Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
POCO-M7-Plus-Jailbreak — Temporary Root Research on Poco M7 Plus (SM6375) via Qualcomm GBL Exploit (CVE-2026-24088) + GhostLock Kernel Analysis (CVE-2026-43499) | Kitploit
Tools/GitHubGitHub/aniketlab/poco-m7-plus-jailbreak
Android SecurityPrivilege EscalationVulnerability AnalysisExploitationReverse EngineeringMobile SecurityPapers & ResearchLearning & EducationPayload Development

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
Binary Exploitation
GitHubaniketlab/poco-m7-plus-jailbreak

POCO-M7-Plus-Jailbreak

Temporary Root Research on Poco M7 Plus (SM6375) via Qualcomm GBL Exploit (CVE-2026-24088) + GhostLock Kernel Analysis (CVE-2026-43499)

View Repository
3218h 30m agoNot yet reviewed

POCO M7 Plus (SM6375) - Jailbreak Root Research

Disclaimer: This document is written purely for educational and security research purposes. All testing was performed on my own device. I am not responsible for bricked devices, data loss, or misuse of this information. The vulnerabilities discussed here are already publicly disclosed and patched. Do not attempt this on devices you do not own.


⬇️ Quick Download — v2.1

FileDescription
GBL-AutoRoot.batOne-click exploit automation tool (Windows)

How to use:

  1. Download GBL-AutoRoot.bat from the link above
  2. Double-click to run - no installation needed
  3. Connect your phone via USB when prompted
  4. Script handles everything: ADB download, device detection, exploit, result

Compatible with any Qualcomm ABL device affected by CVE-2026-24088. If your device returns OKAY, root access is granted automatically.


Supported Devices

This tool targets the Qualcomm ABL vulnerability (CVE-2026-24088). If your device has a vulnerable SoC and hasn't received the patched firmware yet, this tool will work.

StatusDevice / SoC FamilyExample Devices
🟢 ConfirmedSnapdragon 695 (SM6375)POCO M7 Plus 5G, Redmi 15 5G
🟡 PotentialSnapdragon 8 Gen 3 (SM8650)Xiaomi 14 / Pro / Ultra, Redmi K70 Pro
🟡 PotentialSnapdragon 8 Gen 2 (SM8550)Xiaomi 13 / Pro, POCO F5 Pro, Redmi K60 Pro
🟡 PotentialSnapdragon 8+ Gen 1 (SM8475)Xiaomi 12T Pro, POCO F5
🟡 PotentialSnapdragon 888 (SM8350)Mi 11, Mi 11X Pro, POCO F3
🟡 PotentialSnapdragon 7+ Gen 3 (SM7675)POCO F6
🟡 PotentialSnapdragon 7 Gen 3 (SM7550)Xiaomi Civi 4
🟡 PotentialSnapdragon 695 5G (SM6375)POCO X4 Pro 5G, Redmi Note 11 Pro 5G
🟡 PotentialSnapdragon 680 (SM6225)Redmi Note 11, Redmi 10C
🟡 PotentialSnapdragon 662 (SM6115)POCO M3, Redmi 9T
🔴 No SupportMediaTek (MTK)POCO X6 Neo, Redmi Note 13 Pro+
🔴 No SupportPatched FirmwareHyperOS 3.0.304.0+ (Security Patch applied)

📝 Community Testing Required: I do not have all these devices available for testing. If you have one of the "Potentially Supported" devices, please test the tool and let me know the results. This will help me confirm and officially add your device to the "Confirmed Working" list!


Table of Contents

  1. Device & Environment
  2. Research Overview - Two Approaches
  3. Approach A: Qualcomm GBL Exploit (Fastboot Route)
  4. Approach B: GhostLock Kernel Exploit (Attempted)
  5. Comparison: GBL vs GhostLock
  6. Risk & Security Implications
  7. Patch Status & How to Check
  8. Screenshots - Proof of Working
  9. References & Credits

1. Device & Environment

FieldValue
DevicePoco M7 Plus 5G (codename: spring)
ChipsetQualcomm SM6375 (Snapdragon 6s Gen 3)
ArchitectureAArch64, KASLR enabled
SELinuxEnforcing (before exploit)
BootloaderLOCKED
Test PlatformWindows 11, ADB Platform Tools

Firmware Versions Tested During Research

HyperOS VersionKernel VersionGhostLock ResultGBL Exploit Result
2.0.202.06.1.118-android14-11-ga3b9c44908dd-ab13320413❌ Kernel Panic✅ Working
2.0.208.06.1.138-android14-11-g51f8c580613d-ab13911623❌ Kernel Panic✅ Working

Research Note: I initially tested on HyperOS 2.0.202.0 where GhostLock caused kernel panic. I then updated to 2.0.208.0 to check if the newer kernel build (6.1.118 -> 6.1.138) would resolve GhostLock instability. The panic persisted - both builds share the same 6.1 pselect/fd_set internal layout that GhostLock cannot handle. The GBL exploit worked on both versions.


2. Research Overview - Two Approaches

During this research, I tested two independent exploit paths to achieve temporary root on this device without unlocking the bootloader:

Approach A: GBL ExploitApproach B: GhostLock
LayerBootloader (ABL/fastboot)Kernel (Linux 6.1)
CVECVE-2026-24088CVE-2026-43499
Result on this device✅ Working❌ Kernel Panic
Root TypeTemporary (tethered)Temporary (tethered)
Requires ADB?Yes (fastboot mode)Yes (shell access)
Kernel version sensitive?NoYes - only stable on 6.6-6.12

The GBL exploit worked. GhostLock failed with a kernel panic due to a kernel version mismatch. Both findings are documented in detail below.


3. Approach A: Qualcomm GBL Exploit (Fastboot Route)

Vulnerability Background

CVE-2026-24088 affects Qualcomm's Android Boot Loader (ABL) across multiple devices.

Jan 2026 -> Vulnerability discovered during ABL unpacking & analysis
Feb 2026 -> Qualcomm patches: QcomModulePkg: Fix propagation of untrusted input into kernel cmdline
Mar 2026 -> Public PoC released; Xiaomi begins rolling out HyperOS 3.0.304.0 (patched)
Jun 2026 -> CVE-2026-24088 officially assigned in Qualcomm Security Bulletin

Exploit Chain Explained

The exploit works as a three-stage chain at the bootloader level:

Stage 1 - Unsigned GBL Execution

In Android 16, Qualcomm's ABL loads the Generic Bootloader (GBL) from the efisp partition. The critical flaw: ABL only checks if the binary is a valid UEFI application - it does NOT verify its cryptographic signature. This means a custom, unsigned UEFI application can be placed in efisp and it will execute at bootloader stage with full privileges.

Stage 2 - Kernel Command-Line Injection

The fastboot oem set-gpu-preemption command lacks input sanitization. The ABL directly concatenates the provided argument into the kernel command line without filtering.

By passing androidboot.selinux=permissive as an additional argument:

fastboot oem set-gpu-preemption 0 androidboot.selinux=permissive

...the bootloader writes androidboot.selinux=permissive into the kernel cmdline, which Android's init process reads at boot - effectively disabling SELinux enforcement.

Stage 3 - Unlock Flag Manipulation (Optional)

A custom UEFI application placed in efisp can set is_unlocked and is_unlocked_critical flags to permanently unlock the bootloader. (This step was NOT tested - carries hard brick risk.)

Step-by-Step Reproduction

⚠️ Stop before proceeding: Run the patch check in Section 7 first. If your device is patched, none of this will work.

Prerequisites:

  • Windows PC with ADB/Fastboot (Platform Tools)
  • Original USB cable
  • Device on HyperOS 2.0.208.0 or earlier (do NOT update)
  • USB Debugging enabled in Developer Options
  • KernelSU Manager APK or ReSukiSU Manager APK installed on phone
Download Tool