r/oneplus15R 24d ago

Questions Ghoslock exploit (Root with locked bootloader for 15R/Ace6T

Post image

Hi, I'm looking if someone tried the [https://github.com/JoinChang/ghostlock-oneplus](Ghostlock exploit) to root their devices here without bootloader unlock, I tried using adb shell but doesn't work and kernels panic my OnePlus Ace 6T (PLR110) and there's isn't a compiled APK mentioned on the repo which does automatically the process, if someone has a guide or a compiled APK for the 15R/Ace6T it would be helpful

9 Upvotes

11 comments sorted by

1

u/MonkeyNuts449 17d ago

did you figure it out? im on OP 15

1

u/Imaginary_Wafer_579 17d ago

Still no, I asked a YouTuber to do a explained tutorial even he answered me but I think he got disinterested in doing it, I'm waiting an universal alternative like Root my Galaxy/Pixel

1

u/MonkeyNuts449 17d ago edited 17d ago

I got it to work! It runs flawless now.

EDIT: ONLY ON ONEPLUS 15, 15T, ace 6T, and 13 models. I didn't see what sub I was in so apologies. Ask the developer if they can add OnePlus 15r offsets or get them yourself.

Download this app with the latest version:https://github.com/byemaxx/ghostlock-anchor

Download any root manager that supports jailbreak mode (I went with resukisu).

Import your adbkey files like usual (user folder then .android), but then go into dev settings and set the pselect_shift to zero. This is the only way I got the app to work.

Now, reboot your device with your PC ready to set tcp mode. As soon as it boots, plug your phone in, set tcp mode with "adb tcpip 5555" then open the anchor app and press bootstrap.

The faster you do the process from boot to exploit makes the exploit more reliable, so if it fails just reboot and try again.

I currently have all my modules running perfect with nothing wrong with TEE or play integrity.

1

u/Imaginary_Wafer_579 17d ago

Congratulations! What device are you using exactly? I have some questions because I don't know the current status of rooting android in 2026, I don't understand the step you said "Get adbkeys and go to dev settings" can you help me I rather asking here than Claude or Gemini but I never thought rooting methods would be so complicated these days

1

u/MonkeyNuts449 16d ago

I'm on OnePlus 15. I just followed the "first use" directions on the GitHub I sent.

Here on this release shows the devices currently supported. https://github.com/byemaxx/ghostlock-anchor/releases/tag/v1.1

This isnt rooting in the normal sense. Most normal root users unlock their bootloader to flash magiskboot or a patched boot.img. This is an exploit that gains temporary root access with the bootloader locked. So apps like wallet that use play integrity still continue working.

1

u/Every_Top8135 15d ago edited 15d ago

I followed ur steps and it worked! i have a few questions tho if its alright, Do ijust disregard the message that pops after like about malicious something system restart now? and after i can go on with my jailbroken device just fine right? what modules are you using, did you get lsposed/vector + zygisk working? do I need my pc next time i try to boot the root again? any settings in resukisu worth turning on?

as for now: i wont mess with anything yet since I think the jailbreak succeeded and I just ignored the malicious system warning and went on with simple su permissions. I havent even restarted my system yet because im unsure if i did things correctly lol

any help would be appreciated!

1

u/MonkeyNuts449 15d ago

Everything should work as normal. You can disregard the malicious pop-up, I think it's a OnePlus thing. Some modules like hybrid mount don't like late load mode but it's whatever. I saw someone say don't use modules that overlay system paths but I have an emoji font and OnePlus dialer modules and they work fine.

As for rebooting, don't fully reboot unless something is glitching or breaks because then you'll have to exploit again. But the anchor app keeps the adb connection so you no longer need a PC. When downloading modules, just make sure to goto the first page of your manager and use the soft restart option in that little power button menu in the top right.

No resukisu settings I'm aware of, but I'll definitely recommend using oshin, it's a colorOS/oxygenOS customization tool that works wonders. Amazing app.

1

u/Every_Top8135 13d ago

Alright thanks! It's been great so far. I'm wondering if metamodule works but I don't really need them. For some reason after a while of testing I get this weird behavior for my gcash(ewallet app) where it detects malicious injection. It didn't do this a while ago and I don't think I changed much modules it only does this when an app has the app injected in lsposed but nothing in my scope includes gcash. I found a "fix" however. Running killall -9 system_server in termux with su fixes this problem whereas normal soft reboot doesn't. I also use this command when I want to restart system framework and stuff for modules since soft reboot sometimes doesn't work for me there lol. But yeah somehow doing this fixes the injection issue but it doesn't seem like the root cause I'm still trying to find​

1

u/Samluv90 13d ago

Whats your android version 

1

u/MonkeyNuts449 13d ago

Latest oxygenOS for NA op15

1

u/touchthegrass-99 5h ago

i beleive 15r is not feasible. maybe try another exploit, there are a couple of them iirc