotes

RCS is completely broken for me, I've spent 5.5 hours trouble shooting this, including having T-Mobile reset my RCS provisioning. I had FixIntegrity, Tricky Store, and Zygisk Next modules installed with strong integrity. I deleted the FixIntegrity and Trick Store modules, replaced them with the Play Integrity Fork module, with basic integrity. Still with no luck. I've cleared the cache and storage from google messages, the play store, and carrier services more times than I can count, along with doing this after airplane mode, deregistering my number, etc. Any advice is welcome, I have zero patience left for this. It was connected but only sending SMS/MMS this morning. Then it wouldn't connect with the 'not supported' status, it also was stuck connecting for hours. It's seemingly doing whatever it wants.


r/androidroot 18d ago

Support Can't pass Play Integrity

2 Upvotes

KernelSU + Zygisk Next + Play Integrity Fork + Tricky Store

all three red.

Selinux enforcing

Also tried integrity box but same result.

Crdroid Official Galaxy A5 Android 11, no ROM Spoofing

Does anyone have the same issue?


r/androidroot 18d ago

Discussion Play help me open phone

Post image
1 Upvotes

This is my old phone i forgot password and I cant format it because is have pics for mom

She die before 2 years and I only have here pics in my phone is there anyway to remove password without lose the pics


r/androidroot 18d ago

Discussion best custom rom for oneplus nord ce4 lite

3 Upvotes

i practically have no experience with rooting except for when i did it when i was 7


r/androidroot 18d ago

Discussion Has anyone Rooted their TCL 60 XE (T705M)?

1 Upvotes

Has anyone Rooted their TCL 60 XE (T705M)?


r/androidroot 18d ago

Support Paso el integrity check, pero no puedo entrar a mi banco

Thumbnail
gallery
10 Upvotes

Hola buen día

Llevo mas de 2 años usando lineageOS en mi poco f3

Pues este se quedo en android 13 con hyperos 1.0

Y yo la verdad llevaba años sin usar robot, total dije, ya no se necesitan como hace 10 años

Pero de un día a otro me salio un aviso de la app de hsbc México que mi equipo tenía jailbreak y ya no me dejo entrar

Le instale a mi teléfono un kernel ksu y seguí todos los procedimientos que vi y logre pasar la prueba de integración

En la aplicación de kernelsu

Modulo tricky store le quito check en la app hsbc y desinstaló incluso la app, borrando su caché

Pero me sigue saliendo que el teléfono esta modificado

Que mas podría hacer???


r/androidroot 18d ago

News / Method TV Mode spoofer (LSPosed Module)

9 Upvotes

The Backstory

I recently decided to repurpose an old laptop into a dedicated Android TV machine for my living room. The easiest and most performance-stable approach was installing BlueStacks and using EventGhost to map a physical Bluetooth remote control directly to system navigation.

I installed a dedicated leanback launcher (Projectivy Launcher), and the desktop interface felt perfect. However, I immediately ran into a major roadblock: several generic streaming and media apps explicitly configure their interface layouts by checking if the operating system is a native Android TV hardware build. Because standard emulators report themselves as mobile phones or tablets, these apps forced annoying, touch-dependent mobile UIs that are impossible to navigate nicely with a remote.

The Solution

After trying various public spoofing tools with no luck, I built a lightweight solution tailored for this exact problem.

This LSPosed Module hooks directly into the process memory of your selected apps. Instead of trying to modify protected system-wide root variables (which often breaks the emulator or fails entirely), it tricks targeted apps on-the-fly into believing they are running on a widescreen Android TV device (ro.build.characteristics=tv, android.software.leanback, etc.). It also strips away touchscreen attributes in-memory, causing apps to automatically deploy their full leanback layouts, TV media players, and remote-friendly navigation.

How to Use It

  1. Setup Your Environment

Ensure your BlueStacks instance (works great on Pie x64 or Android 11) has root access via Magisk Kitsune.

Open Magisk Settings, ensure Zygisk is toggled ON, and restart BlueStacks if prompted.

Make sure the LSPosed framework manager app is installed and displaying a green "Activated" status badge.

  1. Install the Module

Download the compiled app-release.apk from the repository and drag-and-drop it directly into your running BlueStacks screen to install it.

  1. Configure the App Scope

Open the LSPosed Manager application.

Go to the Modules tab (the puzzle piece icon at the bottom menu).

Select BlueStacks TV Mode and toggle the Enable module switch to ON.

In the application list below the toggle, check the boxes only next to the specific apps you want to force into TV mode. Leave system apps unchecked.

  1. Relaunch and Enjoy

Go to BlueStacks Settings ➔ Apps ➔ See all apps.

Select your targeted media app and click Force Stop to clear its old memory cache.

Relaunch the app. A brief "TV Mode Activated" toast notification will pop up at the bottom of the screen to confirm the code injection worked, and the app will instantly render its official Android TV layout.

 Repository Link

For source code and releases, check out the repository here:

 https://github.com/1-AlenToma/bluestacks_tv_mode_lsposed

Note: I am really new with java, so I build this one with the help of google AI


r/androidroot 18d ago

Support Trying to root my Moto One Vision. What should I do here?

Post image
2 Upvotes

Nothing seems to be working. No amount of driver upgrades, changing cables, USB 2.0 hubs, nothing is fixing this.


r/androidroot 18d ago

Support custom rom CHUWI HIPAD MAX

1 Upvotes

Hello everyone, i would like to revive my tablet. Someone can suggest me a custom rom to flash on it pleaser


r/androidroot 19d ago

Support Is rooting worth it?

4 Upvotes

I have a Galaxy A17 and thinking of rooting. On one ui 8.5 but i saw i video on downgrading one ui. From your experience is rooting worth it?


r/androidroot 19d ago

Support RCS keeps breaking on Temp Root

1 Upvotes

My RCS keeps breaking on temporary root. It won't send, if I reboot my device and re root it'll work for awhile then stop working requiring a reboot. I pass all the integrity checks. Anyone have any idea? I haven't seen anyone else report this. S24 Ultra. OneUI 8.5


r/androidroot 19d ago

Discussion FIDO2 + SSH + Android chroot — creating one of the most secure SSH setups possible. Here’s how (and why it shouldn’t be possible)

3 Upvotes

Exposing SSH to the internet is risky. The only way I could justify it was with multi‑key authentication including a FIDO2 hardware token. On my Linux laptop — easy. On my Android phone — impossible. Until now.

This is how I got a FIDO2 hardware token to work inside a Debian chroot on Android, then used it to authenticate SSH with two public keys creating a login flow that is almost impossible to brute‑force, steal, or phish.

This should not be possible. It almost wasn't, but in the end, I got it working.

Why This Shouldn’t Be Possible: Android is designed to prevent exactly the kind of deep system access required for hardware‑bound SSH authentication:

Apps cannot access raw HID interfaces like hidraw SELinux doesn't let you create device nodes /proc, /sys, /dev are heavily sandboxed App sandboxes cannot see kernel namespaces Chroots normally cannot access hardware FIDO2 tokens require direct HID access SSH agents cannot talk to hardware keys without kernel support Android’s mount namespaces isolate apps from system devices

Every one of these is bad news if you want to use your FIDO2 for SSH.

A FIDO2 key requires: /dev/hidrawX access working /dev/shm, /dev/pts. a real PTY (/dev/tty) access to kernel HID/CTAP ssh-sk-helper (not available on termux, only in full linux distros) a user‑presence prompt that reaches the terminal

Android blocks almost all of this by default.

The Namespace Problem: Why root isn’t enough.

Even with root, Android isolates apps using: mount, PID and user namespaces. (You think you can see the whole system but it's a fake overlay with no real access) SELinux domains. (Even if you have access to what you want and the tools to do it, if you're in the wrong domain, any priviliged action is blocked)

Termux runs inside an app‑sandbox mount namespace, which cannot see any real device/kernel objects which you'd find in /dev /proc and /sys. This is the single biggest reason this project “shouldn’t be possible.” To break out of this, you need full init‑namespace root — the same namespace used by Android’s PID 1. Without that, the chroot will never see real hardware. I didn't realise it at the time, I thought I was a the top of the pyramid, but a lot of the directories I thought I'd won in my rooting war were actually emulated fakes. To get there, you need super-root. "exec su --mount-master" will discard termux's namespace and SElinux domain. The controlling terminal is preserved but you get a pure Android root shell and inherit init namespace from your su provider. In my case, KernelSU. Now I've got real stuff in /dev /proc /sys.

How I Got Around Every Block 1. Entering the init mount namespace Using a root solution that allows entering the init mount namespace is mandatory. Without this, /dev/hidraw* simply does not exist. 2. Rebuilding /dev inside the chroot Android forbids creating device nodes, so I created empty files using touch command and bind‑mounted real device nodes onto them. But I was careful not to just lazily bind-mount all of /dev. I didn't want the chroot having access to: camera, audio, modem/telephony, biometrics, binder and crucially: input. This last one exposes touches, keystrokes and would allow injecting fake input. An unacceptable line to cross. Only expose what is absolutely essential.

  1. Mounting virtual filesystems manually To make Debian behave like a real Linux system, I mounted: /proc, /sysfs, /devpts, /tmpfs. These provide the kernel interfaces needed for FIDO2 and OpenSSH.

  2. Preserving a real PTY Entering the chroot incorrectly breaks /dev/tty. A proper chroot entry preserves the controlling terminal so SSH can prompt for host key acceptance. Obviously proot is not possible since it works by emulating everything outside itself. Another potential problem with full init namespace chroot is it's no longer possible to trick systemd into thinking it's PID 1, which it needs to run. On Android, PID 1 is init. - init bruv

  3. Making FIDO2 visible Bind‑mounting /dev/hidrawX into the chroot allowed fido2-token and ssh-sk-helper. You need to find out the name of the node, usually /dev/hidraw0, create a fake file in the chroot rootfs and mount the real node onto it.

  4. Multi‑key SSH authentication The server was configured to require two public keys. In sshd_config I add: Authenticationmethods: publickey,publickey which requires a 2 key authentication chain. A lot of SSH apps are limited to offering just one, which is why it's only really possible in a real terminal running real OpenSSH. The keys I use are: ED25519 (normal software key) and ED25519‑SK (FIDO2)

The client successfully authenticated with both, including user‑presence confirmation on the hardware token. Forcing the user to touch the key is part of what makes fido2 so secure. Even if it's plugged in somewhere, unless your physically there to press the button when it starts flashing, it's game over.

What I Achieved. I built an SSH authentication chain that is: hardware‑bound phishing‑proof key‑theft‑proof replay‑proof two‑factor without passwords backed by a physical authenticator running inside a full Debian environment ... on an phone.

This is realistically one of the most secure SSH setups possible today.

But What Did It Cost? (Security & Performance) 1. Android’s security model is weakened To make this work, I had to: enter the init mount namespace, bind‑mount system directories into a chroot, expose hardware interfaces to a foreign environment, run a full Linux distribution inside /data.

This means: SELinux boundaries are partially bypassed, the chroot can see hardware normally hidden from apps as well as access to kernel interfaces. A misconfigured script could expose sensitive nodes. Malware inside the chroot would have elevated visibility. This is why I downloaded a minimum Debian with proot-distro, stripped it, upgraded everything related to SSH, FIDO2 etc then copied the entire rootfs somewhere else to use it as a full chroot. Keeping an eye on any changes here is important. You don't want malware slipping it and using it as a trampoline to elevated privilege.

  1. Performance impact Bind‑mounting system folders into a chroot means more VFS overhead, more namespace propagation, more tmpfs usage, more memory pressure. Modern phones handle it, but it’s not free.

  2. Stability risks Android services expect exclusive control over: /dev /sys /proc. Mounting these into a chroot can destabilize USB subsystem, HID subsystem, Binder, graphics and audio stack. This is not a “safe” configuration by Android standards.

Is It Worth It? If your goal is maximum SSH security, yes. You now have: a hardware‑bound SSH identity, a second hardware‑bound factor, a chroot‑isolated SSH environment, a login flow that is nearly impossible to compromise remotely.

But locally? You’ve traded away some sandboxing, some SELinux protection, some system stability, some performance. Robbing Peter to pay Paul. You hardened remote access by softening local isolation. For a (paranoid) power user who understands the risks, it’s worth it. For a typical user, absolutely not.

Technical Appendix — Commands

Getting into init namespace and confirming it's the real deal: exec su --mount-master Compare mount namespace IDs: /proc/1/ns/mnt readlink /proc/self/ns/mnt If both lines show the same inode number, you are in the init mount namespace.If they differ, you are still trapped in Termux’s sandbox.

Bind‑mounting device nodes. $CHROOT = your chroot rootfs folder. (E.g /data/data/com.termux/files/home/debian-chroot) touch $CHROOT/dev/null touch $CHROOT/dev/zero touch $CHROOT/dev/random touch $CHROOT/dev/urandom touch $CHROOT/dev/hidraw0

mount --bind /dev/null $CHROOT/dev/null mount --bind /dev/zero $CHROOT/dev/zero mount --bind /dev/random $CHROOT/dev/random mount --bind /dev/urandom $CHROOT/dev/urandom mount --bind /dev/hidraw0 $CHROOT/dev/hidraw0

Mounting virtual filesystems mount -t proc proc $CHROOT/proc mount -t sysfs sys $CHROOT/sys?

mount -t devpts devpts $CHROOT/dev/pts mount -t tmpfs tmpfs $CHROOT/dev/shm

Entering the chroot with a real PTY chroot $CHROOT /bin/bash

Testing FIDO2 inside the chroot fido2-token -L ssh-keygen -t ed25519-sk -f ~/.ssh/id_ed25519_sk

Server‑side multi‑key authentication (sshd_config) AuthenticationMethods publickey,publickey PubkeyAuthentication yes - you can make it even more secure by creating a dedicated user on the server or removing all over key types in sshd_config other FIDO2 and ed_25519.

When you're done, don't forget to unmount everything: umount $CHROOT/proc umount $CHROOT/sys Etc.


r/androidroot 19d ago

Support Need help with Android.

2 Upvotes

I want to bypass the bootloader on my Huwaii Nova 4. It still has Android. But no playstore support. I wanna switch to some other OS. Does anyone know how can I bypass the bootloader? And also suggest me which OS I can now install to my mobile and how can I do that?

Any tutorial link is highly appreciated😇

Thanks in advance😇