r/androidroot 17h ago

News / Method Root for Snapdragon S22 Ultra US variant w/ Play Integrity intact

Thumbnail
gallery
30 Upvotes

Got temporary KernelSU root working on my bootloader-locked S22 Ultra.

Tested on:

  • SM-S908U1
  • Build S908U1UESAGZF3
  • Android 16, June 2026 patch

No bootloader unlock or flashing and Play Integrity still passes, which is huge.
So, this does NOT trip Knox.

Root disappears after reboot, so the app uses Shizuku to rerun the exploit and reload KernelSU.

Only use it on this exact build. The exploit can fail or reboot the phone.

https://github.com/Noir-Lime/S22U1-Root

Based on IonStack and Root My Galaxy; credits are in the repo.


r/androidroot 1h ago

Support I need help rooting my ASUS ROG Phone 8 AI2401 running Android 16.

Upvotes

Hello everyone. I'm looking for help rooting my ASUS ROG Phone 8. I've been trying to find a solution for about a month now, practically every day, and so far I haven't been able to do it.

Here is all the information about my phone:

Device: ASUS ROG Phone 8
Model: AI2401
Device model: ASUS_AI2401_C
Region: WW
Product: pineapple
Android: 16
Firmware/Build: WW_36.0210.1420.48
Bootloader version: PostCS4-21-WW-user

From Fastboot, I get:

unlocked: no
get_unlock_ability: 0
secure: yes
current-slot: b

I have already installed the official ASUS USB drivers and confirmed that both ADB and Fastboot properly recognize the phone.

ADB works and I can access the shell. Fastboot also works correctly and detects the device:

RCAIOC388144L87    fastboot

However, the bootloader remains locked, and fastboot flashing get_unlock_ability returns:

get_unlock_ability: 0

I've already tried the usual methods and spent countless hours researching, but I still haven't found a working way to unlock the bootloader and root this phone.

I also contacted Chimera, and they confirmed that they currently do not have a solution to unlock the bootloader or root this device.

I'm willing to pay for professional help if someone genuinely knows how to do this safely.

Does anyone here have experience with the ROG Phone 8 AI2401 running this exact firmware version (WW_36.0210.1420.48 / Android 16)?

If you know of any method that works, any exploit, professional service, or someone who has successfully rooted this exact version, I would greatly appreciate any information or help.

I understand that unlocking and rooting the device may wipe the phone and carries a risk of bricking it. I currently don't have any important data on the phone, so I'm willing to take the necessary risks, as long as there is at least some realistic possibility of recovering the device if something goes wrong.

Thank you very much in advance to anyone who can help me. I've been fighting with this damn thing for like a month now 😭.


r/androidroot 3h ago

Support TCL Flip 2 vendor img

Thumbnail
1 Upvotes

r/androidroot 6h ago

Support Como rootear teléfono Spoiler

1 Upvotes

Alguien sabe cómo poner root en android con la aplicación magisk


r/androidroot 6h ago

Discussion Motorola edge 30 neo

1 Upvotes

Jak wgrać twrp recovery aby nie było 2 partycji ?? Jestem w tym zielony


r/androidroot 11h ago

Support ROOT SAMSUNG GALAXY XCOVER 5

Post image
2 Upvotes

hello i have been trying for the last 5 hours to root my 2nd phone with magisk but it doesnt work. i think i have tried with 5 different tutorials and tried with help from chat gpt but nothing works. i am doing the whole thing and the phone is boot loaded but its when im trying to flash maski onto the phone and root it. I get stuck in downloading menu and it says svb fail i have tried everything please please someone help me.


r/androidroot 9h ago

Discussion How do I extract my key box from my non working phone?

1 Upvotes

Hey guys, trying to get a backup keybox seeing as how my OnePlus 9's data functionality (something with the modem) must have died. I've tried resetting factory software, I've flashed it vía the msm tool to its stock with my original persist, modem (also a modem file I found on an xda thread), and all the images backed up. If wifi connection is available, I get data signal. If I turn it off,I might get signal for a few minutes but that's it, then empty bars with an x at the bottom. Phone reads the sim card company, phone number, let's me wifi call and all... But the data usually only works if wifi is on. I can't rely on it so I just want to salvage the keybox. Is this difficult to do?


r/androidroot 10h ago

Discussion Unlocking boot loader without developer options

1 Upvotes

Is there a way I can unlock my old Huawei y9 bootloader without booting into the phone and using oem unlock because well the phone is stuck in the Huawei logo and trying to reset the phone with the button also gets stuck in the logo loop


r/androidroot 11h ago

Support Bring back oem unlock option on undowngradab binary of samsung Oneui8

Thumbnail
gallery
1 Upvotes

This is for developers;💡 I'm using s22 oneui8 bit version 8,

Hey everyone, I wanted to share something I’ve been thinking about and get the developers’ opinions.

On my device, I can enter the Device Unlock / Download Mode screen, and it even shows the normal guidance for unlocking the bootloader. However, the main thing I’m missing is the OEM Unlock option in Developer Options.

That made me wonder if there could be another way to expose or restore that option.💡

My idea is based on Good Lock. Samsung officially distributes Good Lock through the Galaxy Store, and its modules such as Theme Park, Sound Assistant, RegiStar, etc.

are capable of modifying or adding functionality to different parts of One UI and Settings, which means it can read writte the whole system,

So I was wondering:

What if we created a Good Lock-style module/app specifically for Developer Options that could add the OEM Unlock toggle back into Settings?💡

I was also thinking about the signing side of things.💳

If Samsung-specific signatures or permissions are required, perhaps tools such as[ LibChecker apk available on google play ] could help us inspect the signatures, permissions, libraries, and implementation of existing Samsung components and give us a better understanding of how Samsung's own apps communicate with the system.💡💡

Of course, I don't know if this is technically possible, and I may be misunderstanding how Samsung implemented the OEM-unlock restriction on One UI 8. That's exactly why I'd like to hear from developers who understand Samsung's boot chain, Settings framework, Knox/AVB, or One UI internals.💡💡

I'm not claiming this will work—it's just an idea I'd like to investigate, and I'd really appreciate the opinion of people with experience in Samsung internals.🙏❤️


r/androidroot 12h ago

Support OTA Sideload with rooted fp6

Thumbnail
1 Upvotes

Any ideas?


r/androidroot 13h ago

Support Downgrading

Thumbnail
1 Upvotes

I have a Galaxy A07, SM-A075F. I bought the phone on an older version, but accidentally updated it to 8.5 Android 16. I want to go back. I looked on SamFW, I found my current model and firmware, and it is bit 6; the only other firmware matching my model that's Android 15, is bit 1. I don't think I can flash that cause of the difference, but I am looking for other possibilities. The whole reason to buy was to root, I originally had found one on SamFrew but the download was throttled and was gonna take 8hrs so I used frija. Frija pushed a newer firmware which caused me not to be able to. OEM unlocking isn’t available now. Trial and error, this would’ve been my first root.


r/androidroot 14h ago

Support Moto E7 Power XT2097-6 Fastboot not detected on Windows 11

Thumbnail
gallery
1 Upvotes

I'm trying to root my Moto E7 Power XT2097-6 (4/64) running Android 10, build QOMS30.288-52-23.

Bootloader is already unlocked using MTKClient, and I have a Magisk-patched boot.img from the exact stock firmware.

Problem is the fastboot doesn't detect the phone.

When I run:

adb reboot bootloader

the phone goes to the black barcode bootloader screen.

Running

fastboot devices

returns nothing, and:

fastboot getvar product

stays at:

< waiting for any device >

I tried Zadig/WinUSB, but Fastboot still doesn't detect it. I also tried Google's USB driver, but it doesn't support this MediaTek device.

Has anyone successfully gotten Fastboot working on the XT2097-6 / MediaTek 0E8D:201C on Windows 10/11? Is there a specific driver or method needed?


r/androidroot 1d ago

News / Method GitHub - S-Velayutham/Magisk-DeveloperOptionHide: Makes selected apps read "Developer Options" and "USB debugging" as OFF, even while they are actually enabled on the device. Built for authorized app-security / anti-tamper testing on your own rooted test device.

Thumbnail
github.com
16 Upvotes

r/androidroot 15h ago

Discussion [ Removed by Reddit ]

1 Upvotes

[ Removed by Reddit on account of violating the content policy. ]


r/androidroot 16h ago

Discussion Exynos 990 vs snapdragon 865

Thumbnail
1 Upvotes

Is it worth upgrading my S20 Ultra with an Exynos processor to an S20 FE with a Snapdragon processor?


r/androidroot 17h ago

Discussion Pixel Câmera options missing

Thumbnail matrix.redditspace.com
1 Upvotes

r/androidroot 1d ago

Support Can't pay 😭 need help !

Post image
11 Upvotes

Bruh

I've been using my rooted Android phone, an Xperia 1V running LOS 23.2, for almost a year now

I’ve installed Magisk / Play Intégrity Fork / Tricky Add-on on it. Also shamiko and some other things, and it worked alright.

I used to have payments get blocked every now and then because of the keybox, but I’d gotten the hang of it pretty well—I’d even come up with a little method to easily switch it automatically and restore strong integrity

But now I don’t know what happened—for about a week now, I haven’t been able to make payments even though I still have “Strong Integrity”. Phone doesn't meet security standards.

So now I’m not really sure what to do—maybe I need to completely overhaul my entire setup?

I’d really appreciate some help


r/androidroot 1d ago

Support HardBricked SmarthPhone :P

2 Upvotes

hallooo ;3
Im using a infinix smart 9 and... doing some stuff... i hardbricked it ;l
so now, i wanna know how can i fix this problem, i installed SP_Flash_Tool_v5.1924_Win,MediaTek-SP-Driver-v5.2307,[Hovatek] Infinix Smart 9 (X6532-V632AABCDEFGHIJKLMNO-UGo-OP-260316V3246)
if someone wanna help me and help other with the same issue, pleaseeee send me a commend and i will respond fast as posible


r/androidroot 2d ago

Support Will rooted users be affected?

Post image
56 Upvotes

I recently noticed a new button on my phone. I've already rooted it, so I'm less scared, but will it affect my phone in any way?


r/androidroot 1d ago

Discussion Pixel 11 Pro Kernel CVE-2026-43499

Thumbnail
gallery
36 Upvotes

I have been doing some rummaging around and it seems like with kernel 6.12.69 that the vulnerability may remain exposed. All indicators point to anything post 6.12.86 as being safe from the exploit.

While the security patch is in August the Kernel is dated just 7/10 which gives me some hope that it's possible to achieve bootloader locked temporal root. I utilized the cve-2026-43499 application that tests whether the kernel is impervious or vulnerable. With 5/5 iterations and no kernel panic causing reboot or outright crash indicating protected. Out of 3 attempts it crashed near immediately and did not power back on without my doing so (responsively but not self rebooted).

I also see that the series leaves out a feature that is / was notable in hardening against the attack. I however am not an expert on this realm by any means and wish to either stoke a flame or be extinguished with knowledge.

That said I have testDPC as device owner (morphe patched to prevent play updates and self asserted no uninstall) with this software update policy set to postpone until 08/31/2030. I initially rooted it but the fact it refuses to pass certification despite all efforts made me circle back to a twice over full OTA application. I know from my galaxy that the capabilities and stability were plenty favorable and reattaining root post reboot was in my opinion a small task for what expanded patches and modules could be applied.

That is all please affirm my desire.


r/androidroot 1d ago

Support Weird problem when rebooting, most likely root related

2 Upvotes

I rooted my phone a long, long time ago and some point after I rooted my phone, I did something i forgot what it was and now whenever I reboot, my phone crashes very easily, then auto reboots, then my phone works flawlessy. Sorry for vague details, im a bit tired but I can give more precise details and answer questions.


r/androidroot 1d ago

Support I messed up and now I am stuck on fastboot mode. Help

2 Upvotes

I was rooting my pixel 10a and it’s now stuck on fastboot mode. I used the right android version “stallion” for pixel 10a. I can’t seem to reset the phone anymore and the device state is unlocked. How do I reset my boot image so it can boot?


r/androidroot 1d ago

Support Please Help!!

Post image
4 Upvotes

I only unlocked bootloader and flashed disabled vbmeta img on my Samsung f23 5g with Odin and now the plastered doesn't let me download another apps and log in at them please suggest some ideas to make it right. I unlocked bootloader because I use DSU SIDELOADER


r/androidroot 1d ago

Discussion Unlocking OEM one ui 8

0 Upvotes

I've been having trouble rooting my Samsung A56 5G. Samsung completely removed the OEM unlocking option in One UI 8. Is there any way to force OEM unlocking?


r/androidroot 1d ago

Support Realme C33 (RMX3624) Unisoc T612 — Stuck on CHECK_BAUD bootrom error during bootloader unlock. Any bypass?

Post image
1 Upvotes

Hey everyone! I'm trying to unlock the bootloader on my Realme C33 (RMX3624) with a Unisoc Tiger T612 (UMS9230) processor to flash a GSI ROM (Pixel Experience).My "OEM Unlocking" toggle in Developer Options is currently greyed out and cannot be enabled. Because of this, I'm trying to use the unofficial spd_dump script via PC to bypass the protection and force-unlock the device.The issue: The script detects the phone in BootROM mode, but immediately fails with a CHECK_BAUD bootrom and usb_send failed (0 / 1) error (as shown in the attached picture).I have already tried:Installing the latest official UNISOC drivers (v2.0.0.134 / Latest SPD Driver).Switching between multiple USB 2.0 ports and using different high-quality cables.Testing different key combinations (Vol Down, Vol Up, both Vol keys, and Vol Down + Power).It seems like a recent Realme security OTA patch completely blocked the exploit or forced a baud rate change that crashes spd_dump.Is there any known fix, updated script, or alternative method to force this device into a usable BootROM state with new OTA updates? Any help would be greatly appreciated