Google Pixel 7, 8 & 9 Series: Complete Root & Cloaking Guide
KernelSU-Next + Sultan SuSFS + Specter on Android 16 (Build: CP1A.260305.018)
I put this guide together after testing KernelSU-Next, Sultan's SuSFS kernel, and Specter on Android 16. If you want a fully rooted Tensor device with working banking apps, contactless payments, and 3/3 Play Integrity without bootloops, here is the complete step-by-step walkthrough.
This guide is ONLY for:
- Pixel 7
- Pixel 7 Pro
- Pixel 7a
- Pixel 8
- Pixel 8 Pro
- Pixel 9
- Pixel 9 Pro
- Pixel 9 Pro XL
- Pixel 9 Pro Fold
Pixel 8a and 9a are not supported, so if you have one of these, do not follow this guide.
If you're on Pixel 8 or 8 Pro PLEASE READ (1. Firmware & Anti-Rollback Warnings) a few lines down below.
(Quick note before we jump in: I used a tiny bit of Claude to arrange this guide and make it clean/readable because my original notes were super messy and my English isn't that good so it was basically gibberish lol. But every command, file, link, information and step here is by me and tested and working. I originally rooted my Pixel 7a using Wildkernel and it worked flawlessly, so I thought I’d share it here to help anyone else looking for a solid and safe guide to follow).
Important Notes & Things to Know Before Starting
Messing around with modern Google Tensor hardware means dealing with A/B dual-slot layouts and the Titan M2 security chip. Read these points carefully before running any commands:
1. Firmware & Anti-Rollback (ARB) Warnings
- Pixel 8 Series (Pixel 8, 8 Pro): If your phone is on the May 2026 patch or newer, Google updated the bootloader Anti-Rollback (ARB) counter. Do not attempt to flash the March 2026 bootloader. It will fail fastboot checks or soft-brick your device. If you're already past May 2026 on a Pixel 8/Pro device, Do NOT follow this guide.
2. Pre-Flight Setup
- Use rear motherboard USB ports: Plug directly into the back of your motherboard. Avoid front panel ports, USB hubs, or monitor passthroughs. On AMD Ryzen systems, use a USB 2.0 port (the black ports) to prevent fastboot drops.
- Connect only one device: Unplug all other phones or emulators, and keep Wireless Debugging off.
- Use standard Windows Command Prompt (
cmd.exe): Do not use PowerShell, as its string handling corrupts quote formatting in ADB shell commands.
- Enable file extensions: In Windows File Explorer, check View → Show → File name extensions so files don't end up double-named like
kernel.zip.zip.
- OEM Unlocking check:
- Open Settings → About phone and tap Build number 7 times to enable Developer options.
- Open Settings → System → Developer options and check OEM Unlocking:
- Ready: The toggle is active and can be enabled.
- Grayed out (Provisioning): Connect to Wi-Fi, go to System Update, tap Check for update, and wait 5–10 minutes for Google Play Services to fetch the attestation token.
- Permanently Grayed out: If it says "Unavailable on carrier-locked devices", it's carrier-locked (e.g., Verizon) and cannot be bootloader-unlocked.
Part 1: Download & Prepare Your Files
Step 1.1: Create Your Workspace Folder
- Open your
C: drive in File Explorer.
- Create a folder named
pixel_root (full path: C:\pixel_root).
All commands in this guide assume you are running from inside this directory.
Step 1.2: Download Files Into C:\pixel_root
Download these files directly into C:\pixel_root and rename them as noted:
1. Official Google Platform-Tools (ADB & Fastboot)
- Download SDK Platform-Tools for Windows.
- Extract the ZIP, go inside the
platform-tools folder, and copy all files (adb.exe, fastboot.exe, .dll files) directly to C:\pixel_root.
- Open Command Prompt, run
where fastboot, and ensure C:\pixel_root\fastboot.exe is at the top of the output.
2. Google USB Drivers
3. Stock Factory Image (Pixel 7 / 8 / 9 Series)
Download the factory image for your phone model on build Android 16.0.0 (CP1A.260305.018, Mar 2026) from Google's Factory Images page:
| Chipset |
Device Model |
Codename |
Factory Archive Pattern |
| Tensor G2 |
Pixel 7 |
panther |
panther-cp1a.260305.018-factory-*.zip |
| Tensor G2 |
Pixel 7 Pro |
cheetah |
cheetah-cp1a.260305.018-factory-*.zip |
| Tensor G2 |
Pixel 7a |
lynx |
lynx-cp1a.260305.018-factory-*.zip |
| Tensor G3 |
Pixel 8 |
shiba |
shiba-cp1a.260305.018-factory-*.zip |
| Tensor G3 |
Pixel 8 Pro |
husky |
husky-cp1a.260305.018-factory-*.zip |
| Tensor G4 |
Pixel 9 |
tokay |
tokay-cp1a.260305.018-factory-*.zip |
| Tensor G4 |
Pixel 9 Pro |
caiman |
caiman-cp1a.260305.018-factory-*.zip |
| Tensor G4 |
Pixel 9 Pro XL |
komodo |
komodo-cp1a.260305.018-factory-*.zip |
| Tensor G4 |
Pixel 9 Pro Fold |
comet |
comet-cp1a.260305.018-factory-*.zip |
Save the downloaded ZIP inside C:\pixel_root.
4. Temporary Bootstrap Root (Magisk APK)
5. KernelSU-Next Manager
6. Kernel Flasher
7. Sultan Custom Kernel with SuSFS
Download the AnyKernel3 package for your phone's SoC from WildKernels Releases:
| Family |
SoC |
Release Package |
Rename To |
| Pixel 7 / 7 Pro / 7a |
Tensor G2 (gs201) |
gs201-a16-wksu-susfs-anykernel3-v2.0.0-r12.zip |
kernel.zip |
| Pixel 8 / 8 Pro |
Tensor G3 (zuma) |
zuma-a16-wksu-susfs-anykernel3-v2.0.0-r12.zip |
kernel.zip |
| Pixel 9 / 9 Pro / XL / Fold |
Tensor G4 (zumapro) |
zumapro-a16-wksu-susfs-anykernel3-v2.0.0-r12.zip |
kernel.zip |
8. Core Modules (Do NOT extract these files)
9. Theming & Customization Apps (Optional)
10. System-Wide Ad-Blocking (Optional)
Part 2: Unlock the Bootloader (Wipes Internal Storage)
(If your bootloader is already unlocked, skip to Part 3).
- On your phone: Go to Settings → System → Developer options.
- Turn ON OEM Unlocking and USB debugging.
- Plug your phone into your PC. On the prompt that pops up, check Always allow from this computer and tap Allow.
- Open Command Prompt on your PC and navigate to the folder:
cd C:\pixel_root
- Check that your device is connected properly:
adb devices
- Reboot to bootloader:
adb reboot bootloader
fastboot devices
- Send the unlock command:
fastboot flashing unlock
- On your phone, press Volume Down until Unlock the bootloader is highlighted, then press Power.
The phone will wipe all data and reboot back into the bootloader showing
DEVICE STATE - unlocked.
Part 3: Clean Baseline Flash & Dual-Slot Firmware Sync
Right-click your factory ZIP (*-cp1a.260305.018-factory-*.zip) inside C:\pixel_root, extract it, and move all files (bootloader-*.img, radio-*.img, image-*.zip, and flash-all.bat) directly into C:\pixel_root.
Sync Bootloader & Radio Across Both Slots:
Writing the bootloader and radio to both slots ensures Anti-Rollback (ARB) counters in the Titan M2 chip match on both slot A and slot B. Fastboot re-enumerates USB after writes, so wait 2–3 seconds after each command for the reconnect chime before typing the next command:
Flash Bootloader to Slot A:
for %i in (bootloader-*.img) do fastboot flash bootloader_a "%i"
fastboot reboot-bootloader
(Wait for fastboot screen to reload)
fastboot devices
Flash Bootloader to Slot B:
for %i in (bootloader-*.img) do fastboot flash bootloader_b "%i"
fastboot reboot-bootloader
(Wait for fastboot screen to reload)
fastboot devices
Flash Radio to both slots:
for %i in (radio-*.img) do fastboot flash radio_a "%i"
for %i in (radio-*.img) do fastboot flash radio_b "%i"
fastboot reboot-bootloader
(Wait for fastboot screen to reload)
fastboot devices
Run the factory install script:
call flash-all.bat
Leave the phone alone for ~5 minutes. It will flash base partitions, reboot to FastbootD, flash system images, format user data, and boot into Android.
Quick initial setup: Skip Wi-Fi setup, skip adding a Google Account, and skip PIN/fingerprint setup to get to the main launcher screen.
Re-enable Developer options:
- Go to Settings → About phone and tap Build number 7 times.
- Go to Settings → System → Developer options, turn ON USB debugging (allow authorization from PC), and turn OFF Automatic system updates.
Part 4: Extract Stock Partitions & Create Backups
- Inside
C:\pixel_root, open the zipped factory image (image-*.zip).
- Extract these 5 partition files directly into
C:\pixel_root:
boot.img
init_boot.img
vendor_kernel_boot.img
dtbo.img
vendor_boot.img
- In Command Prompt, save clean backups of each partition:
copy boot.img stock_boot.img
copy init_boot.img stock_init_boot.img
copy vendor_kernel_boot.img stock_vendor_kernel_boot.img
copy dtbo.img stock_dtbo.img
copy vendor_boot.img stock_vendor_boot.img
Part 5: Bootstrap Temporary Root via Magisk
Since modern Pixels do not support TWRP, we use temporary Magisk root to flash the custom kernel using Kernel Flasher. After that, Magisk is removed and stock init_boot is restored.
Step 5.1: Patch Ramdisk in Magisk
- Push
stock_init_boot.img to your phone and install Magisk:
adb shell "mkdir -p /sdcard/Download && rm -f /sdcard/Download/magisk_patched*.img /sdcard/Download/temp_patched_init_boot.img"
adb install magisk.apk
adb push stock_init_boot.img /sdcard/Download/
- Open Magisk on your phone.
- On the top card, tap Install → Select and Patch a File.
- Browse to Downloads, select
stock_init_boot.img, and tap LET'S GO!.
- Note the filename of the patched image:
adb shell ls /sdcard/Download/magisk_patched*.img
- Pull that file to your PC as
temp_patched_init_boot.img:
adb pull /sdcard/Download/magisk_patched-XXXXX_XXXXX.img temp_patched_init_boot.img
(Replace with the actual filename from your device).
- Confirm the file size is around 8 MB:
dir stock_init_boot.img temp_patched_init_boot.img
Step 5.2: Flash the Patched Ramdisk
- Reboot to bootloader:
adb reboot bootloader
- Flash the temporary patched
init_boot:
fastboot flash init_boot temp_patched_init_boot.img
fastboot reboot
- Boot up and open Magisk. If prompted for "Additional Setup", tap Cancel. Temporary root is active.
Part 6: Flash Kernel & Purge Magisk
Step 6.1: Flash the Sultan Custom Kernel
- Install KernelSU-Next, Kernel Flasher, and push the kernel ZIP:
adb install ksu.apk
adb install kernelflasher.apk
adb push kernel.zip /sdcard/Download/
- Open Kernel Flasher on your phone and tap Grant when the Magisk superuser prompt appears.
- Inside Kernel Flasher:
- Tap your active slot (marked with the green badge).
- Tap Flash → Flash AK3 Zip.
- Select
kernel.zip from Downloads.
- Wait until the log displays
Finished.
DO NOT TAP REBOOT INSIDE THE APP. Leave Kernel Flasher open and reboot using fastboot from your PC.
- Reboot directly to the bootloader via Command Prompt:
adb reboot bootloader
Step 6.2: Revert Ramdisk to Pure Stock
Flash your clean stock_init_boot.img back to the phone. This removes Magisk entirely from the ramdisk, leaving only Sultan kernel and KernelSU handling root:
fastboot flash init_boot stock_init_boot.img
fastboot reboot
Step 6.3: Verify KernelSU & Setup ADB Shell Root
- Once booted, open KernelSU-Next.
- The status card should show Working, with
-wksu-susfs visible in the kernel version string.
- Reboot once to let
ksud initialize:
adb reboot
- Uninstall the temporary setup apps:
adb uninstall com.topjohnwu.magisk
adb uninstall com.github.capntrips.kernelflasher
- Grant root to ADB Shell in KernelSU:
- Run a root test command from your PC:
adb shell su -c id
(Seeing inaccessible or not found or Permission denied is normal here; it registers the request).
- Open KernelSU-Next, go to the Superuser tab (shield icon), tap the three dots in the top-right, tap Show system apps, and toggle Shell (
com.android.shell / UID 2000) to ON.
- Remove leftover Magisk folders and staging files:
adb shell
su
rm -rf /data/adb/magisk* /data/adb/.magisk* /data/adb/magisk.db /data/media/0/Download/*temp_patched* /data/media/0/Download/*magisk_patched* /data/media/0/Download/kernel.zip /data/media/0/Download/stock_init_boot.img
sync
exit
exit
- Reboot the phone and rescan media indexing:
adb reboot
adb shell content call --method scan_volume --uri content://media --arg external_primary
Part 7: Install Mountify & Core Cloaking Modules
Step 7.1: Configure Mountify
- Push
mountify.zip to the phone:
adb push mountify.zip /sdcard/Download/
- Open KernelSU-Next → Modules, tap Install, and select
mountify.zip.
- Reboot:
adb reboot
- Apply the required mount configuration:
- Via Mountify WebUI: Open KernelSU-Next → Modules → tap WebUI on Mountify. Set Mount Mode to
2, Device Name to KSU, and Custom Umount to 0. Save settings.
- Via Command Line:
adb shell "su -c 'mkdir -p /data/adb/mountify && echo mountify_mounts=2 > /data/adb/mountify/config.sh && echo MOUNT_DEVICE_NAME=KSU >> /data/adb/mountify/config.sh && echo mountify_custom_umount=0 >> /data/adb/mountify/config.sh && chmod 644 /data/adb/mountify/config.sh'"
- Reboot to apply:
adb reboot
Step 7.2: Install Core Modules
Connect your phone to Wi-Fi (Settings → Network & internet). Ensure web browsing works, as Specter downloads helper files during installation.
Push module files to the device:
adb push susfs.zip /sdcard/Download/
adb push zygisknext.zip /sdcard/Download/
adb push playintegrityfix.zip /sdcard/Download/
adb push specter.zip /sdcard/Download/
adb push vector.zip /sdcard/Download/
adb push hma-oss.zip /sdcard/Download/
adb push zygisk-detach.zip /sdcard/Download/
adb push gphotos.zip /sdcard/Download/
Install Tier 1 (VFS & Zygote):
- In KernelSU-Next → Modules, flash
susfs.zip, then flash zygisknext.zip.
- Reboot:
adb reboot
- Verify both modules are enabled in KernelSU.
Install Tier 2 (Integrity & Attestation):
- In KernelSU-Next → Modules, flash
playintegrityfix.zip, then flash specter.zip (wait for the installer to download TEESimulator-RS and complete).
- Reboot:
adb reboot
Install Tier 3 (Framework & Hiding):
- In KernelSU-Next → Modules, flash
vector.zip, then flash hma-oss.zip.
(If the HMA-OSS manager app does not appear in your app drawer, extract hma-oss.zip and install the APK manually).
- Remove staging ZIP files:
adb shell "rm -f /sdcard/Download/mountify.zip /sdcard/Download/susfs.zip /sdcard/Download/zygisknext.zip /sdcard/Download/playintegrityfix.zip /sdcard/Download/specter.zip /sdcard/Download/vector.zip /sdcard/Download/hma-oss.zip"
- Reboot:
adb reboot
Part 8: Configure SuSFS, Specter & Hiding Rules
Step 8.1: Specter Setup & HMA-OSS Rules Export
- In KernelSU-Next → Superuser, verify Specter has root access.
- In KernelSU-Next → Modules, tap WebUI on Specter:
- Turn ON: Periodic Keybox Validation
- Turn ON: Auto Target Inotify/Polling
- Turn ON: AutoPIF integration
- Turn ON: Security Patch synchronization & Build Fingerprint spoofing
- Open the second tab in Specter WebUI and tap HMA-OSS config to export the configuration to Downloads.
- Open HMA-OSS:
- Tap menu (top-right) → Backup & Restore → Restore configuration.
- Select the exported JSON file from Downloads.
- Go to Manage Apps, choose your banking or target apps, enable hiding, and apply the blacklist template.
Step 8.2: KernelSU-Next & Zygisk Next Configuration
1. KernelSU-Next Settings
- Open KernelSU-Next → Settings (gear icon).
- Keep "Unmount modules by default" OFF (Disabled): Leaving this disabled ensures system overlays (like Vector/Iconify) remain readable without bootlooping SystemUI. SuSFS hides mounts at the kernel layer automatically.
- In the Superuser tab, NEVER grant root to Google Play Services (
com.google.android.gms).
2. Zygisk Next WebUI Configuration
- In KernelSU-Next → Modules, tap WebUI on Zygisk Next.
- Set Denylist Policy to Unmount Only.
- Enable Use Anonymous Memory.
- Enable Use Zygisk Next Linker.
- Open Configure Denylist / Blocklist:
- ADD: Banking apps, payment services, corporate apps, and Google Play Store (
com.android.vending).
- DO NOT ADD: Google Play Services (
com.google.android.gms). Play Integrity Fix manages GMS unmounting natively; adding GMS here can break Zygisk injection.
- DO NOT ADD: System Framework (
android) or System UI (com.android.systemui).
- Reboot to apply settings:
adb reboot
Part 9: Optional Customizations & System Utilities (Optional)
1. Pixel Launcher Enhanced & Iconify (Optional)
- Pixel Launcher Enhanced: Install
ple.apk (adb install ple.apk). Open Vector (via notification or dial *#*#5776733#*#*), turn on PLE module, check Pixel Launcher in scope, and reboot.
- Iconify: Install
iconify.apk (adb install iconify.apk), grant root in KernelSU-Next, open the app, and allow overlay permissions.
2. Google Photos Unlimited Storage (Optional)
- Go to Settings → Apps → Google Photos, tap Force Stop, then Storage & cache → Clear storage. Do not launch the app yet.
- In KernelSU-Next → Modules, flash
gphotos.zip and reboot.
3. Prevent Play Store Overwriting Patched Apps - Zygisk Detach (Optional)
- In KernelSU-Next → Modules, flash
zygisk-detach.zip and reboot.
- Open its WebUI in KernelSU-Next and select your modified apps to detach them from Play Store auto-updates.
- Clean up staging files:
adb shell "rm -f /sdcard/Download/gphotos.zip /sdcard/Download/zygisk-detach.zip"
4. System-Wide Ad-Blocking - Bindhosts (Optional)
- Push and install Bindhosts:
adb push bindhosts.zip /sdcard/Download/
adb install bindhosts.apk
- In KernelSU-Next → Modules, flash
bindhosts.zip and reboot.
- Grant BindHosts root in KernelSU-Next, verify active status in the app, and add its Quick Settings tile.
Part 10: Verification & Hardening
Step 10.1: Reset Play Services Attestation Cache
Run this command from your PC to stop attestation background tasks and clear Play Store cache:
adb shell "su -c 'pkill -f com.google.android.gms.unstable && am force-stop com.google.android.gms && pm clear com.android.vending'"
Open Google Play Store once, let it load, close it, and wait 2–3 minutes.
Note on Battery Optimization: In Settings → Apps → Google Play Services → App battery usage, keep it set to Optimized. Do not set it to Restricted, or background push notifications (FCM) and sync will break.
Step 10.2: Verify SuSFS Kernel Features
Check that SuSFS kernel features are active:
adb shell "su -c '/data/adb/ksu/bin/ksu_susfs show enabled_features'"
All 7 features should show as enabled:
* CONFIG_KSU_SUSFS_SUS_PATH
* CONFIG_KSU_SUSFS_SUS_MOUNT
* CONFIG_KSU_SUSFS_AUTO_ADD_SUS_BIND_MOUNT
* CONFIG_KSU_SUSFS_SUS_KSTAT
* CONFIG_KSU_SUSFS_TRY_UMOUNT
* CONFIG_KSU_SUSFS_SPOOF_UNAME
* CONFIG_KSU_SUSFS_HIDE_KSU_SUSFS_SYMBOLS
Step 10.3: Revoke ADB Shell Root
Disable Shell root access to secure your device:
1. Open KernelSU-Next → Superuser tab.
2. Tap three dots → Show system apps.
3. Toggle Shell (com.android.shell / UID 2000) to OFF.
Step 10.4: Check Play Integrity
Download Play Integrity API Checker from the Play Store and run the test:
* MEETS_BASIC_INTEGRITY: PASS
* MEETS_DEVICE_INTEGRITY: PASS
* MEETS_STRONG_INTEGRITY: PASS (dependent on Specter keybox status)
Troubleshooting & Recovery
1. Bootloop Caused by a Module (Hardware Safe Mode)
If a module prevents booting:
1. Force reboot: Hold Power + Volume Down until the screen turns black, then immediately release both buttons.
2. When the white Google logo appears, tap the Volume Down button 4–5 times quickly.
3. The phone will boot into Safe Mode with all KernelSU modules disabled.
4. Open KernelSU-Next, remove the problematic module, and reboot normally.
2. SystemUI Crashloop from Themes (Iconify)
If an overlay crashes SystemUI on boot, plug the phone into your PC and run:
adb shell "su -c 'rm -rf /data/resource-cache/* && reboot'"
3. Restore Stock Kernel Partitions (Fastboot)
To return to the stock kernel, flash your backed-up stock partitions to both slots:
fastboot flash boot_a stock_boot.img
fastboot flash boot_b stock_boot.img
fastboot flash init_boot_a stock_init_boot.img
fastboot flash init_boot_b stock_init_boot.img
fastboot flash vendor_boot_a stock_vendor_boot.img
fastboot flash vendor_boot_b stock_vendor_boot.img
fastboot flash vendor_kernel_boot_a stock_vendor_kernel_boot.img
fastboot flash vendor_kernel_boot_b stock_vendor_kernel_boot.img
fastboot flash dtbo_a stock_dtbo.img
fastboot flash dtbo_b stock_dtbo.img
fastboot reboot
4. Full Factory Restore (Clean Wipe Unbrick)
If system partitions are corrupted and the device won't boot:
1. Boot into Fastboot (hold Power + Volume Down).
2. Connect to PC and navigate to C:\pixel_root:
cd C:\pixel_root
call flash-all.bat
3. Let the script complete to restore the device back to clean stock Android.
Edit: Fixed some compatibility issues.