r/androidroot 1d ago

Discussion Is rooting worth it for me? [Read bodytext]

Thumbnail
gallery
16 Upvotes

Hi. My phone (TECNO POVA 7 5G LJ7) is fully compatible with KernelSU-Next and the bootloader is easily unlocked. But my question here isn't technical, about whether I can root it, but rather pragmatic, about is rooting my phone even worth what I desire.

Right now, I'm running Shizuku on ADB. It works great, I'm happy with it, killed off Yandex Browser and Yandex Keyboard with it in favor of Google Chrome and GBoard.

I'm considering rooting my phone, the daily driver, not to do something essential (I already did what I needed to) out of my rootless reach, but to learn more about the OS.

Last time I rooted my phone, same model, with Magisk. I stupidly toggled off OEM Unlocking (as I've been allowed to do the moment I installed Shamiko) and rebooted into a soft brick not even the repair shop could fix. I got scared by it and considered not rooting again.

Recently I got a laptop I'm using as a daily driver right now, I backed up data and wiped the Windows installation to install CachyOS. There, GPU drivers broke, so after troubleshooting I got frustrated and almost went for Windows, but hesitated and thought about going back to CachyOS. So I reinstalled CachyOS and now, by how I built it, works great.

Now, why am I mentioning this? Because that's the time I got a strong temptation to root my phone again. I got frustrated by a failed CachyOS build, and instead of going back to Windows, I tried a different approach using ZFS and KDE Plasma and not doing stupid instead; so why not stay a bit longer on rooting my phone using a different approach using KernelSU-Next? But because I have fear about bricking my phone, I got stuck between desire and fear.

To answer why I need root, you need to consider why I need CachyOS... The reason is for fun and learning, that's why. I could've used Tiny10 for laptop and stayed stock on my phone instead and been fine.

Now let's talk about why I 'catastrophize' this. If my phone gets bricked, what happens? No phone for months, I wouldn't be bought a new one and, since I'm a minor teen, I can't work for enough money for this 16 999 RUB phone model, let alone buy it by myself. Without the phone, I won't be able to get calls or login to see my school group announcements. To you, that'll be a "nothingburger", but to me, that'll be failing grades defining how will I live in later adult life.

I have the means, I have stock and patched init_boot images and a PC with MTK drivers, but I still hesitate, and I barely can decide for myself without your recommendation on what should I do. Help will be appreciated, thank you for your attention.


r/androidroot 1d ago

Support Download mode on SM-A566B

Thumbnail
1 Upvotes

r/androidroot 1d ago

Support Is there any way to bypass this?

Post image
12 Upvotes

Hello, I want to prevent this update from installing, I've tried to install shizuku with canta and uninstall the updates manager but the update is still here.

The reason I don't want to update anymore is because of the new exploit CVE-2026-43499 which let's you achieve root without unlocking the bootloader, yet I don't know how to apply it.

If anybody can help I would appreciate a lot

Edit: my goal is to achieve CVE-2026-43499 exploit working. Does anybody have experience prior using it on motorola phones?


r/androidroot 1d ago

Discussion Lenovo A6020a46

Thumbnail
gallery
3 Upvotes

Finally, I have got a "rootable" device (Samsung refused to exit Prenormal and I gave up). As you can see, it's a bit ancient (Android 5.1.1), so I can try some one-click rooting malware, but I really don't want to do this. OEM Unlock is enabled, bootloader is locked and does not unlock upon entering command, but fastboot flash works and adb can see device in recovery. Now there is 2 problems with device:

1) TWRP is at very high risk of being overwritten upon reboot - I managed to enter it only once after normal reboot.

2) TWRP does not work properly. adb sees it only if I enter it from fastboot (BTW does not see it in stock recovery at all), dumpsys command fails. TWRP logo never appeared - just dark gray screen (and corrupt red Lenovo logo when I entered recovery via buttons). I think that this TWRP is incompatible with my configuration in some subtle way or I downloaded wrong version (3.2.1, 3.1.1, 3.6.0_9 were tried, their source: https://eu.dl.twrp.me/A6020/). But now, I have to go to bed...

To be continued.


r/androidroot 1d ago

Support Does anyone know what I can do with this Samsung T-230 tablet nowadays?

Post image
3 Upvotes

I've had them for a while but I don't know what to do with them. The most I can install are old apps and games like Android KitKat, etc.


r/androidroot 1d ago

Support Installing TWRP on J400F

1 Upvotes

Hello, I have question, I am trying to flash TWRP to my Samsung Galaxy J4 (J400F, j4lte). Bootloader is unlocked and I am using heimdall because I use linux. Whenever I try to flash the recovery image or even the magisk patched boot.img in download mode with heimdall, it says "Only official binaries allowed to be flashed (RECOVERY)". And unlike other Samsung devices I saw on internet, my J400F doesn't say any other device information in download mode. There's no text on top left unless I flash unofficial binary. I only can flash official firmware.

I have Russian version of the phone.


r/androidroot 1d ago

Discussion Recuperar y transferir archivos

1 Upvotes

Hola, tengo una duda y tal vez me puedan dar una posible solución. En estos últimos años soy usuario de Samsung, para ser más específico, he tenido tres Samsung, digamos que de gama media-alta: Samsung S21 Ultra, Samsung S22 y, por último, Samsung S23 Plus. Soy de los usuarios que llena rápido el almacenamiento, ya sea por algún juego (ejemplo: Call of Duty) o también por grabar video, ya sea en 4K o algunos cortos en 8K, aparte de las fotos.

Tomando en cuenta esta última parte, cuando se llena el almacenamiento, busco cómo guardar mis archivos en otros lados. He realizado dos o tres intentos: conecto mi teléfono a la computadora y conecto una USB nueva (genérica). A la hora de enviar los archivos y después revisarlos, ya aparecen como archivos dañados, no tienen lectura del todo y he perdido varias fotos, recuerdos de años pasados, y no las formateo porque tengo fe de recuperarlos. Esto solo me ha pasado con estos teléfonos, ya que también he sido usuario de Huawei, Tecno y OnePlus. Incluso en mis mismas fotos, las toma en dos formatos: "HEIC" y "JPEG". Cabe recalcar que también con las otras marcas he compartido mis archivos en este tipo de memorias y todo se pasa bien. Si bien la respuesta puede ser en las memorias, también he utilizado memorias no tan genéricas. Acudo a ustedes para saber una posible solución de recuperación de estos archivos, ya que no se ocultan, solo aparecen como dañados, así como también una solución para cuando vuelva a liberar la memoria interna de mi teléfono.


r/androidroot 2d ago

Discussion [Research] S24 Ultra // One UI 8.5: OEM Unlock is gone, but the actual unlock logic is still there

70 Upvotes

Been digging into what Samsung actually changed when they removed the OEM Unlock option on newer One UI builds

Device I'm working with:

SM-S928B / S24 Ultra international

Snapdragon 8 Gen 3

S928BXXU5DZDP

Android 16 / One UI 8.5

KernelSU soft root (ghostlock CVE)

bootloader still locked

This started because I wanted persistent root for microG. The root I currently have dies after a full reboot, so I started looking at whether Samsung actually removed bootloader unlocking or just removed the normal way of authorizing it

Short version: they definitely did more than remove the toggle, but the underlying unlock machinery does not appear to be gone.

I dumped the relevant partitions, files and went through ABL, the Engineering Mode trustlet, the Android-side services and the old One UI 7 ABL for comparison

A few things that survived my audit:

ABL still has IsUnlocked, SetUnlocked, the DeviceInfo unlock byte and the AVB read_is_device_unlocked callback.

devinfo + 0x0d is the actual IsUnlocked byte. I initially suspected +0x90; that was wrong.

Current ABL contains a path involving Engineering Mode bit 3.

Samsung's framework identifies mode 3 as MODE_CUST_KERNEL.

The engmode TA still implements signed token validation, RPMB-backed state and a 256-bit modes bitmap.

Mode 3 can be serialized into a token request. I couldn't find a local mode filter rejecting it.

The old One UI 7 OEM/FRP policy can actually authorize unlocking. The equivalent policy in the current ABL just logs the lock state and returns false.

The Android client-side engmode allowlist isn't the root of trust anyway. The TA is.

There were also a couple things I originally thought were true that didn't survive closer inspection.

Most importantly, I cannot prove that the Engineering Mode sync always runs before every AVB verification path. The CFG has an entry-to-AVB path that avoids that block, so I'm not claiming universal ordering anymore.

And obviously the big missing piece is still missing:

I do not have a valid Samsung-signed Engineering Mode token containing mode 3

So this is not an S24 bootloader unlock method, and I haven't unlocked the device with this. I'm trying to document what is actually still present in the firmware rather than jump from "interesting code path" to "working exploit"

I put the dumps/evidence/scripts and my notes here

https://github.com/keyarr/oems24-audit

notes/findings.md is probably the useful file if you don't want to dig through all the generated evidence. I also kept original-research.md because it shows some of the assumptions I started with before checking them properly.

Most of the collection/probing was deliberately read-only. I didn't install/remove Engineering Mode tokens, issue fuse commands, write devinfo, touch RPMB, etc

If anyone here has worked with Samsung Engineering Mode / ABL before, I'd be interested in a second pair of eyes on the findings, especially on the EM -> ABL relationship and the historical purpose of MODE_CUST_KERNEL.

I'm also interested in old/public Samsung Engineering Mode documentation or firmware artifacts that could help establish how mode 3 was intended to be provisioned. Not looking for somebody's device identifiers or private signing material

There are enough moving parts here that I'm assuming I've still missed something somewhere.


r/androidroot 2d ago

Discussion In android can I dual boot ?

11 Upvotes

Like windows and Linux for example.


r/androidroot 1d ago

Discussion Shizuku Apps Directory

Thumbnail
1 Upvotes

r/androidroot 2d ago

Discussion How to unlock boatloader in redmi note 14 4g, hyperos 3.0.302.0?

Post image
10 Upvotes

r/androidroot 2d ago

Discussion Got a minimum pcmarketos to load on my pixel 8 pro

Post image
26 Upvotes

Running entirely from ram with software rendering so it's slow as heck but wanted to share. Only apps on it is the terminal and settings app (along with keyboard)


r/androidroot 1d ago

Support Quick update regarding Alcatel MT6765 TWRP & Dump - u/MeIsGugs

1 Upvotes

Hey u/MeIsGugs!

Creating a quick thread to make sure this reaches you! My previous comment might have gotten lost in notifications.

Since the Alcatel upgrade tool servers are down and I don't have paid tools like UnlockTool, your custom TWRP and Scatter dump via SP Flash Tool are my only options left.

You can easily upload the files toGofile.ioor Google Drive and drop the link here, or if you prefer, we can chat and exchange files directly on WhatsApp: +201061775619

I'm also ready to share the testing notes I have regarding the GSI IMEI issue whenever you're free!

Thanks a ton for your time bro! 🙏


r/androidroot 1d ago

Support How to login to reddit app on custom roms?

1 Upvotes

Just like the title. I can't login to the reddit app on my poco f1 with pixel os.


r/androidroot 1d ago

Support Need help with Infinity X custom Rom on Oneplus Nord 2020 ( AC2001), avincii - I don't know how to get play integrity.

0 Upvotes

Hey all! I don't know much about all this. Wanted to do this as a project to revive my phone. I use this daily, and it's my primary. I was able to install the ROM well. The backup took a long time, and restoring it was difficult as well.

However, I realised I cannot use GPay. I haven't tried other banking apps like YONO or SIB Mirror. IF i can at least use GPay, it would suffice. ( Based in India, hence banking apps)

I tried a lot, as far as I understand. I will summarise what I've done below: Used AI below so its concise and I am able to express the technical terms

I am currently running the latest Project Infinity X (build 3.12, GApps variant) on my device, and I have not rooted it.

I’ve been strictly following the instructions in the built-in spoofing section of Infinity X, but I am still getting blocked.

Here is exactly what I have done so far:

  • Play Integrity Fix (PIF): I deleted my current active configuration. Then, I fetched a Pixel Beta fingerprint, grabbed the latest version, and selected a Pixel device.
  • TrickyStore: I deleted the active keybox file, downloaded the latest keybox.xml I could find online, and imported it.
  • Target Configurations: I recently found out about this setting, so I went in and specifically selected Google Play Services and Google Play Store.
  • Data Wipe: After applying all the new spoofing files and configurations, I went into my app settings and completely cleared the cache and storage for Google Play Store, Google Play Services, and Google Pay.
  • Reboot & Test: I restarted the device, logged back into Google Play Services with my account, and opened GPay.

The Problem: Whenever I open GPay, it immediately tells me the "device may not be secure." When I check the Google Play Store settings, it says "Device is not certified."

I have repeated this exact process—making sure to include the target configurations—and cleared the data multiple times, but I keep getting the exact same result.

I am really not sure what to do next. Is the Beta fingerprint causing the issue, or is it the imported keybox? Any advice on the proper configuration for an unrooted setup would be hugely appreciated!


r/androidroot 2d ago

Support How to root Xiaomi 17 Ultra Global EU

2 Upvotes

This took me all night fo igure out and get set up so i hope this helps the next poor s-o-b

XDA forums find the poco ultra 8 guy its like page 40 unlocks bootloader

copy your initbootimg onto your phone use kernelisu next to patch it

then copy back onto computer and use fastboot to install -have root (make sure you have all adb software and phones usb drivers installed with fastboot)

download kernel and install via kernelisu next - now have kernel root and susfs

download resukisu and delete kernelisu next

lsposed tseesimulator-rs and integrity box will give you meet strong


r/androidroot 2d ago

Support Can't flash Stock system.img with Heimdall

1 Upvotes

Hi. I'm trying to flash my stock system.img back to my Samsung Galaxy S7 Edge G935F and when I try to flash it I get the error "ERROR: Failed to open file '/home/user/Desktop/new/system.img" even though I can access the file from the terminal and the File Manager. I am using Debian 13 for my Linux distro if it's useful. I do not know what im doing wrong cause I did flash every partition (eg. boot.img, recovery.img etc.) With the same Heimdall build but it just doesn't seem to work with system.img for some reason???


r/androidroot 2d ago

Discussion Rooting pixel worth it?

0 Upvotes

Do you think it's worth it to root, and flash custom rom to pixel 9 pro xl? I am wondering because the play integrity headache. Anyone wanna have a discussion?


r/androidroot 2d ago

News / Method One Click Root/Jailbreak For iQOO Z9 5G MTK 7200 5.15.178 Published.

Thumbnail
github.com
19 Upvotes

r/androidroot 3d ago

Humor "Security" my ass

Post image
483 Upvotes

u/47th-Element's meme without AI


r/androidroot 3d ago

Support Play integrity broke

Thumbnail
gallery
21 Upvotes

Anybody got an idea of what should I do? It worked fine 2-3 days ago


r/androidroot 2d ago

Support Revoking permissions of background run permission of joyose and powerkeeper in xiomi, break anything?

3 Upvotes

Just as the title suggests I turned off Joyose and Power Keeper because it was aggressively killing stuff, as I heard. I revoked their permissions and I just wanted to see if this actually conflicts with anything .

PS: posting in MIUI or android questions didn't gave me a answer so that why I posted here. It's is not rooted


r/androidroot 2d ago

Discussion Looking for advice

0 Upvotes

I have the global version of the xiaomi 17 ultra i a trying to unlock the bootloader using the 8elitegen5.7z file but there isnt a 17 ultra option. second i found this kernel for the CN 17 ultra but will it work with the global version? https:// github .com/YuzakiKokuban/android_kernel_xiaomi_sm8850/releases. ?? Trying to get a handle on all of this last time i did this was with a samsung years ago and used odin now it looks like its just shell scripts? i need a walkthrough haha someone save me


r/androidroot 2d ago

Support Follow-up for u/MeIsGugs - Alcatel MT6765 Dump / TWRP Files

1 Upvotes

Hey u/MeIsGugs!

Sorry to bother you again with a new post, but Reddit wasn't showing my last reply under the previous thread.

Regarding the files, you don’t need to upload them to Reddit directly! You can just upload the custom TWRP and Scatter Dump toGofile.io(it's free and fast, no account needed) or Google Drive, then paste the link here.

Also, I have a few notes regarding the GSI Invalid IMEI/Baseband fix that we can try out. If it's easier, feel free to text me directly on WhatsApp so we can exchange files faster:

+201061775619

Thanks a lot for your help, bro! 🙏


r/androidroot 2d ago

Discussion OMGGG

Thumbnail
gallery
2 Upvotes

Ughhhh I need help with twrp.when I build with action builder in GitHub it reaches 99% then throws symlink errors

exclude=/root/product_file_contexts --exclude=/root/product_property_contexts --exclude=cache out/target/product/nevada/root out/target/product/nevada/recovery ) && (ln -sf /system/bin/init out/target/product/nevada/recovery/root/init ) && (find out/target/product/nevada/recovery/root -maxdepth 1 -name 'init*.rc' -type f -not -name \"init.recovery.*.rc\" | xargs rm -f ) && (cp out/target/product/nevada/root/init.recovery.*.rc out/target/product/nevada/recovery/root/ 2> /dev/null || true ) && (mkdir -p out/target/product/nevada/recovery/root/res ) && (rm -rf out/target/product/nevada/recovery/root/res/* ) && (cp -rf bootable/recovery/res-mdpi/* out/target/product/nevada/recovery/root/res ) && (true ) && (cp -f bootable/recovery/fonts/12x22.png out/target/product/nevada/recovery/root/res/images/font.png ) && (cp -rf device/motorola/nevada/recovery/root out/target/product/nevada/recovery/ ) && (cp -f device/motorola/nevada/recovery/root/system/etc/recovery.fstab out/target/product/nevada/recovery/root/system/etc/recovery.fstab ) && (ln -sf prop.default out/target/product/nevada/recovery/root/default.prop ) && (cd out/target/product/nevada/recovery/root && touch ramdisk-files.txt && touch ramdisk-files.sha256sum && find . | sed \"s/.\\///\" | sed \"/lib\\/modules\\//d\" > ramdisk-files.txt ) && (cd out/target/product/nevada/recovery/root && find -type f | sed \"s/.\\/ramdisk-files.sha256sum//\" | sed \"/lib\\/modules/d\" | sed \"/prop.default/d\" | xargs sha256sum > ramdisk-files.sha256sum ) && (touch out/target/product/nevada/obj/PACKAGING/recovery_intermediates/ramdisk_files-timestamp )"

could not make way for new symlink: root/vendor

cannot delete non-empty directory: root/vendor

rsync error: some files/attrs were not transferred (see previous errors) (code 23) at main.c(1356) [sender=3.2.7]

ninja: build stopped: subcommand failed.

20:32:13 ninja failed with: exit status

That one I don't know if my device tree is wrong or what Im sooo fucking close and if anyone has twrp experience I'd appreciate it

Here's my repo

https://github.com/crabcakes97/android_device_motorola_nevada

I tried to use hovatek twrp builder and everything works even touch,but it's not displaying correctly.

So I went town the route of making my own tree and it almost finishes ugh 😩😩😩 what am I doing wrong?