
Device-specific Android kernel exploit for CVE-2026-64560 on OnePlus 13 builds, providing temporary root via ADB shell with verified payloads and porting tools.
OP5D0DL1) CVE-2026-64560Device-specific adaptation of the CVE-2026-64560 Android proof of concept for
the exact OnePlus 13 (PJZ110) builds listed below. It provides temporary root
access for the current boot through an ADB-shell-only helper.
[!WARNING] This is experimental kernel exploit code. It can reboot the device, corrupt kernel state, or cause data loss. Use it only on a device you own or are explicitly authorized to test. Back up important data first.
This repository targets kernel images, and its profiles target build
fingerprints; an OTA can change one without the other. Both builds below ship
the byte-identical kernel, so they share every offset and differ only in the
device-gate string. docs/BUILDS.md is the index and the
decision tree for a new image — start there.
BP2A.250605.015 | CP2A.260605.016 | |
|---|---|---|
| Android | 16 | 17 |
| Fingerprint | OnePlus/PJZ110/OP5D0DL1:16/BP2A.250605.015/V.58c08ac-32ff28e-33c0954:user/release-keys | OnePlus/PJZ110/OP5D0DL1:17/CP2A.260605.016/V.34246cc-e2d62b-e2d628:user/release-keys |
| Kernel | 6.6.118-android15-8-g9bc34d5b0c79-abogki537459655-4k | same |
| Page size / CPUs | 4 KiB / 8 online | same |
| Decoded Image SHA-256 | ee5ee448d2985eeeb7a8b5ad2e1efc34eeb410a8beae0ab484504d739124d613 | same |
| Payload | bin/cve-2026-64560-fanout-op13-bp2a.250605.015 | bin/cve-2026-64560-fanout-op13-cp2a.260605.016 |
The runner rejects an unexpected fingerprint and verifies every bundled payload before execution. This repository does not contain firmware images, device keys, or device-unique secrets.
Requirements:
adb available on PATHFrom the repository root:
sh scripts/boot-campaign.sh -s <serial> -p bin/cve-2026-64560-fanout-op13-cp2a.260605.016 -n 10
After ROOT_SUCCESS, any new terminal can open the temporary root shell:
adb -s <serial> shell -T /data/local/tmp/su
Run id to verify uid=0(root). Access lasts only for the current boot; rerun
after a reboot. No boot, vendor, or system partition is modified.
The exploit contains a probabilistic kernel race. The chain reaches the bridge
stage reliably and clears its read gate about one boot in eight, so an empty run
of boots is not evidence that anything is broken — budget boots, and see
docs/BUILDS.md for the one
counter that looks like a failure signal and is not.
scripts/boot-campaign.sh is the runner loop in POSIX sh, for hosts where the
PowerShell host for scripts/root.ps1 is unavailable. Both apply the same gates.
Android NDK r29 and API 35 are the reproducible-build defaults. The NDK is not present by default, so pass its root:
.\scripts\build.ps1 -Profile profiles\op13\CP2A.260605.016.json -NdkRoot <path-to-ndk>
The script builds the exploit strategies and the temporary-su helper, strips the outputs, and verifies their pinned SHA-256 values.
rotate is built but deliberately not promoted: it took the kernel down on this
device and has not been re-validated since the timer recalibration.
python tools/extract_image.py <boot.img> <out> # compare the Image digest first
python tools/port_target.py --profile profiles/op13/<BUILD>.json
Everything a build owns is named after the build, so two builds of one device
never collide. See docs/BUILDS.md for the decision tree and
docs/PORTING.md for the full checklist.
The exploit framework this repository adapts — the exploit sources, the
credential and restoration stages, the temporary-su helper, the reproducible
build, the adaptive runner, and the porting toolkit — comes from the Xiaomi 15
dada adaptation:
The OnePlus 13 offsets, race tuning, and validation here were measured on this
device rather than carried over; the two kernel targets are different images, so
almost every address differs. The dada profile and payloads are retained as
the reference the framework was originally validated against.
The original proof of concept, and the vulnerability itself, is upstream of both:
Exact revisions and Linux fixes are listed in
docs/UPSTREAM.md.
Apache License 2.0, inherited from the upstream work. See LICENSE
and NOTICE.
| Path | Purpose |
|---|
bin/ | Verified AArch64 release payloads |
profiles/op13/<BUILD>.json | Target descriptions, one per build fingerprint |
profiles/dada/ | The Xiaomi 15 target this framework came from, kept as reference |
src/ | C sources, generated per build from the shared templates |
targets/ | Measured offset sets for a kernel image |
evidence/ | Trimmed chain logs from runs that landed root |
scripts/boot-campaign.sh | Boot loop with thermal, settle, and timeout gates |
scripts/sweep.sh | Several tuning settings in one boot |
scripts/root.ps1, build.ps1, new-target.ps1 | Runner, build, and scaffolding |
tools/extract_image.py | Kernel image out of a boot dump, both digests |
tools/kallsyms_extract.py | Symbol table from a raw arm64 Image (self-validating) |
tools/ksym.py | Symbol lookup in an extracted table |
tools/btf_offsets.py | Struct member offsets from the Image's BTF blob |
tools/port_target.py | Generates a build source from a template + profile |
docs/BUILDS.md | Build index, decision tree, campaign pitfalls |
docs/OP13.md | Derivation of every offset, with the evidence |
docs/PORTING.md | New-build adaptation and promotion checklist |
docs/UPSTREAM.md | Upstream provenance and fixed revisions |