Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
op13-cve-2026-64560 — Device-specific Android kernel exploit for CVE-2026-64560 on OnePlus 13 builds, providing temporary root via ADB shell with verified payloads and porting tools. | Kitploit
Tools/GitHubGitHub/a23bc/op13-cve-2026-64560
Android SecurityPrivilege EscalationVulnerability AnalysisExploitationMobile App PentestingReverse EngineeringPost-ExploitationMobile SecurityPapers & ResearchPayload DevelopmentBinary Exploitation
41218h 28m agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
GitHuba23bc/op13-cve-2026-64560

op13-cve-2026-64560

Device-specific Android kernel exploit for CVE-2026-64560 on OnePlus 13 builds, providing temporary root via ADB shell with verified payloads and porting tools.

View Repository

OnePlus 13 (OP5D0DL1) CVE-2026-64560

Device-specific adaptation of the CVE-2026-64560 Android proof of concept for the exact OnePlus 13 (PJZ110) builds listed below. It provides temporary root access for the current boot through an ADB-shell-only helper.

[!WARNING] This is experimental kernel exploit code. It can reboot the device, corrupt kernel state, or cause data loss. Use it only on a device you own or are explicitly authorized to test. Back up important data first.

Supported targets

This repository targets kernel images, and its profiles target build fingerprints; an OTA can change one without the other. Both builds below ship the byte-identical kernel, so they share every offset and differ only in the device-gate string. docs/BUILDS.md is the index and the decision tree for a new image — start there.

BP2A.250605.015CP2A.260605.016
Android1617
FingerprintOnePlus/PJZ110/OP5D0DL1:16/BP2A.250605.015/V.58c08ac-32ff28e-33c0954:user/release-keysOnePlus/PJZ110/OP5D0DL1:17/CP2A.260605.016/V.34246cc-e2d62b-e2d628:user/release-keys
Kernel6.6.118-android15-8-g9bc34d5b0c79-abogki537459655-4ksame
Page size / CPUs4 KiB / 8 onlinesame
Decoded Image SHA-256ee5ee448d2985eeeb7a8b5ad2e1efc34eeb410a8beae0ab484504d739124d613same
Payloadbin/cve-2026-64560-fanout-op13-bp2a.250605.015bin/cve-2026-64560-fanout-op13-cp2a.260605.016

The runner rejects an unexpected fingerprint and verifies every bundled payload before execution. This repository does not contain firmware images, device keys, or device-unique secrets.

Usage

Requirements:

  • Android Platform Tools with adb available on PATH
  • USB debugging enabled and authorized
  • a thermal headroom: attempts started above 55 °C miss far more often, and the campaign waits for it rather than hoping

From the repository root:

root@kitploit:~
sh scripts/boot-campaign.sh -s <serial> -p bin/cve-2026-64560-fanout-op13-cp2a.260605.016 -n 10

After ROOT_SUCCESS, any new terminal can open the temporary root shell:

root@kitploit:~
adb -s <serial> shell -T /data/local/tmp/su

Run id to verify uid=0(root). Access lasts only for the current boot; rerun after a reboot. No boot, vendor, or system partition is modified.

The exploit contains a probabilistic kernel race. The chain reaches the bridge stage reliably and clears its read gate about one boot in eight, so an empty run of boots is not evidence that anything is broken — budget boots, and see docs/BUILDS.md for the one counter that looks like a failure signal and is not.

scripts/boot-campaign.sh is the runner loop in POSIX sh, for hosts where the PowerShell host for scripts/root.ps1 is unavailable. Both apply the same gates.

Build

Android NDK r29 and API 35 are the reproducible-build defaults. The NDK is not present by default, so pass its root:

root@kitploit:~
.\scripts\build.ps1 -Profile profiles\op13\CP2A.260605.016.json -NdkRoot <path-to-ndk>

The script builds the exploit strategies and the temporary-su helper, strips the outputs, and verifies their pinned SHA-256 values.

rotate is built but deliberately not promoted: it took the kernel down on this device and has not been re-validated since the timer recalibration.

Porting to another build

root@kitploit:~
python tools/extract_image.py <boot.img> <out>   # compare the Image digest first
python tools/port_target.py --profile profiles/op13/<BUILD>.json

Everything a build owns is named after the build, so two builds of one device never collide. See docs/BUILDS.md for the decision tree and docs/PORTING.md for the full checklist.

Repository layout

Credits

The exploit framework this repository adapts — the exploit sources, the credential and restoration stages, the temporary-su helper, the reproducible build, the adaptive runner, and the porting toolkit — comes from the Xiaomi 15 dada adaptation:

  • https://github.com/quyicheng03-boop/xiaomi15-dada-cve-2026-64560

The OnePlus 13 offsets, race tuning, and validation here were measured on this device rather than carried over; the two kernel targets are different images, so almost every address differs. The dada profile and payloads are retained as the reference the framework was originally validated against.

The original proof of concept, and the vulnerability itself, is upstream of both:

  • NebuSec/CyberMeowfia

Exact revisions and Linux fixes are listed in docs/UPSTREAM.md.

License

Apache License 2.0, inherited from the upstream work. See LICENSE and NOTICE.

Download Tool
PathPurpose
bin/Verified AArch64 release payloads
profiles/op13/<BUILD>.jsonTarget descriptions, one per build fingerprint
profiles/dada/The Xiaomi 15 target this framework came from, kept as reference
src/C sources, generated per build from the shared templates
targets/Measured offset sets for a kernel image
evidence/Trimmed chain logs from runs that landed root
scripts/boot-campaign.shBoot loop with thermal, settle, and timeout gates
scripts/sweep.shSeveral tuning settings in one boot
scripts/root.ps1, build.ps1, new-target.ps1Runner, build, and scaffolding
tools/extract_image.pyKernel image out of a boot dump, both digests
tools/kallsyms_extract.pySymbol table from a raw arm64 Image (self-validating)
tools/ksym.pySymbol lookup in an extracted table
tools/btf_offsets.pyStruct member offsets from the Image's BTF blob
tools/port_target.pyGenerates a build source from a template + profile
docs/BUILDS.mdBuild index, decision tree, campaign pitfalls
docs/OP13.mdDerivation of every offset, with the evidence
docs/PORTING.mdNew-build adaptation and promotion checklist
docs/UPSTREAM.mdUpstream provenance and fixed revisions