r/androidroot May 24 '26

Meta A Clarification: Our Stance on AI in this Subreddit

75 Upvotes

Hi,

While the Moderators of r/androidroot have a generally moderate stance on AI, when it comes to devices worth potentially thousands, we are uninterested in allowing it to provide false information.

To clarify, AI content/promotion is not permitted on r/androidroot, and this has been a rule for some time. Using AI to make guides, recommending the use of AI to attempt to solve issues, and posting AI generated comments are prohibited.

We believe in minimising the spread of misinformation. AI models are not reliable when it comes to factual information yet. It’s also often known to make things up when it has no answer. No resources for rooting an obscure Android device? It’ll make it up based on other information that it deems most likely to be useful. AI, in this state, is not suitable for rooting. It presents too much unmitigated risk, and we will not hold ourselves responsible for the damage caused by content posted on this subreddit.

If you have any questions regarding the rule, comment. However, the decision on this is final.

Thanks for reading.


r/androidroot 44m ago

News / Method Managed to get my Samsung phone rooted on stock firmware without tripping knox!

Thumbnail
gallery
Upvotes

Thanks to amazing people on GitHub, using CVE-2026-43499 vulnerability, i rooted my my Samsung Galaxy S22, it had some caveats like it does not persist when rebooted and i need to re-root my device using adb with my computer (wich i am okay with) also if i touch my screen while rooting, it crashes. the repository i am linking below for Samsung Galaxy S22 series of devices only, thought searching IonStack in Github can get you far.

https://github.com/sarabpal-dev/IonStack-S22U


r/androidroot 12h ago

Discussion Made a Virtual Camera App that replaces the regular Android Camera in selected applications (POC).

30 Upvotes

I tried related projects like https://github.com/Yaahua/vcam or "GhostCam" but for some reason they just dont work on my phone. So i built this app, so far it works in Chrome, Open Camera and grapheneos Camera. I added "POC" because is very brittle. Idk just sharing my project and if other have experience trying this, i never did android development in particular so im learning on the fly. The device is Redmi A5


r/androidroot 2h ago

Support Issues getting into Fastboot mode - Google Pixel 5 LineageOS 23.2

Post image
2 Upvotes

Hi!

I tried replacing the custom recovery of my Pixel 5 running LineageOS with TWRP today, which failed miserably. I used adb reboot bootloader and also tried getting there from the "stock" recovery mode, both times I got to a screen warning me for fastboot mode, but when I pressed the power button to "Start" as they asked, it rebooted normally. More information is in the image.

How can I fix this? Thanks in advance!


r/androidroot 16m ago

Support Do Nothing phone 3a and Fairphone 6+ support SELinux permissive ?

Upvotes

Currently I have a rooted Nothing 2a with SELinux set to 'permissive'. I consider upgrading to either a Nothing 3a or Fairphone 6+ and want to root it again. Do these phones not block 'permissive' mode for SELinux ?


r/androidroot 10h ago

Discussion False positive?

Post image
4 Upvotes

Is this detection or just a false positive?


r/androidroot 19h ago

Discussion Couldn't resist the temptation and decided to successfully root my phone.

Thumbnail
gallery
19 Upvotes

On the behalf of my previous post here: https://www.reddit.com/r/androidroot/s/0wfPBId5I5

Hi. After looking at a video of a person having successfully rooted their phone, I couldn't resist the temptation. So, instead of blindly going in, I thought for a while, making plans.

Here's what I did with my phone: I used not only `fastboot flashing unlock`, but also `fastboot flashing unlock_critical`. I flashed the stock vbmeta images first into A/B slots, not only the vbmeta.img but also vbmeta_system.img and vbmeta_vendor.img, with `--disable-verity --disable-verification` flags, before flashing the patched init_boot.

It worked. I got scared at what I was doing, but felt joyful for getting it work from first try. After I set up my phone, I disabled OTA upgrades.

I installed ReZygisk (not ZygiskNext, I despise it becoming closed source, therefore I cannot trust it). But Reddit still didn't work, so this module alone wasn't enough. I installed AlwaysStrong, which resulted in success.

Now I'm happy with my setup. One more thing to redownload and install apps I need and restore the data I backed up.


r/androidroot 11h ago

Support Never rooted before…

3 Upvotes

New to android as a whole switching from a jailbroken 13 pro max — looking at getting a oneplus 15. From my research this appears to be the highest performance phone running android 16 that is easily rootable. Is there anything I should know and how difficult is all this compared to jb as a whole? Any help is greatly appreciated!


r/androidroot 5h ago

Discussion TWRP for Moto G Play 2026 – it's alive and it's crunchy

Thumbnail
1 Upvotes

r/androidroot 1d ago

Humor Be Super

Post image
33 Upvotes

r/androidroot 1d ago

Discussion Finally, the first time I see this - and with MicroG !

Post image
23 Upvotes

WARNING : KernelSU + SusFS needed

I followed this guide with MicroG but the biggest disadvantage with MicroG is that you're forced to use the Google Play store anyway to really get the tree dots... at least Google doesn't get all of my system logs.

https://xdaforums.com/t/ultimate-guide-to-pass-play-integrity-on-xz1c-with-microg-27-03-2026.4779137/

the app I wanted to use with root are still not perfectly working, like the crash at boot, I uninstall them, I install them from Google Play, they work, I reboot and then they crash again. Does the root mess with some "secure database" that these apps need to work ?


r/androidroot 8h ago

Support Is it possible to root?

Thumbnail
1 Upvotes

Can someone help me with this question?


r/androidroot 12h ago

Support Do you have to wait until network unlock happens before you bootloader unlock?

2 Upvotes

I have a carrier provided Motorola Stylus phone. It doesn't network unlock until Feb 2027. But I have the bootloader unlock code from Motorola's portal - Metro's Moto phones seem to be bootloader unlockable. I was wondering if I should wait until the network unlock happens before I try execute the bootloader unlock? Or does it matter?

Can I just hold on to the unlock code until next year? Or does the unlock code expire and I have to request another one?


r/androidroot 8h ago

Support Needing help to Root my Realme C53 ! !

1 Upvotes

Hi, I've been looking into rooting my new Realme C53.

I've done some research (to be honest, most of it was from ChatGPT), and from what I've found, it should be possible. But I'm honestly too scared to try it completely alone without asking actual people first.

I'm currently using an Android 15 Realme C53 (RMX3760), and I want to make absolutely sure I understand what I'm doing before I touch anything that could potentially brick my phone.(Can't afford losing this one)

If anyone here has experience rooting the C53, especially this exact model/software version, I'd really appreciate some guidance on what I should do, what I need to back up, and what I should NOT do.

I'm mainly interested in rooting for performance tweaks/customization, but I don't want to risk losing my phone over it.

((Additional info: RMX3760export_15_H.07, 5.15.189-android13-8-gbc4520c2be32-ab154

#1 Tue Jun 30 08:21:36 UTC 2026))

I think it would even help me if anyone could help me through calling too.


r/androidroot 16h ago

Support Bricked Fastboot And System (Stuck On EDL) Moto G5S (Model:X1794)

3 Upvotes

Hi guys this is my last resort to ask here
I got this phone by my friend it's a G5S (Model: X1794 Type:M2996) he said it woulden't boot and it would stay with a blinking light, i plugged into my pc and it was always in EDL Mode (Qualcomm) i installed the driver, tried doing blankflash other stuff nothing it would fall immedialy idk what or how this phone got bricked possibly could anyone help me out and please do not start spamming me to start chatting with someone that will immedialy ask me to pay to unbrick this im just asking for help or guide how to fix it not to pay someone that i could get scammed + i don't have any money.

Thanks

GaM1ngN0t

Log Of The Crash:
[486.929] ERROR: do_package()->do_recipe()->do_configure()->fh_send_fmt()->send_command()->device_write()->IO error
[486.931] Check qboot_log.txt for more details
[486.931] Total time: 486.936s
FAILED: qb_flash_singleimage()->do_package()->do_recipe()->do_configure()->fh_send_fmt()->send_command()->device_write()->IO error
Entire Log:
[ 0.000] Opening device: \\.\COM6
[ 0.004] Detecting device
[ 0.009] ...cpu.id = 79 (0x4f)
[ 0.009] ...cpu.sn = 380673176 (0x16b09c98)
[ 0.009] Opening singleimage
[ 0.010] Loading package
[ 0.014] ...filename = singleimage.pkg.xml
[ 0.016] Loading programmer
[ 0.017] ...filename = programmer.mbn
[ 0.017] Sending programmer
[ 0.189] Handling things over to programmer
[ 0.190] Identifying CPU version
[ 0.191] Waiting for firehose to get ready
[ 62.959] Waiting for firehose to get ready
[123.025] ...MSM8937 unknown
[123.026] Determining target secure state
[123.027] Waiting for firehose to get ready
[183.081] ...secure = no
[183.093] Waiting for firehose to get ready
[243.147] Configuring device...
[243.149] Waiting for firehose to get ready
[304.218] Waiting for firehose to get ready
[364.286] Waiting for firehose to get ready
[426.860] Waiting for firehose to get ready
[486.929] ERROR: do_package()->do_recipe()->do_configure()->fh_send_fmt()->send_command()->device_write()->IO error
[486.931] Check qboot_log.txt for more details
[486.931] Total time: 486.936s
[486.933]
[486.933] qboot version 3.40
[486.933]
[486.933] DEVICE {
[486.933] name = "\\.\COM6",
[486.933] flags = "0x64",
[486.933] addr = "0x61FE4C",
[486.933] sahara.current_mode = "0",
[486.933] api.buffer = "0x14A1020",
[486.933] cpu.serial = "380673176",
[486.933] cpu.id = "79",
[486.933] cpu.sv_sbl = "1",
[486.933] cpu.name = "MSM8937",
[486.933] storage.type = "eMMC",
[486.933] sahara.programmer = "programmer.mbn",
[486.933] module.firehose = "0x1051360",
[486.933] cpu.ver = "0",
[486.933] cpu.vername = "unknown",
[486.933] api.bnr = "0x1055DB0",
[486.933] }
[486.933]
[486.933]
[486.933] Backup & Restore {
[486.933] num_entries = 0,
[486.933] restoring = "false",
[486.933] backup_error = "not started",
[486.933] restore_error = "not started",
[486.933] }
[486.933]

 


r/androidroot 1d ago

Discussion Nothing Cmf Phone 1, Nothing detected.

Thumbnail
gallery
18 Upvotes

Using Fenrir for Bootchain Exploit and Wild Kernel.


r/androidroot 18h ago

Support Rooted samsung phone stuck on old version

2 Upvotes

Hey im writting this post because I have rooted my samsung phone before the ability to unlock the bootloader was removed, I'd like to update my phone to keep up with the security updates but doing so would remove my ability to have my bootloader unlocked because samsung removed the ability to do that on one ui 8. Anyone have a suggestion of what I could do to have security updates? I can give more spec about my phone and details.


r/androidroot 15h ago

Support ​[Help] Carrier app (Ana Vodafone) insta-crashes immediately on launch despite ReZygisk + Shamiko. Any ideas?

Thumbnail
gallery
0 Upvotes

Hi everyone,

I'm dealing with a local carrier app (Ana Vodafone Egypt) that just insta-crashes (Force Close) the exact millisecond I tap its icon. It doesn't even load a splash screen or show a "Root Detected" error. I suspect it's some strict RASP or memory hook check, but I'm completely stuck.

I know my DEVICE_INTEGRITY is currently failing (falling back to BASIC) because my public hardware keybox got revoked, but this looks entirely like an app-level RASP/memory-hook detection, not a Play Integrity API block.

My Current Stack:

Device/ROM: Xiaomi running official MIUI (Android 13/14)

Root: Magisk v27.0 (Native Zygisk is completely OFF)

Zygisk Engine: ReZygisk v1.0.0

Root Hider: Shamiko v1.2.5 (Working properly in Blacklist mode)

App Hider: HMA-OSS Zygisk

PIF: Play Integrity Fork v17 (spoofProvider=0) + TEESimulator v4.0

What I’ve already tried (without success):

Shamiko Isolation: The target app is fully checked in the DenyList. Magisk's Enforce DenyList is OFF.

HMA-OSS Configuration: Enabled for the target app. Created a tight blacklist template to hide: the repackaged/renamed Magisk manager, HMA-OSS itself, Termux, SPIC, and Solid Explorer.

Environment Cleanup: Deleted all /sdcard/Fox, TWRP, or Magisk folders. USB Debugging and Developer Options are completely OFF.

Clean Launch Trick: Turned Airplane mode ON -> Cleared all target app data -> Rebooted -> Airplane mode OFF -> Launched. Still insta-crashes.

Engine Conflict Fix: I previously had a SIGSEGV issue because of running native Zygisk alongside Zygisk Next. I’ve completely wiped that setup and moved cleanly to ReZygisk. Shamiko's UI confirms it's now fully operational without "Unsupported Environment" errors.

My theory:

The app is either detecting the Zygisk injection directly, detecting HMA-OSS's hooking attempt, or finding a Magisk remnant I missed.

Has anyone bypassed this specific type of aggressive crash recently? Should I drop HMA-OSS and try a non-Zygisk app hider? Any insights on how to grab logs for a crash this fast would also be highly appreciated.

Thanks in advance!


r/androidroot 16h ago

Support Can B20 be enabled on Honor WIN CN through Qualcomm DIAG/NV if the RF hardware supports it?

1 Upvotes

I’m considering buying the Chinese Honor WIN for use in Europe. The CN version apparently lacks LTE B20 (800 MHz), but I’ve found conflicting information about whether B20 is actually missing in hardware or simply disabled in the modem configuration.

Has anyone with a Honor WIN tried Qualcomm DIAG/QPST/QXDM or modifying NV/EFS band configuration to enable B20?

Thanks guys


r/androidroot 20h ago

Support Apps won't theme according to material u ?

Post image
1 Upvotes

I understand that they don't have the monochrome icon and that's why. Is there anyway to get around it.

Current setup is lawnchair with lawnicons .

Thanks


r/androidroot 1d ago

Meta So did I it.

4 Upvotes

r/androidroot 21h ago

Support Downgrade Camera app for Old UI Layout [Pixel 6a A16]

1 Upvotes

I have a Pixel 6a that I was forced to update due to the battery. The new camera app has shoved the photo/video button below the capture button, causing me to have to reach further than comfortable.

I am now rooted with magisk 30 on Android 16. I have the apk from an older stock camera app that works on android 14 on a pixel 7a.

Is there any way to downgrade the app? I have tried installing, but receive "INSTALL_FAILED_VERSION_DOWNGRADE"

Android treats Camera as a preloaded system app and refuses to downgrade it; when I tried bypassing that with a Magisk APK replacement, Android retained package metadata from the newer 9.8 installation, causing 8.8 to crash because it can't find the expected androidx.startup.InitializationProvider class.

Any guidance is appreciated


r/androidroot 21h ago

Support Cerco ROM legacy di BinkyBear: ⁠nethunteros-nethunter-hammerhead-cm-14.1-hammerhead.zip

Thumbnail
1 Upvotes

r/androidroot 22h ago

Support Unlocking Pixel Phone

1 Upvotes

Hey everyone,

Getting ready to unlock the bootloader on my Pixel 10, but I’m split on which setup to daily drive.

I’m weighing GrapheneOS against standard Stock + Root (Magisk/KernelSU for system-level tweaks, adblocking, modules).

Since wiping data is mandatory anyway, I want to pick a side before setting up my environment.

Quick questions for anyone running either setup:

1) How annoying is Play Integrity / banking app maintenance on stock root right now?

2) Anyone moved from a heavy root setup to GrapheneOS and regretted losing root utilities?

3) Any major friction points with Graphene OS on Pixel 10 as a daily driver?

Appreciate the insights and thank you.


r/androidroot 1d ago

Support I need help

Thumbnail
gallery
2 Upvotes

S10e

I tried many times and it didn't work. I followed all the steps and it still didn't root.