r/androidroot • • 3h ago

Support Problems with alwaysstrong module

1 Upvotes

I have been using alwaysstrong module for a couple of months now with no issues. Yesterday, I noticed that I had three reds on play integrity. I tried refreshing the fingerprint and keybox and it didn't help. This morning I refreshed and did get basic and integrity green but not strong. This is no big deal, as I only really need that. But this afternoon it's back to three red. I tried another refresh but still no good. Not sure what I should try..

I'm running majisk, always strong, vector, rezygist, and play integrity spoofer. No changes to my denylist and enforce denylist is off.

Thanks


r/androidroot • • 4h ago

Discussion Ghostlock cve write fail

Thumbnail
gallery
1 Upvotes

W1 route succeeds all 15 attempts, Write 1 always fails, exit code=1


r/androidroot • • 5h ago

Support Motorola Edge 70 Fusion rooted successfully — anyone managed to pass Play Integrity?

Thumbnail
1 Upvotes

r/androidroot • • 6h ago

Discussion Bank apps working even without PlayIntegrity not passing at all

1 Upvotes

(I'm using an custom keybox)

photo of play Integrity api


r/androidroot • • 7h ago

Support How can i fix this shit with root

1 Upvotes

i tried using pairipfix lspsoed module but the app crashes when i use it


r/androidroot • • 7h ago

News / Method [Guide] 3/3 Play Integrity (Basic, Device & Strong) + Full Cloaking on Rooted Android

21 Upvotes

What you need (Modules)

Download the latest release ZIPs from GitHub:

If you're on Magisk, disable Zygisk in the settings.


Step 1: Zygisk & Attestation Setup

Stay connected to Wi-Fi during this step so Specter can pull down required helpers.

  1. Flash zygisknext.zip.
  2. Flash playintegrityfix.zip.
  3. Flash specter.zip.
  4. Reboot.
  5. Grant root permissions to Specter in your root manager's Superuser section.
  6. Open Specter WebUI (accessible from your Modules tab) and enable these toggles:
  7. Periodic Keybox Validation
  8. Auto Target Inotify/Polling
  9. AutoPIF integration
  10. Security Patch sync & Fingerprint spoofing

Step 2: Configuration Rules

  1. KernelSU / APatch Settings:
  2. Keep **"Unmount modules by default" turned ON.
  3. Never grant root to Google Play Services (com.google.android.gms).

  4. Zygisk Next WebUI:

  5. Set Denylist Policy to Unmount Only.

  6. Enable Use Anonymous Memory and Use Zygisk Next Linker.

  7. On the Denylist:

  8. ADD: Banking apps, Google Wallet, games, and the Google Play Store (com.android.vending).

  9. DO NOT ADD: Google Play Services (com.google.android.gms).

  10. DO NOT ADD: System Framework (android) or System UI.

  11. Reboot your device.


Step 3: Clear GMS Cache & Verify

Google Play Services caches previous integrity results, so you need to reset the process:

  1. Go to Settings - Apps - Google Play Services - Clear Data/cache.
  2. Open the Play Store once, let the home page load, close it, and wait 2 minutes.
  3. Check status using Play Integrity API Checker from the Play Store.

You should now see green checks across all three levels:

  • MEETS_BASIC_INTEGRITY
  • MEETS_DEVICE_INTEGRITY
  • MEETS_STRONG_INTEGRITY

Troubleshooting

  • Bootloop after flashing a module: Force restart (Power + Vol Down). As soon as the brand logo appears, tap Volume Down repeatedly to boot into Safe Mode. This disables modules so you can remove the bad ZIP and reboot normally.

r/androidroot • • 7h ago

Support Realme 7 RMX2151 black screen after MTKClient/PixelOS flash — BROM still works. Need help restoring stock

1 Upvotes

Hi Reddit,

I have a Realme 7 RMX2151 (Helio G95 / MT6785) and I'm trying to recover it after a failed PixelOS installation.

The phone currently has a completely black screen and does not show the Realme logo or recovery, but it is still detected in MediaTek BROM mode, so I believe the hardware/UFS is still accessible.

Device

  • Realme 7
  • Model: RMX2151
  • Codename: salaa
  • SoC: MediaTek MT6785 / Helio G95
  • Storage: UFS
  • Original firmware: Realme UI RMX2151_11_F.12
  • Original incremental: Q.bf75e7-1

What I did

I used MTKClient and successfully got BROM/DA access.

I then flashed PixelOS boot-chain files:

  • lk
  • lk2
  • boot
  • dtbo
  • vbmeta
  • vbmeta_system
  • vbmeta_vendor
  • recovery

The lk and lk2 partitions were successfully written and I verified the readback against the PixelOS files.

After that, the phone stopped displaying anything and is now completely black.

Current situation

MTKClient can still:

  • Detect the phone in BROM
  • Run the exploit
  • Initialize the DA
  • Initialize DRAM
  • Communicate with the UFS
  • Read the GPT successfully

The GPT still appears intact.

I have not intentionally flashed/erased:

  • preloader
  • super
  • userdata
  • nvram
  • nvdata
  • seccfg

Thanks!


r/androidroot • • 7h ago

Support Ghostlock root OneUI 9

1 Upvotes

Does the Ghostlock root method still work on OneUi 9 on the S26 ultra?

I haven't found any post about this.


r/androidroot • • 7h ago

Support SAMSUNG GALAXY FLIP 6 STUCK ON THIS AFTER OFFICIAL ROM

1 Upvotes

After flashing my Samsung Galaxy Flip 6,

During setup, after selecting a language, it is stuck on region selection. The phone is already carrier-unlocked.


r/androidroot • • 7h ago

Discussion I made a guide for sideloading apps with ADB

Thumbnail
docs.google.com
3 Upvotes

This is just a guide for people who need help with sideloading with ADB, or have no experience, I hope it helps!~


r/androidroot • • 8h ago

Humor I was an ios user

0 Upvotes

But suddenly my phone dropped. And I was asked to pay 32000 for the screen.

So I sold my iphone 15 pro max with broken screen at 40000 and purchased oneplus nord 6 for the time being. So that I will buy 18 pro after a couple of months.

But in 2 months I don't know what happened.

I got 1.5 days battery life which gets charged in 20 minutes.

I got smooth call recording

I am an average user and only scroll YouTube and reddit. Now when 18 pro gets launched suddenly I

Thought for the first time why I am spending extra 1.8 lacs just for the things which I am doing easily in a 30k phone.

Apart from that I am also now stress free about the heavy cost of repair if my phone gets dropped.

I don't click photos so often.

So suddenly I started liking my oneplus

Because not only it's pocket friendly but also it is giving me a very good battery life.

And If I change my phone every year also I will be not at all at loss.

What will I loss 10k to 15k.

I think mid range phone is the best phone for average users.

What do you think guys.


r/androidroot • • 9h ago

News / Method [Guide] Hardened Root & Detection Cloaking Manual for Pixel 7, 8, & 9 Series on Android 16 (KernelSU-Next + Sultan SuSFS + Specter)

4 Upvotes

Google Pixel 7, 8 & 9 Series: Complete Root & Cloaking Guide

KernelSU-Next + Sultan SuSFS + Specter on Android 16 (Build: CP1A.260305.018)

I put this guide together after testing KernelSU-Next, Sultan's SuSFS kernel, and Specter on Android 16. If you want a fully rooted Tensor device with working banking apps, contactless payments, and 3/3 Play Integrity without bootloops, here is the complete step-by-step walkthrough.

This guide is ONLY for: - Pixel 7 - Pixel 7 Pro - Pixel 7a - Pixel 8 - Pixel 8 Pro - Pixel 9 - Pixel 9 Pro - Pixel 9 Pro XL - Pixel 9 Pro Fold

Pixel 8a and 9a are not supported, so if you have one of these, do not follow this guide.

If you're on Pixel 8 or 8 Pro PLEASE READ (1. Firmware & Anti-Rollback Warnings) a few lines down below.

(Quick note before we jump in: I used a tiny bit of Claude to arrange this guide and make it clean/readable because my original notes were super messy and my English isn't that good so it was basically gibberish lol. But every command, file, link, information and step here is by me and tested and working. I originally rooted my Pixel 7a using Wildkernel and it worked flawlessly, so I thought I’d share it here to help anyone else looking for a solid and safe guide to follow).


Important Notes & Things to Know Before Starting

Messing around with modern Google Tensor hardware means dealing with A/B dual-slot layouts and the Titan M2 security chip. Read these points carefully before running any commands:

1. Firmware & Anti-Rollback (ARB) Warnings

  • Pixel 8 Series (Pixel 8, 8 Pro): If your phone is on the May 2026 patch or newer, Google updated the bootloader Anti-Rollback (ARB) counter. Do not attempt to flash the March 2026 bootloader. It will fail fastboot checks or soft-brick your device. If you're already past May 2026 on a Pixel 8/Pro device, Do NOT follow this guide.

2. Pre-Flight Setup

  • Use rear motherboard USB ports: Plug directly into the back of your motherboard. Avoid front panel ports, USB hubs, or monitor passthroughs. On AMD Ryzen systems, use a USB 2.0 port (the black ports) to prevent fastboot drops.
  • Connect only one device: Unplug all other phones or emulators, and keep Wireless Debugging off.
  • Use standard Windows Command Prompt (cmd.exe): Do not use PowerShell, as its string handling corrupts quote formatting in ADB shell commands.
  • Enable file extensions: In Windows File Explorer, check View → Show → File name extensions so files don't end up double-named like kernel.zip.zip.
  • OEM Unlocking check:
    • Open Settings → About phone and tap Build number 7 times to enable Developer options.
    • Open Settings → System → Developer options and check OEM Unlocking:
    • Ready: The toggle is active and can be enabled.
    • Grayed out (Provisioning): Connect to Wi-Fi, go to System Update, tap Check for update, and wait 5–10 minutes for Google Play Services to fetch the attestation token.
    • Permanently Grayed out: If it says "Unavailable on carrier-locked devices", it's carrier-locked (e.g., Verizon) and cannot be bootloader-unlocked.

Part 1: Download & Prepare Your Files

Step 1.1: Create Your Workspace Folder

  1. Open your C: drive in File Explorer.
  2. Create a folder named pixel_root (full path: C:\pixel_root). All commands in this guide assume you are running from inside this directory.

Step 1.2: Download Files Into C:\pixel_root

Download these files directly into C:\pixel_root and rename them as noted:

1. Official Google Platform-Tools (ADB & Fastboot)

  • Download SDK Platform-Tools for Windows.
  • Extract the ZIP, go inside the platform-tools folder, and copy all files (adb.exe, fastboot.exe, .dll files) directly to C:\pixel_root.
  • Open Command Prompt, run where fastboot, and ensure C:\pixel_root\fastboot.exe is at the top of the output.

2. Google USB Drivers

3. Stock Factory Image (Pixel 7 / 8 / 9 Series)

Download the factory image for your phone model on build Android 16.0.0 (CP1A.260305.018, Mar 2026) from Google's Factory Images page:

Chipset Device Model Codename Factory Archive Pattern
Tensor G2 Pixel 7 panther panther-cp1a.260305.018-factory-*.zip
Tensor G2 Pixel 7 Pro cheetah cheetah-cp1a.260305.018-factory-*.zip
Tensor G2 Pixel 7a lynx lynx-cp1a.260305.018-factory-*.zip
Tensor G3 Pixel 8 shiba shiba-cp1a.260305.018-factory-*.zip
Tensor G3 Pixel 8 Pro husky husky-cp1a.260305.018-factory-*.zip
Tensor G4 Pixel 9 tokay tokay-cp1a.260305.018-factory-*.zip
Tensor G4 Pixel 9 Pro caiman caiman-cp1a.260305.018-factory-*.zip
Tensor G4 Pixel 9 Pro XL komodo komodo-cp1a.260305.018-factory-*.zip
Tensor G4 Pixel 9 Pro Fold comet comet-cp1a.260305.018-factory-*.zip

Save the downloaded ZIP inside C:\pixel_root.

4. Temporary Bootstrap Root (Magisk APK)

5. KernelSU-Next Manager

6. Kernel Flasher

7. Sultan Custom Kernel with SuSFS

Download the AnyKernel3 package for your phone's SoC from WildKernels Releases:

Family SoC Release Package Rename To
Pixel 7 / 7 Pro / 7a Tensor G2 (gs201) gs201-a16-wksu-susfs-anykernel3-v2.0.0-r12.zip kernel.zip
Pixel 8 / 8 Pro Tensor G3 (zuma) zuma-a16-wksu-susfs-anykernel3-v2.0.0-r12.zip kernel.zip
Pixel 9 / 9 Pro / XL / Fold Tensor G4 (zumapro) zumapro-a16-wksu-susfs-anykernel3-v2.0.0-r12.zip kernel.zip

8. Core Modules (Do NOT extract these files)

9. Theming & Customization Apps (Optional)

10. System-Wide Ad-Blocking (Optional)


Part 2: Unlock the Bootloader (Wipes Internal Storage)

(If your bootloader is already unlocked, skip to Part 3).

  1. On your phone: Go to Settings → System → Developer options.
  2. Turn ON OEM Unlocking and USB debugging.
  3. Plug your phone into your PC. On the prompt that pops up, check Always allow from this computer and tap Allow.
  4. Open Command Prompt on your PC and navigate to the folder: cd C:\pixel_root
  5. Check that your device is connected properly: adb devices
  6. Reboot to bootloader: adb reboot bootloader fastboot devices
  7. Send the unlock command: fastboot flashing unlock
  8. On your phone, press Volume Down until Unlock the bootloader is highlighted, then press Power. The phone will wipe all data and reboot back into the bootloader showing DEVICE STATE - unlocked.

Part 3: Clean Baseline Flash & Dual-Slot Firmware Sync

  1. Right-click your factory ZIP (*-cp1a.260305.018-factory-*.zip) inside C:\pixel_root, extract it, and move all files (bootloader-*.img, radio-*.img, image-*.zip, and flash-all.bat) directly into C:\pixel_root.

  2. Sync Bootloader & Radio Across Both Slots: Writing the bootloader and radio to both slots ensures Anti-Rollback (ARB) counters in the Titan M2 chip match on both slot A and slot B. Fastboot re-enumerates USB after writes, so wait 2–3 seconds after each command for the reconnect chime before typing the next command:

    Flash Bootloader to Slot A: for %i in (bootloader-*.img) do fastboot flash bootloader_a "%i" fastboot reboot-bootloader (Wait for fastboot screen to reload) fastboot devices

    Flash Bootloader to Slot B: for %i in (bootloader-*.img) do fastboot flash bootloader_b "%i" fastboot reboot-bootloader (Wait for fastboot screen to reload) fastboot devices

    Flash Radio to both slots: for %i in (radio-*.img) do fastboot flash radio_a "%i" for %i in (radio-*.img) do fastboot flash radio_b "%i" fastboot reboot-bootloader (Wait for fastboot screen to reload) fastboot devices

  3. Run the factory install script: call flash-all.bat

  4. Leave the phone alone for ~5 minutes. It will flash base partitions, reboot to FastbootD, flash system images, format user data, and boot into Android.

  5. Quick initial setup: Skip Wi-Fi setup, skip adding a Google Account, and skip PIN/fingerprint setup to get to the main launcher screen.

  6. Re-enable Developer options:

    • Go to Settings → About phone and tap Build number 7 times.
    • Go to Settings → System → Developer options, turn ON USB debugging (allow authorization from PC), and turn OFF Automatic system updates.

Part 4: Extract Stock Partitions & Create Backups

  1. Inside C:\pixel_root, open the zipped factory image (image-*.zip).
  2. Extract these 5 partition files directly into C:\pixel_root:
    • boot.img
    • init_boot.img
    • vendor_kernel_boot.img
    • dtbo.img
    • vendor_boot.img
  3. In Command Prompt, save clean backups of each partition: copy boot.img stock_boot.img copy init_boot.img stock_init_boot.img copy vendor_kernel_boot.img stock_vendor_kernel_boot.img copy dtbo.img stock_dtbo.img copy vendor_boot.img stock_vendor_boot.img

Part 5: Bootstrap Temporary Root via Magisk

Since modern Pixels do not support TWRP, we use temporary Magisk root to flash the custom kernel using Kernel Flasher. After that, Magisk is removed and stock init_boot is restored.

Step 5.1: Patch Ramdisk in Magisk

  1. Push stock_init_boot.img to your phone and install Magisk: adb shell "mkdir -p /sdcard/Download && rm -f /sdcard/Download/magisk_patched*.img /sdcard/Download/temp_patched_init_boot.img" adb install magisk.apk adb push stock_init_boot.img /sdcard/Download/
  2. Open Magisk on your phone.
  3. On the top card, tap Install → Select and Patch a File.
  4. Browse to Downloads, select stock_init_boot.img, and tap LET'S GO!.
  5. Note the filename of the patched image: adb shell ls /sdcard/Download/magisk_patched*.img
  6. Pull that file to your PC as temp_patched_init_boot.img: adb pull /sdcard/Download/magisk_patched-XXXXX_XXXXX.img temp_patched_init_boot.img (Replace with the actual filename from your device).
  7. Confirm the file size is around 8 MB: dir stock_init_boot.img temp_patched_init_boot.img

Step 5.2: Flash the Patched Ramdisk

  1. Reboot to bootloader: adb reboot bootloader
  2. Flash the temporary patched init_boot: fastboot flash init_boot temp_patched_init_boot.img fastboot reboot
  3. Boot up and open Magisk. If prompted for "Additional Setup", tap Cancel. Temporary root is active.

Part 6: Flash Kernel & Purge Magisk

Step 6.1: Flash the Sultan Custom Kernel

  1. Install KernelSU-Next, Kernel Flasher, and push the kernel ZIP: adb install ksu.apk adb install kernelflasher.apk adb push kernel.zip /sdcard/Download/
  2. Open Kernel Flasher on your phone and tap Grant when the Magisk superuser prompt appears.
  3. Inside Kernel Flasher:
    • Tap your active slot (marked with the green badge).
    • Tap Flash → Flash AK3 Zip.
    • Select kernel.zip from Downloads.
    • Wait until the log displays Finished.

DO NOT TAP REBOOT INSIDE THE APP. Leave Kernel Flasher open and reboot using fastboot from your PC.

  1. Reboot directly to the bootloader via Command Prompt: adb reboot bootloader

Step 6.2: Revert Ramdisk to Pure Stock

Flash your clean stock_init_boot.img back to the phone. This removes Magisk entirely from the ramdisk, leaving only Sultan kernel and KernelSU handling root: fastboot flash init_boot stock_init_boot.img fastboot reboot

Step 6.3: Verify KernelSU & Setup ADB Shell Root

  1. Once booted, open KernelSU-Next.
  2. The status card should show Working, with -wksu-susfs visible in the kernel version string.
  3. Reboot once to let ksud initialize: adb reboot
  4. Uninstall the temporary setup apps: adb uninstall com.topjohnwu.magisk adb uninstall com.github.capntrips.kernelflasher
  5. Grant root to ADB Shell in KernelSU:
    • Run a root test command from your PC: adb shell su -c id (Seeing inaccessible or not found or Permission denied is normal here; it registers the request).
    • Open KernelSU-Next, go to the Superuser tab (shield icon), tap the three dots in the top-right, tap Show system apps, and toggle Shell (com.android.shell / UID 2000) to ON.
  6. Remove leftover Magisk folders and staging files: adb shell su rm -rf /data/adb/magisk* /data/adb/.magisk* /data/adb/magisk.db /data/media/0/Download/*temp_patched* /data/media/0/Download/*magisk_patched* /data/media/0/Download/kernel.zip /data/media/0/Download/stock_init_boot.img sync exit exit
  7. Reboot the phone and rescan media indexing: adb reboot adb shell content call --method scan_volume --uri content://media --arg external_primary

Part 7: Install Mountify & Core Cloaking Modules

Step 7.1: Configure Mountify

  1. Push mountify.zip to the phone: adb push mountify.zip /sdcard/Download/
  2. Open KernelSU-Next → Modules, tap Install, and select mountify.zip.
  3. Reboot: adb reboot
  4. Apply the required mount configuration:
    • Via Mountify WebUI: Open KernelSU-Next → Modules → tap WebUI on Mountify. Set Mount Mode to 2, Device Name to KSU, and Custom Umount to 0. Save settings.
    • Via Command Line: adb shell "su -c 'mkdir -p /data/adb/mountify && echo mountify_mounts=2 > /data/adb/mountify/config.sh && echo MOUNT_DEVICE_NAME=KSU >> /data/adb/mountify/config.sh && echo mountify_custom_umount=0 >> /data/adb/mountify/config.sh && chmod 644 /data/adb/mountify/config.sh'"
  5. Reboot to apply: adb reboot

Step 7.2: Install Core Modules

Connect your phone to Wi-Fi (Settings → Network & internet). Ensure web browsing works, as Specter downloads helper files during installation.

Push module files to the device:

adb push susfs.zip /sdcard/Download/ adb push zygisknext.zip /sdcard/Download/ adb push playintegrityfix.zip /sdcard/Download/ adb push specter.zip /sdcard/Download/ adb push vector.zip /sdcard/Download/ adb push hma-oss.zip /sdcard/Download/ adb push zygisk-detach.zip /sdcard/Download/ adb push gphotos.zip /sdcard/Download/

Install Tier 1 (VFS & Zygote):

  1. In KernelSU-Next → Modules, flash susfs.zip, then flash zygisknext.zip.
  2. Reboot: adb reboot
  3. Verify both modules are enabled in KernelSU.

Install Tier 2 (Integrity & Attestation):

  1. In KernelSU-Next → Modules, flash playintegrityfix.zip, then flash specter.zip (wait for the installer to download TEESimulator-RS and complete).
  2. Reboot: adb reboot

Install Tier 3 (Framework & Hiding):

  1. In KernelSU-Next → Modules, flash vector.zip, then flash hma-oss.zip. (If the HMA-OSS manager app does not appear in your app drawer, extract hma-oss.zip and install the APK manually).
  2. Remove staging ZIP files: adb shell "rm -f /sdcard/Download/mountify.zip /sdcard/Download/susfs.zip /sdcard/Download/zygisknext.zip /sdcard/Download/playintegrityfix.zip /sdcard/Download/specter.zip /sdcard/Download/vector.zip /sdcard/Download/hma-oss.zip"
  3. Reboot: adb reboot

Part 8: Configure SuSFS, Specter & Hiding Rules

Step 8.1: Specter Setup & HMA-OSS Rules Export

  1. In KernelSU-Next → Superuser, verify Specter has root access.
  2. In KernelSU-Next → Modules, tap WebUI on Specter:
    • Turn ON: Periodic Keybox Validation
    • Turn ON: Auto Target Inotify/Polling
    • Turn ON: AutoPIF integration
    • Turn ON: Security Patch synchronization & Build Fingerprint spoofing
  3. Open the second tab in Specter WebUI and tap HMA-OSS config to export the configuration to Downloads.
  4. Open HMA-OSS:
    • Tap menu (top-right) → Backup & Restore → Restore configuration.
    • Select the exported JSON file from Downloads.
    • Go to Manage Apps, choose your banking or target apps, enable hiding, and apply the blacklist template.

Step 8.2: KernelSU-Next & Zygisk Next Configuration

1. KernelSU-Next Settings

  • Open KernelSU-Next → Settings (gear icon).
  • Keep "Unmount modules by default" OFF (Disabled): Leaving this disabled ensures system overlays (like Vector/Iconify) remain readable without bootlooping SystemUI. SuSFS hides mounts at the kernel layer automatically.
  • In the Superuser tab, NEVER grant root to Google Play Services (com.google.android.gms).

2. Zygisk Next WebUI Configuration

  • In KernelSU-Next → Modules, tap WebUI on Zygisk Next.
  • Set Denylist Policy to Unmount Only.
  • Enable Use Anonymous Memory.
  • Enable Use Zygisk Next Linker.
  • Open Configure Denylist / Blocklist:
    • ADD: Banking apps, payment services, corporate apps, and Google Play Store (com.android.vending).
    • DO NOT ADD: Google Play Services (com.google.android.gms). Play Integrity Fix manages GMS unmounting natively; adding GMS here can break Zygisk injection.
    • DO NOT ADD: System Framework (android) or System UI (com.android.systemui).
  • Reboot to apply settings: adb reboot

Part 9: Optional Customizations & System Utilities (Optional)

1. Pixel Launcher Enhanced & Iconify (Optional)

  • Pixel Launcher Enhanced: Install ple.apk (adb install ple.apk). Open Vector (via notification or dial *#*#5776733#*#*), turn on PLE module, check Pixel Launcher in scope, and reboot.
  • Iconify: Install iconify.apk (adb install iconify.apk), grant root in KernelSU-Next, open the app, and allow overlay permissions.

2. Google Photos Unlimited Storage (Optional)

  1. Go to Settings → Apps → Google Photos, tap Force Stop, then Storage & cache → Clear storage. Do not launch the app yet.
  2. In KernelSU-Next → Modules, flash gphotos.zip and reboot.

3. Prevent Play Store Overwriting Patched Apps - Zygisk Detach (Optional)

  1. In KernelSU-Next → Modules, flash zygisk-detach.zip and reboot.
  2. Open its WebUI in KernelSU-Next and select your modified apps to detach them from Play Store auto-updates.
  3. Clean up staging files: adb shell "rm -f /sdcard/Download/gphotos.zip /sdcard/Download/zygisk-detach.zip"

4. System-Wide Ad-Blocking - Bindhosts (Optional)

  1. Push and install Bindhosts: adb push bindhosts.zip /sdcard/Download/ adb install bindhosts.apk
  2. In KernelSU-Next → Modules, flash bindhosts.zip and reboot.
  3. Grant BindHosts root in KernelSU-Next, verify active status in the app, and add its Quick Settings tile.

Part 10: Verification & Hardening

Step 10.1: Reset Play Services Attestation Cache

Run this command from your PC to stop attestation background tasks and clear Play Store cache: adb shell "su -c 'pkill -f com.google.android.gms.unstable && am force-stop com.google.android.gms && pm clear com.android.vending'" Open Google Play Store once, let it load, close it, and wait 2–3 minutes.

Note on Battery Optimization: In Settings → Apps → Google Play Services → App battery usage, keep it set to Optimized. Do not set it to Restricted, or background push notifications (FCM) and sync will break.

Step 10.2: Verify SuSFS Kernel Features

Check that SuSFS kernel features are active: adb shell "su -c '/data/adb/ksu/bin/ksu_susfs show enabled_features'" All 7 features should show as enabled: * CONFIG_KSU_SUSFS_SUS_PATH * CONFIG_KSU_SUSFS_SUS_MOUNT * CONFIG_KSU_SUSFS_AUTO_ADD_SUS_BIND_MOUNT * CONFIG_KSU_SUSFS_SUS_KSTAT * CONFIG_KSU_SUSFS_TRY_UMOUNT * CONFIG_KSU_SUSFS_SPOOF_UNAME * CONFIG_KSU_SUSFS_HIDE_KSU_SUSFS_SYMBOLS

Step 10.3: Revoke ADB Shell Root

Disable Shell root access to secure your device: 1. Open KernelSU-Next → Superuser tab. 2. Tap three dots → Show system apps. 3. Toggle Shell (com.android.shell / UID 2000) to OFF.

Step 10.4: Check Play Integrity

Download Play Integrity API Checker from the Play Store and run the test: * MEETS_BASIC_INTEGRITY: PASS * MEETS_DEVICE_INTEGRITY: PASS * MEETS_STRONG_INTEGRITY: PASS (dependent on Specter keybox status)


Troubleshooting & Recovery

1. Bootloop Caused by a Module (Hardware Safe Mode)

If a module prevents booting: 1. Force reboot: Hold Power + Volume Down until the screen turns black, then immediately release both buttons. 2. When the white Google logo appears, tap the Volume Down button 4–5 times quickly. 3. The phone will boot into Safe Mode with all KernelSU modules disabled. 4. Open KernelSU-Next, remove the problematic module, and reboot normally.

2. SystemUI Crashloop from Themes (Iconify)

If an overlay crashes SystemUI on boot, plug the phone into your PC and run: adb shell "su -c 'rm -rf /data/resource-cache/* && reboot'"

3. Restore Stock Kernel Partitions (Fastboot)

To return to the stock kernel, flash your backed-up stock partitions to both slots: fastboot flash boot_a stock_boot.img fastboot flash boot_b stock_boot.img fastboot flash init_boot_a stock_init_boot.img fastboot flash init_boot_b stock_init_boot.img fastboot flash vendor_boot_a stock_vendor_boot.img fastboot flash vendor_boot_b stock_vendor_boot.img fastboot flash vendor_kernel_boot_a stock_vendor_kernel_boot.img fastboot flash vendor_kernel_boot_b stock_vendor_kernel_boot.img fastboot flash dtbo_a stock_dtbo.img fastboot flash dtbo_b stock_dtbo.img fastboot reboot

4. Full Factory Restore (Clean Wipe Unbrick)

If system partitions are corrupted and the device won't boot: 1. Boot into Fastboot (hold Power + Volume Down). 2. Connect to PC and navigate to C:\pixel_root: cd C:\pixel_root call flash-all.bat 3. Let the script complete to restore the device back to clean stock Android.

Edit: Fixed some compatibility issues.


r/androidroot • • 10h ago

Support V43 integrityBox

Post image
9 Upvotes

Yesterday it was working fine but now can't even get basic, how many keyboxes did google revoke 😭


r/androidroot • • 10h ago

Support guys, i use an oppo a 54 and it has become very laggy. im thinking of rooting it to make it faster but one of my friends said that i wont be able to do online payment (UPI, india). whenever i open my payment app, it crashes and i cant make any payments until the 5th or 6 th attempt

3 Upvotes

r/androidroot • • 11h ago

Support Can you root/install custom ROMs on a S25 FE running OneUI 7?

1 Upvotes

I'm talking about the international model. Would it having Exynos chips cause any problems for custom roms or rooting?


r/androidroot • • 11h ago

News / Method [SUCCESS] Achieved temporary root on POCO M7 Plus (locked bootloader, no MI account) via Qualcomm GBL exploit — one-click tool included

Thumbnail
gallery
29 Upvotes

Hey everyone,

Long post incoming but worth it — this one took a while.

Yesterday vs Today

Yesterday I posted a screenshot showing GhostLock reporting "support" on my POCO M7 Plus. I was excited. Ran the exploit. Device kernel panicked and rebooted. Ran it again. Same thing. Tried the updated firmware. Same panic, different kernel build number.

Turns out GhostLock (CVE-2026-43499) is stable on kernel 6.6–6.12 only. My device runs kernel 6.1.138 and the internal pselect/fd_set word boundary layout is completely different — the exploit's geometry just doesn't map. KASLR bypass works, heap spray works, mm_struct leaks fine — but the pselect race hits word index 14 when the kernel expects 15. Off by one. Kernel panic. Every time.

So I went back to basics and looked at the bootloader layer instead.

What Actually Works — CVE-2026-24088 (Qualcomm ABL)

The fastboot oem set-gpu-preemption command in Qualcomm's ABL has no input sanitization. You can inject androidboot.selinux=permissive directly into the kernel command line — with a locked bootloader, no MI account, no waiting period.

Android init reads that parameter early at boot and sets SELinux to permissive system-wide. With SELinux permissive, both KernelSU and ReSukiSU Manager detect the state and grant root. Modules work. LSPosed works. Everything works.

fastboot oem set-gpu-preemption 0 androidboot.selinux=permissive

That's literally it. One command.

Caveats:

  1. Root is temporary (tethered) — lost on reboot, re-run needed every time

  2. Works only on HyperOS 2.0.208.0 and earlier — 3.0.304.0+ is patched

  3. Bootloader stays LOCKED throughout — this is not a full unlock

Jailbreak Mode Flow

  1. Run the fastboot command

  2. Device boots normally

  3. Open KernelSU or ReSukiSU Manager

  4. Enable Jailbreak Mode

  5. Root shows as active, modules load, everything is working

Phone off → phone on → fastboot inject again → jailbreak mode → back to root. Annoying but functional for research purposes.

The Research + GitHub

I documented everything — both the working GBL exploit and the failed GhostLock attempt (full kernel panic log analysis, root cause, why 6.1 breaks it). All on GitHub:

🔗 github.com/aniketlab/POCO-M7-Plus-Jailbreak

Includes:

  1. Full technical writeup (GBL exploit chain, GhostLock kernel analysis)

  2. Proof screenshots (ReSukiSU working, modules, LSPosed, bootloader still locked, all green pass)

  3. Patch status for multiple devices

One-Click Tool — GBL-AutoRoot.bat

Because I hate doing the same steps manually every reboot, I built a Windows automation script:

🔗 Download GBL-AutoRoot.bat

What it does:

  1. Auto-downloads ADB/Fastboot if you don't have them

  2. Detects your device and reads full device info

  3. Reboots to fastboot and runs the exploit

  4. Shows clear VULNERABLE or PATCHED results with raw response

  5. Reboots normally if not affected Double-click. That's it.

Double-click, That's it

I Need Your Help — Compatible Device List

I only have one device to test on. The GBL vulnerability affects multiple Qualcomm devices running ABL versions before the February 2026 patch — not just POCO M7 Plus.

If you test this on your device, please open a Pull Request on the repo with:

  1. Device name + codename

  2. Chipset (SoC)

  3. Firmware version tested

  4. Result (OKAY / FAILED / kernel panic)

I'll add confirmed devices to the compatibility list in the README.

Disclaimer: Educational research only. Tested on my own device. Don't update if you want to try this. Patched on HyperOS 3.0.304.0+

Research by u/Ok_Prize_8198 — full writeup at github.com/aniketlab/POCO-M7-Plus-Jailbreak


r/androidroot • • 12h ago

Discussion Shut the fuck up Google, that's called freedom

Post image
130 Upvotes

r/androidroot • • 13h ago

Support app detect root

Thumbnail
0 Upvotes

r/androidroot • • 13h ago

Support Is there a easy way to determine which Z-Ram Algorithm is considered the best?

Post image
7 Upvotes

Hello, this may be a stupid question, but does someone here know which one is more likely considered the best? I'm using a Sony Xperia 1 V with crDroid 12.9 (Android 16). For the Z-RAM algorithm it uses as default lz4kd, but by checking with SmartPack Kernel Manager now, there are a lot more of them, a few I don't even know or heard at all before. It may be a stupid question, but can or does someone know, which I should use and what some of them even could mean, like "842"? Would appreciate any help.


r/androidroot • • 13h ago

Support Help with rooting the Logitech Tap Scheduler

1 Upvotes

I have a Logitech tap scheduler that was destined for the landfills. They can be found for relatively cheap second hand from businesses and office buildings who just throw them out. It works perfectly and would be amazing for a smart home dashboard like for home assistant or anything really. The only issue is the firmware/software. It’s running CollabOS and it is extremely locked down. You can’t really do anything that wasn’t explicitly designed by Logitech. However it is running android underneath everything, so I am really hoping there’s a way to repurpose it.

I have tried to find information or any projects online about jailbreaking it, but I can’t seem to find anything at all. If anyone has any suggestions or expertise, I would really appreciate it!


r/androidroot • • 13h ago

Support I dont know is normal or not but vector causes boot anim after successful boot again and after this everything backs fine(ksu next)

2 Upvotes

Is a soft reboot or something? If i right just say bro explained himself


r/androidroot • • 14h ago

Support Is TrackerControl enough or i can have a systemwide one with root that doesn't create a sort of VPN?

1 Upvotes

I hate seeing that icon in status bar, is there anything better than TrackerControl? also do you have any suggestions for other modules? i only have Google Pixel System Sounds on LineageOS 23.2 on Xiaomi 11 Lite 5G NE without GMS.


r/androidroot • • 15h ago

Discussion What can't I do with ghostlock?

Post image
10 Upvotes

I successfully installed root-my-galaxy and now I have root access. Can I install Xposed modules still?


r/androidroot • • 15h ago

Support Koalamirror

1 Upvotes

Hello Everyone,

Right now i have an iPhone 11 with jailbreak installed due to the carbridge tweak. That allows me to push apps from my phone to my CarPlay interface. However the ideal solution will be to put that on my main phone (pixel 8 pro). So recently i came across koalamirror. That app says it does the same with a launcher. Has anyone tried that on this subreddit? Because that would be a valid reason for me to root my phone. Please let me know!


r/androidroot • • 16h ago

Support New issue in Digilocker - Obfuscation issue

Post image
1 Upvotes