Skip to content
KitploitKITPLOIT
أدواتالمدونة
Log in
إرسال
أدواتالمدونة
إرسال

أدوات الاختراق واختبار الاختراق والأمن السيبراني لترسانتك الأمنية!

Kitploit هو دليل لأدوات الاختراق والأمن السيبراني واختبار الاختراق. اكتشف آخر تحديثات المشاريع للعثور على الثغرات وتحليل الأنظمة وأتمتة الاختبارات وتعزيز أمنك.

الخلاصاتاتصالالخصوصية© 2026 Kitploit

دليل الأدوات

الفئات

عرض جميع الفئات
Loading categories
lenovo_y700_tb320fc_on_CVE-2025-21479 — In-memory kernel privilege escalation for Lenovo Legion Y700 2023 (TB320FC) exploiting CVE-2025-21479, a Qualcomm Adreno GPU SMMU flaw, with ReSukiSU root management. | Kitploit
أدوات/GitHubGitHub/xjoker/lenovo_y700_tb320fc_on_cve-2025-21479
Android SecurityPrivilege EscalationPersistence MechanismsExploitationMobile App PentestingPost-ExploitationMobile SecurityPayload DevelopmentBinary Exploitation

الأكثر شعبية

عرض الكل →

اكتشف الأدوات الأكثر استخدامًا من قبل مجتمعنا.

استكشف جميع الأدوات

تصفح مجموعتنا من الأدوات

عرض جميع الأدوات →
مشاركة
GitHubxjoker/lenovo_y700_tb320fc_on_cve-2025-21479

lenovo_y700_tb320fc_on_CVE-2025-21479

In-memory kernel privilege escalation for Lenovo Legion Y700 2023 (TB320FC) exploiting CVE-2025-21479, a Qualcomm Adreno GPU SMMU flaw, with ReSukiSU root management.

عرض المستودع
37منذ 19 أياملم تتم المراجعة بعد
المحتوى غير متوفر باللغة المطلوبة. عرض النسخة الإنجليزية.

TB320FC Kernel Root — CVE-2025-21479

English | 简体中文

In-memory kernel privilege escalation for the Lenovo Legion Y700 2023 (TB320FC), exploiting CVE-2025-21479 (Qualcomm Adreno GPU SMMU vulnerability), with full root management provided by ReSukiSU.

No bootloader unlock. No flashing. No PC required for activation.

⚠️ For authorized security research on devices you own. See Disclaimer.


Target Device

All offsets and behavior in this project are tuned for the following device. Do not expect it to work on other models/ROMs without retuning (see exploit/device_info.txt).

ModelLenovo Legion Y700 2023 (TB320FC) / TB320FC_PRC
SoCQualcomm SM8475 (Snapdragon 8+ Gen 1, Adreno 730)
SystemZUXOS 1.1.350 / Android 15 (SDK 35)
BuildAQ3A.240812.002 (TB320FC_CN_OPEN_USER_Q00031.0_V_ZUXOS_1.1.350_ST_250418)
Kernel5.10.209-android12-9-gef44381c3e04-ab50
Security patch2025-03-05
BootloaderLocked (this project does not unlock it)

Verified working as of 2026-09 on the above firmware.

Features

CapabilityImplementation
Privilege escalationcheese exploit: KGSL SMMU bug → GPU arbitrary physical R/W → in-memory root (uid 0 + full caps)
Root managementReSukiSU (KernelSU fork) in late-load mode loads kernelsu.ko; su served by an in-kernel hook (u:r:ksu:s0)
SELinuxRestored to Enforcing after activation (ReSukiSU policy rules stay applied)
One-tap UXRootActivator APK with embedded exploit + ksud; a single tap after boot
Auto-recovery (optional)Boot-triggered self-healing chain: adaptive load-gated trigger → cheese → root pipeline → optional hosts/Vector. Off by default (com.poc.roottool.CONFIG)
Xposed modulesSupported via NeoZygisk (ptrace zygote injection) + Vector
PersistenceNone by design (in-memory): re-activate after each reboot (~3-4 min; or enable the auto-recovery chain)

Screenshots

RootActivator (activated)ReSukiSU (working, 2 modules)
RootActivatorReSukiSU

Left: RootActivator after successful activation — SELinux Enforcing, kernelsu loaded, su available. Right: ReSukiSU manager — LKM mode working with 2 modules (NeoZygisk + Vector).

How It Works

RootActivator APK
   │
   ├─ libcheese.so ── KGSL SMMU exploit (CVE-2025-21479)
   │     1. Adreno 730 microcode access-check flaw (SDS packet mistaken for RingBuffer)
   │     2. Fake CP_SMMU_TABLE_UPDATE overwrites GPU TTBR0 → arbitrary physical R/W
   │     3. Zero selinux_state.enforcing; dump kernel from fixed PA 0xA8000000,
   │        parse kallsyms from the raw image (SM8475 has no physical KASLR)
   │     4. Patch __do_sys_capset with an escalation shellcode
   │        (prepare_kernel_cred(0) + commit_creds + clear TIF_SECCOMP);
   │        forked child calls capset() → uid 0 + full caps
   │
   └─ libksud.so (ReSukiSU) ── late-load mode
         1. kernelsu.ko loaded from ksud's embedded assets with manual relocation
            (does not rely on kernel symbol exports)
         2. install → /data/adb/ksu (ksud/busybox/bootctl)
         3. su channel online: /system/bin/su → kernel hook redirect → u:r:ksu:s0
         4. setenforce 1 — Enforcing restored, policy rules already injected by the ko

Notable engineering points

  • Qualcomm GKI trims kernel symbol exports. 77 symbols required by upstream KernelSU are missing, so a plain insmod kernelsu.ko fails. ReSukiSU's late-load resolves symbols itself and loads fine.
  • CPU affinity fix in cheese. With multiple cores, patched kernel text can be executed with stale instructions on another core (I-cache coherence), causing a panic. Pinning the process to one core makes the exploit far more reliable.
  • Load sensitivity. During the post-boot initialization storm (5-10 min) the failure rate is significantly higher. See docs/TROUBLESHOOTING.md.

Quick Start

1. Get RootActivator

Build from source (see Building) or grab the APK from the GitHub Releases page (not stored in the repo).

2. Install ReSukiSU manager

Download from ReSukiSU Releases and install the manager APK.

3. Activate

  1. After boot, wait 5-10 minutes (the tool auto-detects system load and waits if needed)
  2. Open RootActivator → tap Activate Root
  3. Wait 3-4 minutes (progress is shown in the built-in log)
  4. When done, open the ReSukiSU manager and grant root to your apps (Shizuku, terminals, ...)

4. (Optional) Xposed module support

  1. Install NeoZygisk (via ReSukiSU manager → Modules → install from storage)
  2. Install Vector (Xposed framework)
  3. After root is active, start the injector on the device (activation does not do this):
    su -c 'sh /data/adb/modules/zygisksu/post-fs-data.sh'
    
  4. Details in docs/VECTOR.md

Repository Layout — PoC + activator

The repo contains the PoC (the exploit) and its one-tap activator. The custom device layers (debloat scripts, privacy-hosts module, Xposed scope tooling, bring-up helpers) are kept out of tree in a separate private archive — they are deliberately not part of this repository. Details: docs/ARCHITECTURE.md.

├── LICENSE / CHANGELOG.md
├── README.md / README.zh-CN.md
│
├── exploit/            the PoC — root acquisition (CVE-2025-21479)
│   ├── source/         cheese.c / kallsyms_lookup.c / adrenaline.h
│   ├── device_info.txt Target device parameters (offsets, verified facts)
│   ├── build.sh        Build script (requires Android NDK)
│   └── README.md       Boundary statement, runtime chain, known failure modes
│
├── app/                RootActivator — one-tap activator (all extras OFF by default)
│   ├── src/            BootReceiver / HealGuardService / HealConfig / MainActivity (Kotlin)
│   ├── assets/         selfheal.sh / waiter.sh / xposed-up.sh
│   ├── native/         libcheese.so + libksud.so (built from exploit/; see tools/fetch_assets.py)
│   ├── AndroidManifest.xml
│   ├── debug.keystore  debug signing key used by the public APK
│   ├── build.py        Build script (kotlinc + d8 + aapt2 + apksigner)
│   └── README.md       App documentation
│
├── tools/              Build / inspection helpers
│   ├── fetch_assets.py         Host: prepare native assets (exploit + ksud)
│   ├── status_check.sh         On-device: root / module snapshot
│   └── check_mods.sh           On-device: module inspection helper
├── docs/               Documentation (English)
│   ├── ARCHITECTURE.md         Chains, engineering notes, root-cause records
│   ├── TROUBLESHOOTING.md      Failure handling, success-rate data
│   └── VECTOR.md               Xposed (NeoZygisk + LSPosed/Vector) setup
└── screenshots/        On-device PNG evidence

Building

exploit (Android NDK)

cd exploit
NDK=/path/to/android-ndk ./build.sh
# Produces ./cheese (arm64) → used as app/native/libcheese.so

RootActivator APK

تنزيل الأداة