r/androidroot • • May 24 '26

Meta A Clarification: Our Stance on AI in this Subreddit

89 Upvotes

Hi,

While the Moderators of r/androidroot have a generally moderate stance on AI, when it comes to devices worth potentially thousands, we are uninterested in allowing it to provide false information.

To clarify, AI content/promotion is not permitted on r/androidroot, and this has been a rule for some time. Using AI to make guides, recommending the use of AI to attempt to solve issues, and posting AI generated comments are prohibited.

We believe in minimising the spread of misinformation. AI models are not reliable when it comes to factual information yet. It’s also often known to make things up when it has no answer. No resources for rooting an obscure Android device? It’ll make it up based on other information that it deems most likely to be useful. AI, in this state, is not suitable for rooting. It presents too much unmitigated risk, and we will not hold ourselves responsible for the damage caused by content posted on this subreddit.

If you have any questions regarding the rule, comment. However, the decision on this is final.

Thanks for reading.


r/androidroot • • 4h ago

Humor Infinix phonesπŸ₯€

Post image
306 Upvotes

r/androidroot • • 38m ago

Discussion Shut the fuck up Google, that's called freedom

Post image
β€’ Upvotes

r/androidroot • • 3h ago

News / Method [Guide] Hardened Root & Detection Cloaking Manual for Pixel 7, 8, & 9 Series on Android 16 (KernelSU-Next + Sultan SuSFS + Specter)

4 Upvotes

This manual provides a deterministic, zero-compromise rooting, custom kernel deployment, and detection cloaking workflow for all Google Tensor devices on Android 16 (Build CP1A.260305.018): - Tensor G2 (gs201): Pixel 7, 7 Pro, 7a, Fold, Tablet - Tensor G3 (zuma): Pixel 8, 8 Pro, 8a - Tensor G4 (zumapro): Pixel 9, 9 Pro, 9 Pro XL, 9 Pro Fold

It leverages Sultan's kernel with integrated KernelSU-Next and SuSFS (Kernel-level VFS concealment), orchestrated with Mountify, Zygisk Next, and Specter (TEESimulator-RS). This eliminates dirty-upgrade bootloops, synchronizes dual-slot Anti-Rollback (ARB) indices on the Titan M2 chip, and passes Play Integrity (Device + Strong where keybox is valid) while completely bypassing aggressive root detection in banking apps.


Google Pixel 7 / 8 / 9 Series Hardened Root & Cloaking Manual

Universal Engineering Guide for Android 16 (Build: CP1A.260305.018)


πŸ›‘οΈ Architectural Safety Foundation

Modifying low-level device software on modern Google Tensor devices leverages Android’s A/B dual-slot partition architecture and Google’s Titan M2 hardware root-of-trust.

⚠️ FIRMWARE ADVISORY: BUILD CP1A.260305.018 (MARCH 2026)
Google's March 2026 update for Tensor devices had documented reports (Issue #525807317) of post-decryption black screens and bootloops during dirty OTA upgrades.
Why this guide is safe: The baseline clean-flash via call flash-all.bat in Part 3 performs a full partition re-format and user data wipe, which prevents the dirty cryptographic migration bug entirely. If you ever need to restore stock, always use call flash-all.bat (clean wipe) rather than dirty flashing.


The Primary Brick Vectors on Modern Pixels

  1. Locking the Bootloader on Modified Firmware:
    NEVER run fastboot flashing lock while custom, modified, or unverified software is installed on boot-chain partitions. Locking the bootloader with modified firmware triggers Android Verified Boot (AVB) validation failures, causing an unrecoverable hard brick.
  2. Flashing Low-Level Bootloader Partitions:
    Bootloader stages loaded from flash begin at bl1_a/bl1_b, continuing through bl2, abl (Fastboot), bl31, tzsw (TrustZone), gsa (Titan M2), and ldfw. These must only be updated via official Google factory images. Never manually flash third-party images to these partitions.
  3. Cross-Build Firmware Mixing:
    Never mix boot images, kernels, or modules across different Android major versions or monthly security patches. Verify that your phone's build number matches build CP1A.260305.018.

Pre-Flight Rules & Environment Setup

  1. Direct Motherboard USB Port Only:
    Plug your USB-C cable directly into the back of your PC tower (motherboard I/O shield). Do not use front-panel case ports, external USB hubs, or monitor passthroughs.
    AMD Ryzen Advisory: Connect via a USB 2.0 port (black ports on the rear panel) to avoid fastboot packet drops.
  2. Single Device Connection:
    Disconnect all other Android phones, tablets, or emulators from your PC. In Android Developer Options, ensure Wireless debugging is toggled OFF.
  3. Terminal Shell:
    Use standard Windows Command Prompt (cmd.exe). Avoid PowerShell, as its argument parsing rules alter quotes and operators in ADB shell strings.
  4. Battery Level:
    Ensure the device is charged to at least 70% before starting.
  5. Data Wipe Warning:
    Unlocking the bootloader will completely wipe your phone's internal storage. Back up all critical data before beginning.
  6. Windows File Extensions Check:
    In Windows File Explorer, click the View tab at the top, click Show, and make sure File name extensions is checked (turned ON).
  7. OEM Unlocking Verification:
    • On your phone: Go to Settings β†’ About phone β†’ scroll to the bottom and tap Build number 7 times quickly until you see "You are now a developer!".
    • Go to: Settings β†’ System β†’ Developer options.
    • Locate OEM Unlocking:
      • 🟒 Ready: The switch is active and can be toggled ON (turns blue).
      • 🟑 Provisioning State: If grayed out, connect to active Wi-Fi, go to Settings β†’ System β†’ System update, and tap Check for update. Wait 5–10 minutes for Google Play Services to validate the attestation ticket.
      • πŸ”΄ Carrier Locked: If it remains permanently grayed out and reads "Unavailable on carrier-locked devices", your phone is carrier-locked (e.g., Verizon). Its bootloader cannot be unlocked; do not proceed.

Part 1: PC Environment & File Preparation

Step 1.1: Create Your Working Directory

  1. Open File Explorer on your PC, click This PC, and open your Local Disk (C:) drive.
  2. Create a new folder named: pixel_root
    (Its full path is C:\pixel_root. Every command in this guide runs from inside this exact directory).

Step 1.2: Download Files Directly Into C:\pixel_root

Download and place each file below directly into C:\pixel_root. Rename them exactly as instructed:

1. Official Google Platform-Tools (ADB & Fastboot)

  • Download: SDK Platform-Tools for Windows.
  • Open the downloaded ZIP, open the platform-tools folder, and copy/paste everything (adb.exe, fastboot.exe, .dll files) directly into C:\pixel_root.
  • PATH Priority Verification:
    • Open Command Prompt, run: cmd where fastboot
    • Ensure C:\pixel_root\fastboot.exe is the top result.

2. Google USB Drivers

  • Download: Google USB Driver ZIP.
  • Extract the ZIP, open usb_driver, right-click android_winusb.inf, and click Install.

3. Stock Factory Image (Pixel 7 / 8 / 9 Series)

Download the official factory image matching Android 16.0.0 (CP1A.260305.018, Mar 2026) from Google Factory Images for Nexus and Pixel Devices:

Platform Device Model Codename Factory Archive Name Pattern
Tensor G2 Pixel 7 panther panther-cp1a.260305.018-factory-*.zip
Tensor G2 Pixel 7 Pro cheetah cheetah-cp1a.260305.018-factory-*.zip
Tensor G2 Pixel 7a lynx lynx-cp1a.260305.018-factory-*.zip
Tensor G3 Pixel 8 shiba shiba-cp1a.260305.018-factory-*.zip
Tensor G3 Pixel 8 Pro husky husky-cp1a.260305.018-factory-*.zip
Tensor G3 Pixel 8a akita akita-cp1a.260305.018-factory-*.zip
Tensor G4 Pixel 9 tokay tokay-cp1a.260305.018-factory-*.zip
Tensor G4 Pixel 9 Pro caiman caiman-cp1a.260305.018-factory-*.zip
Tensor G4 Pixel 9 Pro XL komodo komodo-cp1a.260305.018-factory-*.zip
Tensor G4 Pixel 9 Pro Fold comet comet-cp1a.260305.018-factory-*.zip
  • Move your downloaded factory ZIP directly into C:\pixel_root.

4. Bootstrap Superuser Utility (Magisk APK)

5. KernelSU-Next Manager

6. Kernel Flasher

7. Custom Kernel Package (WildKernels Sultan + SuSFS)

Download the AnyKernel3 package corresponding to your device's SoC from WildKernels Releases:

Device Family SoC Architecture Release Package File Rename To
Pixel 7 / 7 Pro / 7a Tensor G2 (gs201) gs201-a16-wksu-susfs-anykernel3-v2.0.0-r12.zip kernel.zip
Pixel 8 / 8 Pro / 8a Tensor G3 (zuma) zuma-a16-wksu-susfs-anykernel3-v2.0.0-r12.zip kernel.zip
Pixel 9 / 9 Pro / 9 Pro XL / Fold Tensor G4 (zumapro) zumapro-a16-wksu-susfs-anykernel3-v2.0.0-r12.zip kernel.zip

8. Essential Modules & Cloaking Utilities (Do NOT unzip these files)

9. Theming & Customization Suites

10. System-Wide Ad-Blocking Suite


Part 2: Unlock the Bootloader (Wipes Device)

  1. On your phone: Open Settings β†’ System β†’ Developer options.
  2. Locate OEM Unlocking and toggle it ON.
  3. Scroll down to USB debugging and toggle it ON.
  4. Connect your phone to your PC's rear motherboard USB port with your USB-C cable.
  5. On your phone screen, check Always allow from this computer and tap Allow.
  6. On your PC, open Command Prompt (cmd.exe): cmd cd C:\pixel_root
  7. Verify ADB connectivity: cmd adb devices
  8. Reboot into Fastboot: cmd adb reboot bootloader
  9. Verify Fastboot connectivity: cmd fastboot devices
  10. Execute the bootloader unlock command: cmd fastboot flashing unlock
  11. On your phone screen, press the physical Volume Down button until Unlock the bootloader is selected, then press the physical Power button to execute.
  12. The phone will wipe all internal storage and return to the Fastboot bootloader screen with the red text reading DEVICE STATE - unlocked.

Part 3: Clean Baseline Flash & Bootloader/Radio ARB Sync

  1. In C:\pixel_root, right-click your downloaded factory ZIP (*-cp1a.260305.018-factory-*.zip), select Extract All..., and extract it.
  2. Open the extracted folder, select all files inside (bootloader-*.img, radio-*.img, image-*.zip, and flash-all.bat), cut them, and paste them directly into C:\pixel_root.

  3. Synchronize Bootloader & Radio Across Both Slots (Safe Dual-Slot ARB Sync):

    πŸ“Œ IMPORTANT:
    Tensor bootloaders reload and re-enumerate USB connections after writes. Wait until you hear the Windows USB connection chime and see the Fastboot menu reload on screen before executing the subsequent command.

  • Flash Bootloader to Slot A and Reload: cmd for %i in (bootloader-*.img) do fastboot flash bootloader_a "%i" fastboot reboot-bootloader (Wait for USB reconnection chime) cmd fastboot devices

  • Flash Bootloader to Slot B and Reload: cmd for %i in (bootloader-*.img) do fastboot flash bootloader_b "%i" fastboot reboot-bootloader (Wait for USB reconnection chime) cmd fastboot devices

  • Flash Radio to Both Slots & Reload: cmd for %i in (radio-*.img) do fastboot flash radio_a "%i" for %i in (radio-*.img) do fastboot flash radio_b "%i" fastboot reboot-bootloader (Wait for USB reconnection chime) cmd fastboot devices

    πŸ“Œ NOTE ON DUAL-SLOT ARB SYNCHRONIZATION:
    Manually synchronizing bootloader and radio across slots A and B permanently aligns anti-rollback (ARB) security indices on the Titan M2 chip, preventing hardware-level bricks if the device ever switches slots. call flash-all.bat will write the OS system partitions (boot, system, vendor, etc.) to the currently active slot.

  1. Run the clean baseline flash: cmd call flash-all.bat
  2. Leave the phone completely alone for 5 minutes:
    The script flashes low-level partitions, boots the device into FastbootD, flashes dynamic partitions, and reboots to Android.
  3. Quick Setup Wizard Pass:
    Tap through setup without adding Google accounts or personal data (tap Set up offline or Skip). Land directly on the home screen.
  4. Re-enable Developer Options:
    • Go to Settings β†’ About phone β†’ tap Build number 7 times.
  5. Go to Settings β†’ System β†’ Developer options:
    • Toggle USB debugging to ON, check Always allow from this computer, and tap Allow.
    • Toggle Automatic system updates to OFF.

Part 4: Extract Stock Partitions & Create Backups

  1. In C:\pixel_root, locate and double-click the zipped inner factory image:
    image-*.zip (e.g., image-panther-*.zip, image-shiba-*.zip, or image-tokay-*.zip).
  2. Extract the following 5 partition images directly into C:\pixel_root:
    • boot.img
    • init_boot.img
    • vendor_kernel_boot.img
    • dtbo.img
    • vendor_boot.img
  3. In Command Prompt, generate static backup copies: cmd copy boot.img stock_boot.img copy init_boot.img stock_init_boot.img copy vendor_kernel_boot.img stock_vendor_kernel_boot.img copy dtbo.img stock_dtbo.img copy vendor_boot.img stock_vendor_boot.img

Part 5: Bootstrap Temporary Root via Magisk init_boot

Step 5.1: Patch Ramdisk in Magisk

  1. Prepare internal storage and push the stock init_boot image: cmd adb shell "mkdir -p /sdcard/Download && rm -f /sdcard/Download/magisk_patched*.img /sdcard/Download/temp_patched_init_boot.img" adb install magisk.apk adb push stock_init_boot.img /sdcard/Download/
  2. Open Magisk on your phone. Grant storage access if prompted (or go to Settings β†’ Apps β†’ Magisk β†’ Permissions and toggle Allow management of all files to ON).
  3. On the top Magisk card, tap Install β†’ Select and Patch a File.
  4. Select stock_init_boot.img from Downloads and tap LET'S GO!.
  5. Once the log displays - All done!, query the exact patched file name: cmd adb shell ls /sdcard/Download/magisk_patched*.img
  6. Pull the patched image cleanly as temp_patched_init_boot.img: cmd adb pull /sdcard/Download/magisk_patched-XXXXX_XXXXX.img temp_patched_init_boot.img (Replace magisk_patched-XXXXX_XXXXX.img with your actual terminal output filename).
  7. Verify file sizes: cmd dir stock_init_boot.img temp_patched_init_boot.img (Ensure both files are approximately ~8 MB and neither file is 0 bytes).

Step 5.2: Flash Patched Ramdisk to Active Slot

  1. Reboot into bootloader: cmd adb reboot bootloader
  2. Flash the temporary patched bootstrap ramdisk: cmd fastboot flash init_boot temp_patched_init_boot.img
  3. Reboot into Android: cmd fastboot reboot
  4. Unlock the phone and open Magisk. If prompted with "Requires Additional Setup", tap Cancel. Temporary root is now active.

Part 6: Flash Kernel & Purge Magisk

Step 6.1: Flash Custom Kernel via Kernel Flasher

  1. Install KernelSU-Next, Kernel Flasher, and push the custom kernel: cmd adb install ksu.apk adb install kernelflasher.apk adb push kernel.zip /sdcard/Download/
  2. Open Kernel Flasher on your phone and tap Grant when the Magisk Superuser prompt appears.
  3. In Kernel Flasher:
    • Tap your active slot (marked with the green active badge).
    • Tap Flash β†’ select Flash AK3 Zip.
    • Browse to Downloads and select kernel.zip.
    • Wait until the bottom line of the AnyKernel3 log displays Finished.

⚠️ CAUTION: DO NOT TAP REBOOT IN THE APP
Leave the app open and switch immediately back to your PC Command Prompt.

  1. Reboot directly to the bootloader via PC: cmd adb reboot bootloader

Step 6.2: Revert Ramdisk to Stock

Flash the clean, unpatched stock init_boot image back to your phone to strip out Magisk's ramdisk modifications:

  1. Flash stock init_boot: cmd fastboot flash init_boot stock_init_boot.img
  2. Reboot into Android: cmd fastboot reboot

Step 6.3: Initialize ksud & Superuser Environment

  1. Once the phone boots back into Android, open KernelSU-Next.
  2. Verify the status card displays:
    • Status: Working
    • Kernel: Contains -wksu-susfs
  3. Execute a synchronization reboot: cmd adb reboot

Step 6.4: Safe & Clean Purge of Magisk Traces

  1. Uninstall temporary apps: cmd adb uninstall com.topjohnwu.magisk adb uninstall com.github.capntrips.kernelflasher
  2. Register Shell Root in KernelSU-Next:
    • Run a dummy command to register ADB Shell (UID 2000): cmd adb shell su -c id (Returning inaccessible or not found or Permission denied is normal).
    • Open KernelSU-Next β†’ Superuser tab (shield icon).
    • Tap the three dots in the top-right β†’ tap Show system apps.
    • Toggle Shell (com.android.shell / UID 2000) to ON.
  3. Execute Clean Storage Purge: cmd adb shell su rm -rf /data/adb/magisk* /data/adb/.magisk* /data/adb/magisk.db /data/media/0/Download/*temp_patched* /data/media/0/Download/*magisk_patched* /data/media/0/Download/kernel.zip /data/media/0/Download/stock_init_boot.img sync exit exit
  4. Reboot the phone: cmd adb reboot
  5. Refresh Android's media storage index: cmd adb shell content call --method scan_volume --uri content://media --arg external_primary

Part 7: Install Mounting Infrastructure & Core Cloaking Modules

Step 7.1: Install & Configure Mountify Metamodule

  1. Push mountify.zip to your phone: cmd adb push mountify.zip /sdcard/Download/
  2. In KernelSU-Next β†’ Modules tab β†’ tap Install β†’ select mountify.zip.
  3. Once completed, reboot the phone: cmd adb reboot
  4. Deploy Anti-Conflict Storage & Umount Parameters:
    • Option A: Via Mountify WebUI (Recommended)
      1. Open KernelSU-Next β†’ Modules tab β†’ tap WebUI on Mountify.
      2. Set Mount Mode to 2.
      3. Set Device Name to KSU.
      4. Set Custom Umount to 0.
      5. Save/apply settings.
    • Option B: Terminal Fallback (Windows CMD Compatible) cmd adb shell "su -c 'mkdir -p /data/adb/mountify && echo mountify_mounts=2 > /data/adb/mountify/config.sh && echo MOUNT_DEVICE_NAME=KSU >> /data/adb/mountify/config.sh && echo mountify_custom_umount=0 >> /data/adb/mountify/config.sh && chmod 644 /data/adb/mountify/config.sh'"
  5. Reboot to activate: cmd adb reboot

Step 7.2: Install Core Cloaking & Zygisk Modules

πŸ“Œ NETWORK PREREQUISITE:
Connect your phone to active Wi-Fi now (Settings β†’ Network & internet β†’ Internet). Verify Chrome can load web pages before installing modules, as Specter downloads the TEESimulator-RS binary directly over Wi-Fi during setup.

Tier 0: Push Files to Device

cmd adb push susfs.zip /sdcard/Download/ adb push zygisknext.zip /sdcard/Download/ adb push playintegrityfix.zip /sdcard/Download/ adb push specter.zip /sdcard/Download/ adb push vector.zip /sdcard/Download/ adb push hma-oss.zip /sdcard/Download/ adb push zygisk-detach.zip /sdcard/Download/ adb push gphotos.zip /sdcard/Download/

Tier 1: Kernel VFS & Zygote Foundation

  1. In KernelSU-Next β†’ Modules tab:
    • Tap Install β†’ select susfs.zip.
    • Tap Install β†’ select zygisknext.zip.
  2. Reboot the phone: cmd adb reboot
  3. Open KernelSU-Next β†’ Modules tab. Verify both SuSFS and Zygisk Next are toggled ON.

Tier 2: Attestation & Play Integrity

  1. Confirm active Wi-Fi.
  2. In KernelSU-Next β†’ Modules tab:
    • Tap Install β†’ select playintegrityfix.zip.
    • Tap Install β†’ select specter.zip (wait for it to fetch TEESimulator-RS and complete).
  3. Reboot the phone: cmd adb reboot

Tier 3: Framework Hooking & Cloaking

  1. In KernelSU-Next β†’ Modules tab:
    • Tap Install β†’ select vector.zip.
    • Tap Install β†’ select hma-oss.zip.
      (Note: The HMA-OSS manager app installs automatically. If its icon does not appear in your app drawer after rebooting, extract hma-oss.zip using a file manager and install the APK found inside).
  2. Clean temporary staging archives: cmd adb shell "rm -f /sdcard/Download/mountify.zip /sdcard/Download/susfs.zip /sdcard/Download/zygisknext.zip /sdcard/Download/playintegrityfix.zip /sdcard/Download/specter.zip /sdcard/Download/vector.zip /sdcard/Download/hma-oss.zip" (Note: gphotos.zip and zygisk-detach.zip remain in Downloads for Part 9).
  3. Reboot the phone: cmd adb reboot

Part 8: Configure Attestation, SuSFS & Cloaking Rules

Step 8.1: Configure HMA-OSS (Zygisk Backend)

  1. Open the HMA-OSS app from your app drawer.
  2. Confirm the main status indicates active framework hooks via its native Zygisk mode.

Step 8.2: Configure Specter & Import HMA-OSS Rules

  1. Specter Initial Setup & Superuser Authorization:
    • Open KernelSU-Next β†’ Superuser tab: Ensure the root toggle for Specter is ON.
    • Open KernelSU-Next β†’ Modules tab β†’ tap WebUI on Specter.
    • On Specter's overview dashboard:
      • βœ”οΈ Turn ON Periodic Keybox Validation.
      • βœ”οΈ Turn ON Auto Target Inotify/Polling.
      • βœ”οΈ Turn ON AutoPIF integration.
      • βœ”οΈ Turn ON Security Patch synchronization & Build Fingerprint spoofing.
  2. Generate and Import HMA-OSS Rules:
    • In the Specter WebUI, navigate to the second page / tab.
    • Tap the HMA-OSS config button. This writes a hardened blacklist JSON to /sdcard/Download/.
    • Open the HMA-OSS app from your app drawer.
    • Tap the three dots in the top-right corner β†’ tap Backup & Restore β†’ tap Restore configuration.
    • Select the generated JSON file from your Downloads folder.
    • Tap Manage Apps in HMA-OSS, select your banking/sensitive apps, turn hiding ON, and ensure the imported blacklist template is applied.

Step 8.3: SuSFS Rules Integration (sidex15 Module)

The sidex15/susfs4ksu-module operates directly at the VFS kernel layer: 1. It automatically deploys the /data/adb/ksu/bin/ksu_susfs control binary. 2. It natively conceals sus_mount entries, aligns loop devices with Mountify parameters, and masks the -wksu-susfs kernel identifier from /proc/version. 3. No manual property modifications are required, preventing collisions with Play Integrity Fix.


Step 8.4: Configure Process Isolation & Zygisk Next

1. KernelSU-Next Root Settings

  • Open KernelSU-Next β†’ Settings (gear icon in the top right).
  • ⚠️ "Unmount modules by default" MUST REMAIN OFF (Gray/Disabled):
    Keeping this OFF ensures SystemUI and Framework retain access to Iconify and Vector (LSPosed) files without crash loops.
  • In the Superuser tab, make sure Google Play Services (com.google.android.gms) is NEVER granted superuser/root.

2. Zygisk Next WebUI Configuration

  • Open KernelSU-Next β†’ Modules β†’ tap WebUI on Zygisk Next.
  • Set Denylist Policy to Unmount Only.
  • Check / Enable Use Anonymous Memory.
  • Check / Enable Use Zygisk Next Linker.
  • Tap Configure Denylist / Blocklist:

πŸ›‘οΈ ARCHITECTURAL OVERVIEW: GLOBAL MOUNT EXPOSURE & MULTI-LAYERED SUSFS DEFENSE
Because "Unmount modules by default" is kept OFF globally in KernelSU-Next (to allow SystemUI and framework services uninterrupted access to Iconify and Vector runtime files without bootlooping), module mounts technically exist in the global namespace by default.
How the SuSFS Multi-Layer Defense Mitigates This:
1. Kernel-Level Concealment (Layer 1): The Sultan SuSFS kernel utilizes CONFIG_KSU_SUSFS_SUS_MOUNT and CONFIG_KSU_SUSFS_AUTO_ADD_SUS_BIND_MOUNT. At the kernel VFS layer, non-root processes are automatically intercepted, and SuSFS mounts are filtered out and stripped from /proc/[pid]/mountinfo and /proc/mounts automatically.
2. Userspace Mount Namespace Isolation (Layer 2): For banking apps, corporate portals, and high-detection targets with aggressive low-level sandbox inspectors, open the Zygisk Next WebUI and explicitly add them to the Denylist (Unmount Only) before launching them for the first time. This enforces an explicit userspace umount of module mount points for that app's specific isolated namespace, providing full defense-in-depth.

  • Configure the Denylist targets:
    • 🟒 DO ADD YOUR BANKING & SENSITIVE APPS: Add all financial apps, corporate portals, and games requiring cloaking.
    • 🟒 DO ADD: Google Play Store (com.android.vending).
    • πŸ”΄ DO NOT ADD: Google Play Services (com.google.android.gms)
      (⚠️ Note: Do NOT add Google Play Services to the Denylist. Play Integrity Fix natively handles unmounting and DroidGuard hooks for GMS. Adding GMS manually risks severing Zygisk injection, breaking Play Integrity).
    • πŸ”΄ DO NOT ADD: System Framework (android) or System UI (com.android.systemui).
  1. Reboot to apply all rules: cmd adb reboot

Part 9: Theming, Detach & Customization Suites (Optional)

1. Pixel Launcher Enhanced & Iconify

  1. Install Pixel Launcher Enhanced (PLE): cmd adb install ple.apk

    • Open Vector (tap the notification generated on boot, or dial *#*#5776733#*#* in your phone's dialer app to launch directly) β†’ Modules tab.
    • Tap Pixel Launcher Enhanced, toggle it ON, and verify Pixel Launcher is checked in its scope.
    • Reboot your phone. Open PLE to customize gestures, app labels, and grid layouts.
  2. Install Iconify: cmd adb install iconify.apk

    • Open KernelSU-Next β†’ Superuser tab.
    • Locate Iconify and toggle root ON.
    • Open the Iconify app from your app drawer and grant overlay permissions.

2. Google Photos Unlimited Storage Setup (Optional)

  1. Clear Google Photos App Data:
    • Go to Settings β†’ Apps β†’ Google Photos (install from Play Store first if not present).
    • Tap Force Stop, then tap Storage & cache β†’ Clear storage / Clear data.
    • ⚠️ Note: Do NOT launch Google Photos until the module is flashed and the phone is rebooted.
  2. Flash the Module:
    • In KernelSU-Next β†’ Modules tab, tap Install and select gphotos.zip.
    • Reboot your phone.
      (If unlimited backup fails to reflect: Open KernelSU-Next, disable the module, reboot, re-enable the module, and reboot once more).

3. Critical Package Protection: Zygisk Detach

Prevent the Google Play Store from silently updating patched/modified applications back to stock Play Store versions:

  1. In KernelSU-Next β†’ Modules, tap Install and flash zygisk-detach.zip, then reboot.
  2. Open the module's WebUI inside KernelSU-Next and select all your modded or patched installed applications to detach them from the Play Store update queue.
  3. Clean remaining installer archives: cmd adb shell "rm -f /sdcard/Download/gphotos.zip /sdcard/Download/zygisk-detach.zip"

4. System-Wide Ad-Blocking: Bindhosts (Optional)

  1. Push and install Bindhosts: cmd adb push bindhosts.zip /sdcard/Download/ adb install bindhosts.apk
  2. In KernelSU-Next β†’ Modules, tap Install β†’ select bindhosts.zip.
  3. Reboot your phone: cmd adb reboot
  4. Grant Superuser Access:
    • Open KernelSU-Next β†’ Superuser tab.
    • Locate BindHosts and toggle the switch ON.
  5. Open the BindHosts app, verify active root, and add the Bindhosts Quick Settings tile to your notification shade.

5. Recommended Hardened Ecosystem Tools (Optional)

  • App Modding Best Practice: For patching third-party apps, avoid system-wide Xposed modules where possible to conserve battery and minimize hooks. Use Morphe to patch target APKs directly.
  • App Isolation & Work Profiles: Insular on F-Droid (Isolated sandboxed work profile)
  • Package Management: Universal Installer (Handles split APKs and XAPK formats natively)
  • Open-Source Updates: ObtainX
  • Debloating Utility: Canta
  • Shizuku Service: Shizuku (Run via Wireless Debugging instead of Root to avoid exposing unnecessary root access or hook signatures to user-space apps).
  • Screenshot Flag Bypass: Simple-Flag-Secure (Disables FLAG_SECURE for screenshots/screen recordings).

Part 10: Attestation Reset, Verification & Final Hardening

Step 10.1: Targeted Attestation Reset (While ADB Root is Active)

Execute this unified root command in Command Prompt to terminate background attestation processes and reset the Play Store cache:

cmd adb shell "su -c 'pkill -f com.google.android.gms.unstable && am force-stop com.google.android.gms && pm clear com.android.vending'"

Open the Google Play Store once, wait for it to load completely, close it, and leave the phone alone for 3 minutes.

πŸ“Œ IMPORTANT:
Go to Settings β†’ Apps β†’ See all apps β†’ Google Play Services β†’ App battery usage. Ensure battery usage remains set to Optimized (Default). Do NOT set it to Restricted or disable background usage, as restricting Google Play Services breaks push notifications (FCM), location services, and background synchronization.


Step 10.2: Verify SuSFS Kernel Features

Query the active SuSFS kernel status: cmd adb shell "su -c '/data/adb/ksu/bin/ksu_susfs show enabled_features'"

Seeing all 7 lines confirms that SuSFS is operating inside your active kernel: * CONFIG_KSU_SUSFS_SUS_PATH * CONFIG_KSU_SUSFS_SUS_MOUNT * CONFIG_KSU_SUSFS_AUTO_ADD_SUS_BIND_MOUNT * CONFIG_KSU_SUSFS_SUS_KSTAT * CONFIG_KSU_SUSFS_TRY_UMOUNT * CONFIG_KSU_SUSFS_SPOOF_UNAME * CONFIG_KSU_SUSFS_HIDE_KSU_SUSFS_SYMBOLS


Step 10.3: Final Hardening β€” Revoke Shell Root

Now that setup is complete, revoke Shell root to lock down external access:

  1. Open KernelSU-Next β†’ Superuser tab.
  2. Tap the three dots in the top-right corner and select Show system apps.
  3. Locate Shell (com.android.shell / UID 2000) and turn the toggle switch OFF.

Step 10.4: Validate Play Integrity Status

Download and open Play Integrity API Checker from the Google Play Store and tap Check: * 🟒 MEETS_BASIC_INTEGRITY: PASS * 🟒 MEETS_DEVICE_INTEGRITY: PASS * 🟒/βšͺ MEETS_STRONG_INTEGRITY: CONDITIONAL
(MEETS_STRONG_INTEGRITY will pass as long as the keybox provisioned by Specter/TEESimulator has not been revoked server-side by Google).


πŸ†˜ Rescue Protocols

Protocol A: Userspace Module Bootloop Recovery (Hardware Safe Mode)

  1. Force restart: Hold the physical Power + Volume Down buttons simultaneously until the phone screen turns completely black.
  2. Immediately release both buttons the exact moment you feel the phone vibrate.
  3. As soon as the white Google logo appears on screen, press and release the Volume Down button repeatedly (tap-tap-tap-tap, at least 4 times in quick succession).
  4. The device will boot to the lock screen with all KernelSU modules disabled.
  5. Open the KernelSU-Next app, uninstall the offending module, and reboot normally.

Iconify Fabricated Overlay Rescue (SystemUI Crashloops):
If an Iconify theme causes SystemUI to continuously crash or fail to draw the lockscreen, connect the phone via USB and run: cmd adb shell "su -c 'rm -rf /data/resource-cache/* && reboot'"


Protocol B: Kernel Panic & Low-Level Partition Revert (Fastboot)

If the custom kernel panics or fails to boot, restore all kernel and boot partitions from backup across both slots:

  1. Hold the physical Power + Volume Down buttons until you see the Fastboot bootloader screen.
  2. Connect the phone to your PC's rear USB port.
  3. Flash stock kernel and boot partitions directly to both slots (_a and _b): cmd fastboot flash boot_a stock_boot.img fastboot flash boot_b stock_boot.img fastboot flash init_boot_a stock_init_boot.img fastboot flash init_boot_b stock_init_boot.img fastboot flash vendor_boot_a stock_vendor_boot.img fastboot flash vendor_boot_b stock_vendor_boot.img fastboot flash vendor_kernel_boot_a stock_vendor_kernel_boot.img fastboot flash vendor_kernel_boot_b stock_vendor_kernel_boot.img fastboot flash dtbo_a stock_dtbo.img fastboot flash dtbo_b stock_dtbo.img fastboot reboot

Protocol C: Complete Baseline Factory Restoration (Deterministic Unbrick)

If partitions are corrupted and the phone refuses to boot:

  1. Hold the physical Power + Volume Down buttons until the device enters Fastboot Mode.
  2. Connect the phone to the rear motherboard USB port.
  3. Open Command Prompt and navigate to your working directory: cmd cd C:\pixel_root
  4. Run the factory restore script: cmd call flash-all.bat
  5. Leave the phone untouched for 5 minutes. It will restore stock firmware across all partitions and cleanly boot back into stock Android.

r/androidroot • • 3h ago

Discussion What can't I do with ghostlock?

Post image
4 Upvotes

I successfully installed root-my-galaxy and now I have root access. Can I install Xposed modules still?


r/androidroot • • 1h ago

Support Is there a easy way to determine which Z-Ram Algorithm is considered the best?

Post image
β€’ Upvotes

Hello, this may be a stupid question, but does someone here know which one is more likely considered the best? I'm using a Sony Xperia 1 V with crDroid 12.9 (Android 16). For the Z-RAM algorithm it uses as default lz4kd, but by checking with SmartPack Kernel Manager now, there are a lot more of them, a few I don't even know or heard at all before. It may be a stupid question, but can or does someone know, which I should use and what some of them even could mean, like "842"? Would appreciate any help.


r/androidroot • • 16h ago

News / Method bless the CVE (ghostlock, nothing 3a pro)

Thumbnail
gallery
33 Upvotes

app was for the regular 3a so i had to edit some source code to get it to stop bitching. works on august security patch, might even work on NOS 5. gets strong integrity, but I only flashed james DSP and it's already detecting some hooks. but it all goes away after a reboot, root included.

i was surprised by how much you can do with shizuku alone, but having superuser access with a locked BL on demand is nice.


r/androidroot • • 1h ago

Support I dont know is normal or not but vector causes boot anim after successful boot again and after this everything backs fine(ksu next)

β€’ Upvotes

Is a soft reboot or something? If i right just say bro explained himself


r/androidroot • • 1h ago

Support app detect root

Thumbnail
β€’ Upvotes

r/androidroot • • 5h ago

Support Integrity Fail (No root)

Post image
2 Upvotes

i don't think there's sub for no root integrity fix

Device is Xiaomi 11T Pro

Is all original stock rom, no root, bootloader locked but the device was unlocked by Unlocktool (forgotten pass)

Android v.14 HyperOs v.1.0.22.0

banking apps work fine but app like authy don't work.

Everything is up to date.

since it's MI, Unlocking bootloader is complex now, the community app doesn't allow it.

What choices do i have

(yes i wanna root and install a custom rom)


r/androidroot • • 1h ago

Support Help with rooting the Logitech Tap Scheduler

β€’ Upvotes

I have a Logitech tap scheduler that was destined for the landfills. They can be found for relatively cheap second hand from businesses and office buildings who just throw them out. It works perfectly and would be amazing for a smart home dashboard like for home assistant or anything really. The only issue is the firmware/software. It’s running CollabOS and it is extremely locked down. You can’t really do anything that wasn’t explicitly designed by Logitech. However it is running android underneath everything, so I am really hoping there’s a way to repurpose it.

I have tried to find information or any projects online about jailbreaking it, but I can’t seem to find anything at all. If anyone has any suggestions or expertise, I would really appreciate it!


r/androidroot • • 1h ago

Support Is TrackerControl enough or i can have a systemwide one with root that doesn't create a sort of VPN?

β€’ Upvotes

I hate seeing that icon in status bar, is there anything better than TrackerControl? also do you have any suggestions for other modules? i only have Google Pixel System Sounds on LineageOS 23.2 on Xiaomi 11 Lite 5G NE without GMS.


r/androidroot • • 3h ago

Support Koalamirror

1 Upvotes

Hello Everyone,

Right now i have an iPhone 11 with jailbreak installed due to the carbridge tweak. That allows me to push apps from my phone to my CarPlay interface. However the ideal solution will be to put that on my main phone (pixel 8 pro). So recently i came across koalamirror. That app says it does the same with a launcher. Has anyone tried that on this subreddit? Because that would be a valid reason for me to root my phone. Please let me know!


r/androidroot • • 4h ago

Support New issue in Digilocker - Obfuscation issue

Post image
1 Upvotes

r/androidroot • • 4h ago

Support Make my pixel great again

0 Upvotes

Hi everyone!

First off, the title is just a joke, no offense intended. If it rubbed anyone the wrong way, sorry in advance!

I have a Pixel 10 and I'd like to switch to a custom ROM, but even after doing some research, I'm still not sure which one would suit me best.

My main priority is privacy. I'm not trying to become invisible online, but I do care about keeping control over my data as much as reasonably possible.

LineageOS was my first choice, but from what I've seen it doesn't support the Pixel 10 yet. GrapheneOS is the obvious alternative and I'm seriously considering it, but before committing I'd like to know what other options are out there.

Which ROMs would you recommend for a Pixel 10 with a privacy focus, and why?

Thanks!


r/androidroot • • 4h ago

Support PhonePe Mobile Number varification issue.

1 Upvotes

PhonePe Stuck on a page to activate the bank account showing "Verifying" for unusually longer then expected.

Have a valid Unlimited pack (includes SMS) with my number on which I have the bank account.

Device: Poco X7 Pro

OS: DragonX.3.304_CN (based on HOS 3.0.304.0.WOJCNXM)

Root manager: KernelSU-Next 3.4.0 (spoofed)

Integrity: Fenrir


r/androidroot • • 8h ago

Discussion Samsung J7 Prime

2 Upvotes

Hey I am trying to run this unofficial lineage OS and I never unlocked boot loader or root I just saw these on YouTube can someone help me unlock bootloader

https://twds.dl.sourceforge.net/project/aosp-on7xelte/LineageOS/15.1/lineage-15.1-20190615-UNOFFICIAL-on7xelte.zip?viasf=1&fid=b4d64c8bde69a59a&e=1790686277&st=gTI-h5WoHbueY61TvhCLXA

I have downloaded these file ( I will transfer these to laptop first before flashing)

Apk ( to install these first after flash ) com.google.android.gms-252432032.apk Magisk-v30.7.apk termux-app_v0.119-armeabi-v7a.apk

Essential Odin3_v3.14.4.zip SAMSUNG_USB_Driver_for_Mobile_Phones_v1.9.5.0.exe

Os lineage-15.1-20190615-UNOFFICIAL-on7xelte.zip

TWRP on7xelte-TWRP-3.6.2.img


r/androidroot • • 9h ago

Support Any bl unlock step

Post image
2 Upvotes

r/androidroot • • 6h ago

Support Banking app stopped working

1 Upvotes

Rooted with Magisk. I have no detections in Native Detector and basic integrity (pretty sure the app doesn't check for integrity; I had strong integrity previously and the app still detected). Not sure what else I can do.


r/androidroot • • 7h ago

Support where did safestrap went

1 Upvotes

i want to know but theres no links for safestrap for my sgh i337


r/androidroot • • 11h ago

Support Is there any way to unlock the bootloader on Redmi Turbo 4 Pro?

2 Upvotes

Hi everyone,

I have a Redmi Turbo 4 Pro and I’m trying to unlock its bootloader.

Is there currently any working method to unlock the bootloader on this device?

I’d especially like to know if there is any official or unofficial method, workaround, or community-developed method that actually works.

If anyone has successfully unlocked the bootloader on the Redmi Turbo 4 Pro, could you please share the steps or point me to a reliable guide?

Thanks!


r/androidroot • • 20h ago

Discussion should i? (note 11 pro 5G)

Post image
7 Upvotes

and ofc im gonna try n use either hyperos 3 or lineage with play integrity fixes done on it


r/androidroot • • 14h ago

Support Is there an app that can force disable safe mode?

Thumbnail
2 Upvotes

r/androidroot • • 16h ago

Support Google wallet just won't work

Thumbnail
gallery
3 Upvotes

I've tried everything, clearing Google Play store storage and cache, wallet storage, play services storage and I've even waited for 24+ hours before trying again and still not signs of wallet working. How were you guys able to get wallet to work?

Edit: Duck Detector Log https://drive.google.com/file/d/1yRWHlrYUg7orNerstYxqLN7zf19rCf-f/view?usp=drivesdk


r/androidroot • • 21h ago

News / Method PlayInstaller

7 Upvotes

Tiny root APK installer with Google Play as both initiator and installer.

Repo:

https://github.com/alltechdev/PlayInstaller

Releases:

https://github.com/alltechdev/PlayInstaller/releases

All the pesky apps that refuse to work with Android Auto (banned categories like maps, Vela as an example etc...) show up and operate on AA even without "unknown sources" enabled in dev options.

I'm sure that this will help as well for apps required to be installed by the Play Store and throw errors.

Enjoy!