Forwarded from LSPosed
This media is not supported in your browser
VIEW IN TELEGRAM
We discovered a privileged process arbitrary code execution vulnerability in Android 17. This vulnerability was patched in Android 17 QPR1 but was not included in any security bulletin. Combined with the dirty frag vulnerability (CVE-2026-43284), we achieved full root privilege escalation on Android 17.0.
The DirtyFrag vulnerability was disclosed 3 months ago but is still exploitabe, because Google has delayed the release frequency of vulnerability patches, changing from monthly to quarterly security bulletins. In the AI era, this behavior is completely incomprehensible. A large number of devices in the Android ecosystem are vulnerable to attacks due to the vulnerability details leaked in the Pixel system; even Pixel devices not participating in the beta program are not immune.
Therefore, we used two "already patched" vulnerabilities to demonstrate full rooting on Google Pixel 10 with the latest patches as a warning, urging Google to change its practices and release vulnerability patches promptly.
The DirtyFrag vulnerability was disclosed 3 months ago but is still exploitabe, because Google has delayed the release frequency of vulnerability patches, changing from monthly to quarterly security bulletins. In the AI era, this behavior is completely incomprehensible. A large number of devices in the Android ecosystem are vulnerable to attacks due to the vulnerability details leaked in the Pixel system; even Pixel devices not participating in the beta program are not immune.
Therefore, we used two "already patched" vulnerabilities to demonstrate full rooting on Google Pixel 10 with the latest patches as a warning, urging Google to change its practices and release vulnerability patches promptly.
Forwarded from LSPosed
GitHub
GitHub - LSPosed/LSPromise: Android complete exploit chain that enables privilege escalation from a local untrusted app to root/kernel…
Android complete exploit chain that enables privilege escalation from a local untrusted app to root/kernel, combination of CVE-2026-49881 and CVE-2026-43284 - LSPosed/LSPromise
Forwarded from 𝑨𝒎𝒓 𝑮𝒂𝒎𝒂𝒍 𝑺𝒕𝒐𝒓𝒆 (𝑪𝒍𝒐𝒖𝒅) (Karpov𝕏ek)
XiaomiDialerPort-v0.3.zip
38.9 MB
Xiaomi Dialer & Contacts port (HyperOS 3) for AOSP
Ported by Islam AlorabI
Telegram: @IslamAlorabI
Channel: @Shadow6by8
• Install: KernelSU / Magisk module (requires a mount metamodule on KernelSU 3+)
• It should work on Android 15/16; otherwise, it is unknown and requires your testing. Set the "Phone" app as default to ensure it works properly.
Ported by Islam AlorabI
Telegram: @IslamAlorabI
Channel: @Shadow6by8
Source: Xiaomi 15 Global, HyperOS 3.0.303.0 (Android 16)
• Install: KernelSU / Magisk module (requires a mount metamodule on KernelSU 3+)
• It should work on Android 15/16; otherwise, it is unknown and requires your testing. Set the "Phone" app as default to ensure it works properly.
Note: This is a test build intended for testing and is not yet stable for daily use. Test everything and report bugs with logs
Forwarded from шинко
https://github.com/mitschud/DirtyFrag
Рут на любой телефон без прошивки, патч безопасности должен быть до лета 26
6.1-Android14 НЕ ВОРК
Рут на любой телефон без прошивки, патч безопасности должен быть до лета 26
6.1-Android14 НЕ ВОРК
GitHub
GitHub - mitschud/DirtyFrag: Ephemeral root via the CVE-2026-43284 page-cache exploit
Ephemeral root via the CVE-2026-43284 page-cache exploit - mitschud/DirtyFrag
yukiteru
https://github.com/mitschud/DirtyFrag Рут на любой телефон без прошивки, патч безопасности должен быть до лета 26 6.1-Android14 НЕ ВОРК
GitHub
GitHub - YuKongA/ghostlock-app: GhostLock One-Tap Execution App (CVE-2026-43499)
GhostLock One-Tap Execution App (CVE-2026-43499). Contribute to YuKongA/ghostlock-app development by creating an account on GitHub.
yukiteru
https://github.com/YuKongA/ghostlock-app
тут берете ссылку на зеркало вашей рекавери прошивки,и по ссылке можете извлечь
❤2
Forwarded from салзи лох кот лох
перезагрузкой зафиксится же да?
❤1
Forwarded from салзи лох кот лох
так бутлуп перезагрузкой фикситчя
❤2